Zoom Lied about End-to-End Encryption

The facts aren’t news, but Zoom will pay $85M — to the class-action attorneys, and to users — for lying to users about end-to-end encryption, and for giving user data to Facebook and Google without consent.

The proposed settlement would generally give Zoom users $15 or $25 each and was filed Saturday at US District Court for the Northern District of California. It came nine months after Zoom agreed to security improvements and a “prohibition on privacy and security misrepresentations” in a settlement with the Federal Trade Commission, but the FTC settlement didn’t include compensation for users.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Evolve With XDR – The Modern Approach to SecOps

If you are part of an organization aspiring to evolve and modernize your SecOps practice with greater efficiencies with XDR, this read is for you.

So, what’s all the continuous hype about XDR? Is it for you and what does it mean to your organization? If you haven’t already, I invite you to read our XDR—Please Explain and Unravel to XDR Noise blogs for added context. From here we can begin to ask, what are XDRs and what are they not? What happens once you acquire components that add the “X-factor” to your threat detection and response (TDR) practice? And how can SOC teams use it for investigation, prioritization, remediation and hunting?

I’ll cover the basics in this blog and hopefully by the end I’ve piqued your interest enough to join us for a webinar on August 19th where we will cover these aspects in detail.

Live Webinar

Evolve With XDR – The Modern Approach to SecOps

Thursday, August 19, 2021
11am PT | 1pm CT | 2pm ET

Register Now

For security practitioners, there’s one question that is top of mind—am I protected against the latest threats? But let’s face it, threats are evolving, adversaries are evolving too and a shortage of talent make it near impossible to keep up with alerts.

In fact, according to the latest XDR research by ESG, The Impact of XDR in the Modern SOC March 2021 [1], the top challenges related to TDR for respondents were:

  1. 31% spend time addressing high priority/emergency threats and not enough time on more comprehensive strategy and process improvement for TDR
  2. Another 29% have “blind spots” on the network due to inability to deploy agents
  3. 23% find it difficult to correlate and combine data from different security controls, which impacts TDR efficiency/efficacy

Advanced threats are now commonplace, challenging most security professionals to detect and respond before damage is done, we know that these attacks leverage multiple attack vectors to gain a foothold and execute. XDR solutions bring together security telemetry across multiple controls, correlating and stitching together complex attacks so analyst can quickly assess and investigate. XDR is seen as having the potential to modernize the SOC with enriched and aggregated security analytics capabilities to accelerate the investigation to a resolution.

What’s more, McAfee Enterprise is here to help you evolve your SecOps practice into the next era of security analytics, threat detection and response. McAfee’s MVISION XDR tools provide visibility across multiple control points to not only detect threats but to help organizations improve their security posture. In addition, MVISION Insights provides relevant threat intel to help customers proactively prevent threats on multiple control points like endpoint.

We invite you to a joint webinar with Mo Cashman, Enterprise Architect at McAfee Enterprise, and Dave Gruber, Senior Analyst at ESG, as they cover what XDRs are and aren’t, the keys to SOC modernization for XDR with a focus on the SOAPA approach to security, and how McAfee’s MVISION XDR lays out the flexible groundwork for organizations aspiring to evolve with XDR. Here is the link to register. 

Whether you are building a SOC function with limited resources or maturing a well-established SOC, McAfee Enterprise is here to help you simplify and strengthen your security operations with MVISION XDR. With MVISION XDR, you can proactively identify, investigate and mitigate threat actors targeting your organization before they can gain a foothold in the network. By combining the latest machine-learning techniques with human analysis, XDR connects and amplifies the early warning signals from your sensors at the network, endpoint, and cloud to improve situational awareness, drive better and faster decisions, and elevate your SOC. [2]

We hope to see you there!

 

1 – ESG Research Report: The Impact of XDR in the Modern SOC by Jon Oltsik

2 – Cyber Cyber, Burning Bright: Can XDR Frame Thy Fearful Asymmetry?

 

The post Evolve With XDR – The Modern Approach to SecOps appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Gangs and the Name Game Distraction

It’s nice when ransomware gangs have their bitcoin stolen, malware servers shut down, or are otherwise forced to disband. We hang on to these occasional victories because history tells us that most ransomware moneymaking collectives don’t go away so much as reinvent themselves under a new name, with new rules, targets and weaponry. Indeed, some of the most destructive and costly ransomware groups are now in their third incarnation.

A rough timeline of major ransomware operations and their reputed links over time.

Reinvention is a basic survival skill in the cybercrime business. Among the oldest tricks in the book is to fake one’s demise or retirement and invent a new identity. A key goal of such subterfuge is to throw investigators off the scent or to temporarily direct their attention elsewhere.

Cybercriminal syndicates also perform similar disappearing acts whenever it suits them. These organizational reboots are an opportunity for ransomware program leaders to set new ground rules for their members — such as which types of victims aren’t allowed (e.g., hospitals, governments, critical infrastructure), or how much of a ransom payment an affiliate should expect for bringing the group access to a new victim network.

I put together the above graphic to illustrate some of the more notable ransom gang reinventions over the past five years. What it doesn’t show is what we already know about the cybercriminals behind many of these seemingly disparate ransomware groups, some of whom were pioneers in the ransomware space almost a decade ago. We’ll explore that more in the latter half of this story.

One of the more intriguing and recent revamps involves DarkSide, the group that extracted a $5 million ransom from Colonial Pipeline earlier this year, only to watch much of it get clawed back in an operation by the U.S. Department of Justice.

After acknowledging someone had also seized their Internet servers, DarkSide announced it was folding. But a little more than a month later, a new ransomware affiliate program called BlackMatter emerged, and experts quickly determined BlackMatter was using the same unique encryption methods that DarkSide had used in their attacks.

DarkSide’s demise roughly coincided with that of REvil, a long-running ransomware group that claims to have extorted more than $100 million from victims. REvil’s last big victim was Kaseya, a Miami-based company whose products help system administrators manage large networks remotely. That attack let REvil deploy ransomware to as many as 1,500 organizations that used Kaseya.

REvil demanded a whopping $70 million to release a universal decryptor for all victims of the Kaseya attack. Just days later, President Biden reportedly told Russian President Vladimir Putin that he expects Russia to act when the United States shares information on specific Russians involved in ransomware activity.

A REvil ransom note.

Whether that conversation prompted actions is unclear. But REvil’s victim shaming blog would disappear from the dark web just four days later.

Mark Arena, CEO of cyber threat intelligence firm Intel 471, said it remains unclear whether BlackMatter is the REvil crew operating under a new banner, or if it is simply the reincarnation of DarkSide.

But one thing is clear, Arena said: “Likely we will see them again unless they’ve been arrested.”

Likely, indeed. REvil is widely considered a reboot of GandCrab, a prolific ransomware gang that boasted of extorting more than $2 billion over 12 months before abruptly closing up shop in June 2019. “We are living proof that you can do evil and get off scot-free,” Gandcrab bragged.

And wouldn’t you know it: Researchers have found GandCrab shared key behaviors with Cerber, an early ransomware-as-a-service operation that stopped claiming new victims at roughly the same time that GandCrab came on the scene.

GOOD GRIEF

The past few months have been a busy time for ransomware groups looking to rebrand. BleepingComputer recently reported that the new “Grief” ransomware startup was just the latest paintjob of DoppelPaymer, a ransomware strain that shared most of its code with an earlier iteration from 2016 called BitPaymer.

All three of these ransom operations stem from a prolific cybercrime group known variously as TA505, “Indrik Spider” and (perhaps most memorably) Evil Corp. According to security firm CrowdStrike, Indrik Spider was formed in 2014 by former affiliates of the GameOver Zeus criminal network who internally referred to themselves as “The Business Club.”

The Business Club was a notorious Eastern European organized cybercrime gang accused of stealing more than $100 million from banks and businesses worldwide. In 2015, the FBI offered a standing $3 million bounty for information leading to the capture of the Business Club’s leader — Evgeniy Mikhailovich Bogachev. By the time the FBI put a price on his head, Bogachev’s Zeus trojan and later variants had been infecting computers for nearly a decade.

The alleged ZeuS Trojan author, Evgeniy Mikhaylovich Bogachev. Source: FBI

Bogachev was way ahead of his colleagues in pursuing ransomware. His Gameover Zeus Botnet was a peer-to-peer crime machine that infected between 500,000 and a million Microsoft Windows computers. Throughout 2013 and 2014, PCs infected with Gameover were seeded with Cryptolocker, an early, much-copied ransomware strain allegedly authored by Bogachev himself.

CrowdStrike notes that shortly after the group’s inception, Indrik Spider developed their own custom malware known as Dridex, which has emerged as a major vector for deploying malware that lays the groundwork for ransomware attacks.

“Early versions of Dridex were primitive, but over the years the malware became increasingly professional and sophisticated,” CrowdStrike researchers wrote. “In fact, Dridex operations were significant throughout 2015 and 2016, making it one of the most prevalent eCrime malware families.”

That CrowdStrike report was from July 2019. In April 2021, security experts at Check Point Software found Dridex was still the most prevalent malware (for the second month running). Mainly distributed via well-crafted phishing emails — such as a recent campaign that spoofed QuickBooks — Dridex often serves as the attacker’s initial foothold in company-wide ransomware attacks, CheckPoint said.

REBRANDING TO AVOID SANCTIONS

Another ransomware family tied to Evil Corp. and the Dridex gang is WastedLocker, which is the latest name of a ransomware strain that has rebranded several times since 2019. That was when the Justice Department put a $5 million bounty on the head of Evil Corp., and the Treasury Department’s Office of Foreign Asset Control (OFAC) said it was prepared to impose hefty fines on anyone who paid a ransom to the cybercrime group.

Alleged Evil Corp leader Maksim “Aqua” Yakubets. Image: FBI

In early June 2021, researchers discovered the Dridex gang was once again trying to morph in an effort to evade U.S. sanctions. The drama began when the Babuk ransomware group announced in May that they were starting a new platform for data leak extortion, which was intended to appeal to ransomware groups that didn’t already have a blog where they can publicly shame victims into paying by gradually releasing stolen data.

On June 1, Babuk changed the name of its leaks site to payload[dot]bin, and began leaking victim data. Since then, multiple security experts have spotted what they believe is another version of WastedLocker dressed up as payload.bin-branded ransomware.

“Looks like EvilCorp is trying to pass off as Babuk this time,” wrote Fabian Wosar, chief technology officer at security firm Emsisoft. “As Babuk releases their PayloadBin leak portal, EvilCorp rebrands WastedLocker once again as PayloadBin in an attempt to trick victims into violating OFAC regulations.”

Experts are quick to point out that many cybercriminals involved in ransomware activity are affiliates of more than one distinct ransomware-as-a-service operation. In addition, it is common for a large number of affiliates to migrate to competing ransomware groups when their existing sponsor suddenly gets shut down.

All of the above would seem to suggest that the success of any strategy for countering the ransomware epidemic hinges heavily on the ability to disrupt or apprehend a relatively small number of cybercriminals who appear to wear many disguises.

Perhaps that’s why the Biden Administration said last month it was offering a $10 million reward for information that leads to the arrest of the gangs behind the extortion schemes, and for new approaches that make it easier to trace and block cryptocurrency payments.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHUSA: What is the Future of Security Advisories?

#BHUSA: What is the Future of Security Advisories?

Organizations of all sizes are bombarded with a seemingly endless stream of security advisories on a daily basis. The challenge for many is figuring out whether a given advisory actually impacts their organization.

At the Black Hat US 2021 event, Allan Friedman, director of cybersecurity initiatives at NTIA, US Department of Commerce, and Thomas Schmidt, ICS and advisory expert, Federal Office for Information Security (BSI) in Germany, outlined an emerging approach to help solve the challenge of being overwhelmed by security advisories.

“How do we communicate that a device or piece of software is not actually exploitable?” Friedman asked. “The answer is a new idea called the Vulnerability Exploitability eXchange, or VEX.”

The VEX concept actually builds on several other key ideas, including having an automated machine-readable format for security advisories. VEX will identify whether a particular version of software is impacted by an advisory and what action needs to be taken. Friedman emphasized that he wants VEX to be what he referred to as a “negative” security advisory. Whereas a normal security advisory conveys what products are impacted, the goal of VEX is to communicate what is not affected.

Automation is the Key to VEX

A real challenge with security advisories today is that there is a lot of manual effort required by organizations to assemble, analyze and understand them.

Schmidt noted that what’s needed to make security advisories effective is automation. That’s where an effort known as the Common Security Advisory Framework (CSAF) comes into play. CSAF is an open standards approach to providing security advisories that are in a machine-readable format.

With CSAF, humans in an organization no longer need to parse though security advisories with various formats to try to figure out what’s important to them. Schmidt emphasized that CSAF can reduce the workload for overburdened IT staff.

“We don’t have to search this boring stuff for advisories; we see only the relevant advisories, as it is machine readable,” Schmidt said. “You don’t have to worry about corporate design stuff, so it’s scalable across vendors, and you can do your risk assessment based on your own environment.”

Friedman noted that VEX, in turn, is a profile in CSAF. As part of a CSAF deployment, organizations should also have some form of asset management in place, where they know what software and devices are running. In the ideal scenario, an automated CSAF advisory can be ingested by an organization that can then automatically map that to their own assets and, with VEX, know immediately that they are, or are not, at risk.

“We can provide real value for our users, not just in which vulnerabilities they should pay attention to, but which ones they shouldn’t,” Friedman said.

One particular industry that can potentially really benefit from VEX is healthcare. Friedman noted that patching and security updates impose real costs as organizations often need to take things offline that they may not want to do on a live network. For example, without knowing for sure if a given device is vulnerable, a hospital might have to figure out a way to care for a patient while they take a critical device offline to update it.

“The more efficient and automated we can make updates, it’s going to bring real benefits not just for security, but for human health and safety,” Friedman said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHUSA: The 9 Lives of the Charming Kitten Nation-State Attacker

#BHUSA: The 9 Lives of the Charming Kitten Nation-State Attacker

Not all nation-state attacker groups use innovative techniques to be successful; some will just use the same tried and true techniques again and again.

In a session at Black Hat US 2021, a pair of researchers from IBM X-Force outlined how a nation-state group that it refers to as ITG18 continues to use the same techniques to attack victims. ITG18, which is alleged to be backed by Iran, is also known by other names that it has been given by other research groups, including Charming Kitten, Phosphorous, and APT35.

Richard Emerson, senior threat hunt analyst at IBM X-Force, explained that his team was able to find an open file directory used by Charming Kitten and found a treasure trove of information about the group and how it operates. The directory included hours of training videos, detailing how members of the adversary group could infect and exfiltrate data from victims.

A hallmark of Charming Kitten’s operations, according to Emerson, was the group’s phishing attacks against personal, social media, and webmail accounts to support their espionage and surveillance objectives. Even after their efforts were discovered, Charming Kitten has continued to pounce on new victims.

In March 2019, Microsoft claimed that it significantly disrupted Charming Kitten, taking over 99 domains associated with the group. Emerson noted that in the months and years since, Charming Kitten has just registered new domains and has continued with the same basic tactics.

“This group does not seem to particularly care about public disclosure of their activities like other groups do, possibly because they continue to enjoy success with their tactics,” Emerson said.

Among the tools used by Charming Kitten is one that the IBM researchers have named LittleLooter. Emerson explained that LIttleLooter is a functionally rich backdoor that is capable of recording video and sound phone calls, gathering information on call history and SMS messages, as well as gathering location data and browser history.

“With all this personal information taken from targets of interest, we can only guess at how it’s been used by the Iranian government to further their objectives,” Emerson said.

Charming Kitten is a Large Operation

Allison Wikoff, senior strategic cyber-threat analyst at IBM X-Force, noted that she is confident that Charming Kitten is a very large operation, in terms of the number of people involved.

For example, she noted that IBM has collected over 2,000 unique indicators associated with the group’s activities and over 2 terabytes of data stolen from victims. The fact that the group has training videos also implies they are recruiting new members and have some turnover in their operations.

“They have consistently targeted Iranian journalists and researchers in country and abroad, but they’ve also gone after foreign targets like COVID researchers, nuclear regulators, US politicians and financial regulators, all depending on what’s happening,” Wikoff said.

How to Defend Against Charming Kitten

There are a number of different things organizations can do to help limit the risk from Charming Kitten. Wikoff emphasized that a key foundational step is to have multi-factor authentication on everything.

Additionally, Wikoff said that it’s important for organizations to think about how to train employees to notice and report threats. In the case of Charming Kitten, as well as with other threat actors, she noted that personal resources are targeted, and as such the personal computing habits of employees can impact the organizational security of a company.

“We’ve seen they have the ability to mass collect information, not just off personal webmail accounts but also off of cell phones,” Wikoff said. “They have hardly changed their tactics in the last four years and yet they continue to expand their targets and operations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHUSA: Hacking a Capsule Hotel to Silence a Noisy Neighbor

#BHUSA: Hacking a Capsule Hotel to Silence a Noisy Neighbor

Security researcher Kya Supa was staying at a capsule hotel in Japan while on vacation and had a noisy neighbor.

Every day at around 2 a.m., the neighbor would be on the phone making a loud call. Supa politely asked the neighbor to not be so loud, but the neighbor didn’t listen. What happened next was the subject of Supa’s session at the Black Hat US 2021 hybrid event, where he detailed how he was able to hack the hotel’s system to get back at his noisy neighbor, whom he referred to as Bob.

“Some people just don’t take anything seriously,” Supa said about Bob. “So I thought it would be nice if I could take control of his room and make him have a lovely night.”

How the Capsule Hotel Was Hacked

The capsule hotel that Supa was staying at was highly automated. Each room had an iPad that enabled control of the small room’s amenities, including lights, fan and an adjustable bed that could be converted into a sofa.

After inspecting the room, Supa also discovered that each room had a pair of Internet of Things (IoT) gateway control devices from Japanese vendor Nasnos, which controlled the room’s operations. The iPad that connected to the Nasnos devices was locked down in what Apple refers to as Guided Access, which restricts access to only one application.

While Guided Access initially would not allow Supa to access other features on the iPad, he figured out an easy way to get around that. Simply by letting the iPad run out of power and then rebooting, he was able to bypass Guided Access and get full control of the device.

Using scanning tools, Supa was able to discover the Nasnos access point and realized that it was secured with the insecure WEP protocol. Adding further insult to injury, Supa discovered that the gateway devices that were controlling the IoT devices in each capsule room were using a default password of—1,2,3,4,5.

By observing the data traffic in his own room as he turned the lights on and off and adjusted his bed, Supa was able to figure out how to control everything using his own laptop. After some additional investigation, Supa was also able to figure out how to gain access to specific routers in specific rooms. With that knowledge, he could control the functions of another guest’s room—like his noisy neighbor, Bob.

Simply turning the lights on and off in Bob’s room wasn’t enough for Supa though; he wanted to do something more disrupting. What Supa ended up doing was writing a script that ran every two hours that would turn the lights on and off, while collapsing the bed into a sofa.

“I’m sure he had a wonderful night,” Supa said about Bob. “I hope he’ll be more respectful of his neighbors in the future.”

Supa noted that he disclosed all the security issues he found to the hotel, after he had messed with Bob, and that the issues have since been remediated by the hotel.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHUSA: Researchers Criticize Apple Bug Bounty Program

#BHUSA: Researchers Criticize Apple Bug Bounty Program

According to a pair of researchers at the Black Hat US 2021 event, there is no shortage of ways to bypass privacy mechanisms in Apple’s macOS operating system. While Apple does have a bug bounty program to reward researchers for disclosing flaws, the time it takes to fix issues is a real concern.

Wojciech Reguła, senior IT security specialist at SecuRing, explained that at the core of macOS is the Transparency, Consent and Control (TCC) system. Regula said that macOS users are familiar with the privacy tab in TCC, which grants permissions to applications to operate. Alongside Csaba Fitzl, content developer at Offensive Security, Regula enumerated a list of over 20 different ways that TCC can potentially be abused or bypassed to leak private information.

One of the ways that TCC can be bypassed is via application plug-ins, which is what CVE-2020-27937 does, which is a vulnerability disclosed by Regula and patched in macOS 11.0.1. With that vulnerability, the application plug-in abuses the authorizations from the macOS directory utility to get unauthorized access.

Process injection is another way TCC can be bypassed, which is something that CVE-2020-10006 enables, which was also patched in macOS 11.0.1. More recently, Apple patched CVE-2021-30751 in macOS 11.4, which is a TCC bypass in the Notes application that is part of the operating system.

In particular, Regula noted that third-party apps are quite useful for enabling TCC bypasses through process injection. In his view, all apps built with the Electron JavaScript framework are vulnerable by default in current versions of macOS. The Firefox web browser is also vulnerable to a TCC process injection attack on macOS.

Another way that TCC can be bypassed is via application behavior. For example, Fitzl noted that some applications move files when they execute an operation, and that movement might enable access to private files. That type of bypass can lead to information leaks, according to Fitzl. In the last two years, Fitzl and Regula have reported no less than five different vulnerabilities in TCC that can lead to info leaks.

Why Apple’s Security Bounty Needs to Improve

The two researchers noted they have submitted all the vulnerabilities they find via the Apple Security Bounty (ASB) program, which rewards researchers for responsibly disclosing issues.

Fitzl noted that ASB has a category for privacy bypasses, which can range from $25,000 for small leaks, up to $100,000 USD for major bypasses. While the payouts can be substantial, Fitzl argued that the bug fixes can be really slow. Additionally, he complained that there is a lack of transparency from Apple about when, or even if, a reported issue will be fixed. In fact, Fitzl noted that in at least one case it took two years for a submitted issue to be patched by Apple. Fitzl also complained that there can sometimes be a very delayed response to an initial report, with one case taking seven months to get a response.

“There are a lot of things that Apple should improve,” Regula said. “For example, I would like to see a transparent way to see the current state of bug reports, if they are fixed or there are plans to fix, because we have heard about a lot of silent fixes.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk