Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Sunday, March 24, 2024

Repository=Malware Depository

 Not too long ago, repositories were not targeted. If you used a library or repository, there was a reasonable assumption it could be trusted and used without an issue. There started to be a trend around 2017 with malicious packages being placed in the Python Package Index (PyPI). There was also the case of the University of Minnesota sending buggy packages to Linux as a research experiment. Somehow this was approved by their research ethics board. The University was banned for their behavior from the repository.

In January 2024, more malicious packages were detected in the PyPI. One piece of malware noted this time around was the White Snake Stealer. These were uploaded by a bad actor named “WS”. The malware is designed to harvest data from web browsers, cryptocurrency wallets, and apps.

This is one reason not to blindly trust the repositories. You never know. Generally, you will be fine. As President Reagan is often quoted, “Trust, but verify.” There are several tools openly available to scan these for vulnerabilities. The last thing you want is to poison your elegant code with malicious code from a “trusted” repository. 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Tuesday, June 1, 2021

New Zealand Health Services Attacked

 


Hospitals provide a plethora of data. The attackers could target hospital and/or patient data. This is exceptionally marketable to many different entities. When the attackers couple this with ransomware, there is ample chances for severe attacks. This malicious tool has been used over the last few years in many different industries. The medical industry has been exceptionally hit by this. This is partially due to the criticality of the data. The attackers know patient care is totally dependent on the EMR/EHR being readily accessible by the medical staff. This was truly a significant problem starting two years with the attacks in the UK.

The attackers have pivoted down under and have attacked the New Zealand health service. Specifically the Waikato District Health Board’s (DHB) network. The Waikato hospital network was successfully breached. The attack, while on point, did not completely cripple the entry network. Of the 103 surgeries, 73 still were able to move ahead. Another hospital in the network did however have to reschedule its surgeries. In rural hospitals, all outpatient activity needed to be deferred. The staff were working to remediate the issue and get the systems back online.

In this case, it appears the attack vector was the simple email attachment. This is another example of an area for employee training. All it takes is the right employee in the right department at the wrong time clicking an attachment.

 

Free software bi-products

 

We all like free software. We find what we want on the internet and download it. Generally, there isn’t an issue. You can download Nmap, Kali Linux, and others with no issue. There is, however, always the anomaly or edge case when there is a problem. A recent issue occurred at a medical institute.

In this instance, a student was working at a biomolecular institute in Europe. The institute happed to allow personal computers on their network. You can guess what happened next. The facility, which was not named, allowed the student on their network with the student’s personal computer. The student happened to have downloaded free software (data visualization software). A little bit of malware piggy backed its way onto the personal computer and then into the network. The student attempted to download the software, which was blocked by Windows Defender. Not taking the hint, the student disabled the service, and then downloaded the software.

Fortunately, the institute had back-ups to use. These were not fully up-to-date, but viable. Recreating a week’s worth of data is painful, but workable. As a wrinkle, the institute also had to rebuild the entity of the computer and server files prior to the data being uploaded.

This attack is a lesson in allowing unknown or tested equipment on the network. Without a NAC or other tools in place, anyone’s personal computer and all the issues associated with it are also invited into the network. There are several tools available to assist with securing this portion of network control along with policies to be implemented.

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Sunday, March 22, 2020

U of U Compromises-Uh Oh



The University system tends to focus on research in specific disciplines. These may be business, psychology, sociology, criminal justice, medical, or any of the other areas within the University system. While the staff is fulfilling their tasks, the IT area of operations is continuously working to detect attacks and put in place mitigations to reduce the opportunity for a breach. This is a daunting task for many reasons. One such target was the University of Utah Health system. The organization was unfortunately breached at least twice recently.
Attack
The system is deluged with attacks and the beginning stages of attacks, just like any other medical facility. Unfortunately, two of these recently were successful.

The first was from January 22 through February 27, 2020. This successful attack was focused on email accounts. During this period there was an unauthorized access to a portion of the University of Utah Health staff email accounts. This was accomplished through the infamous phishing attack. This attack vector is so successful with such little capital or effort, this is bound to not slow down.

The second known successful attack was in the form of malware on a system. This was detected on February 3, 2020. Once this was found, the University of Utah Health contacted a third-party cybersecurity organization to assist them with the investigation. This investigation noted the malware may have been able to access a portion of the patient’s data, which was located in the respective employee’s email.
Data
With both of these noted successful attacks, the commonality was an unauthorized access to patient data. With these breach instances, the patient data may have included the patient name, date of birth, medical record numbers, and a limited amount of treatment information.
Post-Attack Actions
The investigation into the attack was not a simple review of logs. The compromises were alleged of a complex nature and of a highly technical nature. This is not an unusual statement by the University of Utah Health. If they were to state the attack was exceptionally simple, the management would be having additional issues from many other parties, including potentially the federal government, attorneys, and others.

The organization is also mailing letters to the affected patients. This is the standard protocol. To lower the potential for this to occur again, the organization is updating InfoSec procedures with the employees. This may or may not be successful, based on the implementation. If after a few months, the management does not reinforce the idea of cybersecurity, any lessons learned will fall by the wayside.
Looking Forward
This is yet another case of where training needs to be done through the year, insightful, and have some level of entertainment. Without this in place, the organizations will continue to be reactive post-breach, instead of pro-active to minimize the potential for a breach. Having known the method for the phishing attack would have been a great step forward. The industry could have learned from this and tailored other’s training to avoid this issue.

Resources
Bennett, L. (2020, March 21). University of Utah health says some patients’ data compromised in ‘phishing’ security breach. Retrieved from https://www.ksl.com/article/46732931/university-of-utah-health-says-some-patients-data-compromised-in-phishing-security-breach

DeWitt, K. (2020, March 20). U of U health announces phishing schemes caused unauthorized access to some employee accounts. Retrieved from https://www.abc4.com/news/top-stories/u-of-u-health-announces-phishing-schemes-caused-unauthorized-access-to-some-employee-email-accounts/

Roberts, A. (2020, March 21). Hacked: Some patient information compromised in U of U Health breach. Retrieved from https://kutv.com/news/local/some-u-of-u-health-patient-information-may-be-compromised-in-data-breach

Tuesday, January 21, 2020

Watch your PoS!


Seemingly, a restaurant or restaurant chain would not be a high value target, placed near the top of the target list as they don’t have or retain any PII (e.g. name, social security number, medical records, and other confidential data). Curiously though, this industry has much the same data that others do, which is very sale-able. The primary data here for the attackers are the credit card numbers. These may be monetized in a few different ways which we have seen time and time again with bulk sales or simply creating new physical credit cards via placing the data on the magnetic strip. One such restaurant facing these difficulties in 2019 was the Huddle House. The Huddle House, headquartered in Atlanta, is a casual dining and fast food operations. 
Attack
Huddle House was targeted for an attack, which was very successful. They released a statement on February 1st  of the malware infection. The specific system breached was the point-of-sale (PoS) system, just like other retailers, which was infected with malware at various locations. The PoS system was a third party’s. The malware was coded to allow attackers to steal credit card information used by Huddle House’s clients (name, credit or debit card number, expiration date, cardholder verification number, and service code). With this data, you could have a great shopping experience, on someone else’s dime.

Unfortunately the variant of malware was not disclosed. This would have been very useful not only for research purposes, but also for other businesses to learn from. This would include what to watch for, how it worked, etc. 

The malware delivery system was interesting, as the attackers gained remote access by exploiting the 3rd party’s assistance tools, allowing the third party to deploy the malware. This was deployed throughout every Huddle House, but this did make it to an estimated 341 locations. With the malware being spread across all of these locations, the reach was extended every time a client used their credit or debit card. 

This was noticed after a bit of time has lapsed. The infection span was from August 1, 2018 to February 1, 2019. In essence, anyone using their card for the seven months during the infection, their credit card information is probably at risk 
Detected 
Another interesting aspect to this is the Huddle House did not detect the malware or issue. They perceived no indication of an issue. This was however detected by law enforcement and the Huddle House’s credit card processor. Seemingly, the Huddle House would have noticed something in the logs. 
Post-Attack 
After the notification, the investigation began. Initially the business had no idea of how many of their locations were involved or the number of customers affected. They contracted with a third party forensics company and working with law enforcement within 24 hours of becoming aware. 

The business notification was for their client’s to monitor their credit card statements and possibly call the credit card companies to request new cards. While this is helpful, yet obvious, this still created work for their clients now and in the future. 
Lessons (Not) Learned (Still) 
The Huddle House story is much like most other breaches. There is nothing exciting above the other breaches. What does make this a bit more interesting is the attack. The old saying is you are only as strong as the weakest link. This continues to be the case. When a business allows another organization (3rd party) access to their network and/or data, the business is allowing not only the third party into the network, but also the baggage and issues with their system come along for the ride. These likewise have full access to all the 3rd party does, and much more. 

There is a massive retailer, with stores throughout the US, allowing access to third parties to their network. They are allowed to use this authorize access to upload invoices or various other functions. As they connect and log in, any infection they have may be shared with your system. This is the issue facing cybersecurity and supply chain management. While the business certainly has some level of transparency into their network, in general, this is not prevalent with 3rd parties. Gaining access to cybersecurity data for the 3rd parties is difficult as this is new ground for the vendors, and naturally, they don’t want to tell others of their vulnerabilities for fear this information could be accessed by unauthorized parties and exploited. The SOC report, and other reports show, at a certain day in time, what their vulnerable points were. This in the wrong hands could create a large issue. 

As time passes and these requests become greater in number and frequency, the attitude will slowly change. Until then, start and continue to ask for these and put this in our contracts. The business and the 3rh party vendor have to understand this is a vulnerability attack point. If everyone continuing to keep their head in the sand hoping all will be well, all won’t be well. Just ask the national retailer whose AC vendor introduced malware into their system, which breached the PoS system just before the largest, in dollars and people. 

Also, it is notable that the Huddle House had no idea there was a problem...until they received the call. If an estimated 341 sites are affected, and the credit card data is being sent to the C&C servers in small or large blocks of data, it would seem that the cybersecurity team would have been able to look at the log and notice the activity due either to the amount of data or frequency. Granted the data logs can be large, however, that’s why they sell SIEMs and the person can also code a program to parse through this looking for trends. 


Resources 
Abrams, L. (2019, February 5). Huddle house fast food chain suffers data breach in POS system. Retrieved from https://www.bleepingcomputer.com/news/security/huddle-house-fast-food-chain-suffers-data-breach-in-pos-systems/

Cutoday. (2019, February 6). Restaurant chain announces data breach. Retrieved from https://www.cutoday.info/Fresh-Today/Restaurant-Chain-Announces-Data-Breach 

Huddlehouse. (2019, February 1). Important security and personal data protection notification. Retrieved from https://www.huddlehouse.com/data-protection-notification/ 

Muncaster, P. (2019, February). Huddle house suffers POS malware breach. Retrieved from https://www.infosecurity-magazine.com/news/huddle-house-suffers-pos-malware/ 

NNT. (2019, February 5). Huddle house restaurant chain suffers POS malware breach. REtrieved from https://www.newnettechnologies.com/huddle-house-restaurant-chain-suffers-pos-malware-breach.html 

The Paypers. (2019, February 5). Huddle house announces security breach, POS system is affected. Retrieved from https://www.thepaypers.com/digital-identity-security-online-fraud/huddle-house-announces-security-breach-pos-system-is-affected/777240-26 

Wednesday, July 31, 2019

Qakbot: Malware nuance causing headaches!


Malware is a valid, viable tool for attackers. There are the usual variants that have been coded over time. As these are introduced over time, the signature attack became known and the defensive systems know to look for these. The attackers clearly are aware of this and code variants of this malware to evade detection. One such example is Qakbot.
Origins
Qakbot is not a new malware example. This has been around since 2007, making it an old veteran of the computer infection/malware game. While this has been in the environment for such an extended period, it is still a viable attack tool, especially with the nuance as of late.
Operations
This works via propagating with network shares. This was designed to not only disable a node, but also an entire network. This works with multiple components is endeavors. The early variants used the “.qbot” string. This used a single layer of encryption when encrypting the machines.

As time passed, the later variants set the configuration files to hidden. To yet further obscure the files, and folders, this also used random names. To further complicate the host’s workflow, the configuration file’s encryption was doubled.

With this iteration, to infect the client, the attacker may lure the victim to a malicious site, which would host the exploit kit. They also may simply email the special pdf to the victim. As the victim becomes infected, the malware began to detect if the user was visiting a banking or finance related website. Specifically, this malware was coded to detect activity with JPMorgan Chase, Citibank, Citigroup, Huntington Bank, Bank of America, Wells Fargo, 5/3 Bank, Key Bank, PNC Bank, and others.

This was also configured to harvest credentials from Windows machines, Outlook, Windows Live Manager, RDP, and Gmail messenger. If this was not enough, the malware also looked for Internet Explorer’s password manager.
Long-Lasting Malware
In the cybersecurity field, not all malware has such a long, viable life in actually being useful in attacks. With this iteration, there are many components, with each of these functioning differently. A useful update is when it detects being in a VM, the malware uninstalls itself. With this function, it would be substantially difficult for the researcher to reverse engineer the sample or monitor its acts, as it removes itself. The malware isn’t static, offering a difficulty in placing a signature in the AV tools, as the malware is updated as needed from the C&C center. To make itself even more difficult in detecting, the updates are designed to mutate its appearance. At one point in this cycle, 85% of the infected systems were in the US. The primary successful targets were the academic, government, and healthcare industries. This level of penetration was mostly due to its code allowing it to modify itself.

Resources
Cluley, G. (2016, April 16). Mutating qbot worm infects over 54,000 PCs at organizations worldwide. Retrieved from https://www.tripwire.com/state-of-security/featured/qbot-malware/

Dela Torre, J. (2011, September 1). Qakbot: A disaster waiting to happen. Retrieved from https://www.virusbulletin.com/virusbulletin/011/09/qakbot-disaster-waiting-happen

Millman, R. (2019, May 3). Qakbot malware avoids discovery by breaking itself in two. Retrieved from https://www.scmagazineuk.com/qakbot-malware-avoids-discovery-breaking-itself-two/article/153689

Trend Micro. (2011, January 12). QAKBOT: A prevalent infostealing malware. Retrieved from https://www.trendmicro.com/vinfo/us/threat-encyclepedia/web-attack/80/qakbot-a-prevalent-infostealing-malware

Sunday, June 2, 2019

Woesnotgone Meadow; May 31, 2019



All is well here at Woesnotgone Meadow, where everyone has above average bandwidth.
In the Meadow, we certainly play video games. Sometimes by ourselves, other times with our children or grandchildren. We play racing games, zombie games, and many others. We expect to have a great time with this. What we don’t expect is to be a victim of ransomware.

Ransomware
The new ransomware, Anatova, has been detected. This was originally detected by McAfee. The research indicates this was released on January 1, 2019. The ransomware has been noted as infecting others in a private peer to peer networks. This has been analyzed. The ransomware curiously was engineered to be modular in nature. This allows the ransomware to be updated for new functions. This also makes the ransomware more difficult to detect. While this is the case, it has been detected across the globe in Belgium, Germany, France, and the UK, among other European countries.

Code
This version of ransomware was engineered with a slight twist. This does encrypt files just like the other ransomware tools already do. This ransomware also checks for connected network shares and encrypts these files.

It is not known who or what group coded this ransomware. Curiously, the malware does not infect systems located in Syria, Egypt, Morocco, Iraq, and India.

How it Works
 This uses an old social engineering trick/method. Anatova has an icon of a game or application. This fools the user into believing they will be double-clicking on the game. Post-double click, the system shows a request for admin rights. If the user just clicks this for convenience or believes this is a requirement, their (not-so much) fun begins.

This encrypts their system and files, on the PC and servers. The ransomware uses strong encryption, using a pair of RSA keys. The malware retrieves the username of the logged in party and/or active user. These names are compared with default usernames used with sandboxes. If this is found, the ransomware will not work.

Demands
Once the infection is in place and the user has the “uh-oh” moment, the system notifies the user of the ransomware. The system then demands a payment to unlock the files, just as with the other ransomware samples.

Lessons
This is another example of the additional training needed by the staff. There are very limited occasions when downloading a game is required at work. The equipment really should be used for work.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest encryption.

Resources
Allen, D. (2019, January 23). Anatova is a nasty new ransomware that targets gamers. Retrieved from https://www.techradar.com/news/anatova-is-a-nasty-ransomware-that-targets-gamers

Bhatnagar, V. (2019). Anatova ransomware is targeting gamers. Retrieved from http://www.hackbusters.com/news/stories/4297915-anatova-ransomware-is-targetting-gamers

Digital Trends. (n.d.). Latest ransomware targets gamers with a malicious sophistication. Retrieved from https://www.digitaltrends.com/computing/anatova-ransomware-targets-gamers-malicious/

EHacking News.(2019, January 26). Anatova ransomware is targeting gamers. Retrieved from http://www.ehackinghews.com/2019/01/anatova-ransomware-is-targeting-gamers.html

Fire-Ball Cyber Security. (2019, January 26). Anatova ransomware is targeting gamers. Retrieved from https://fireballcybersecurity.blogspot.com/2019/01/anatova-ransomware-is-targeting-gamers.html

Palmer, D. (2019, January 24). New ransomware poses as gamers and software to trick you into downloading it. Retrieved from https://www.zdnet.com/article/new-ransomware-poses-as-gamers-and-software-to-trick-you-into-downloading-it/

Salim, S. (2019, January 25). Alert: Ransomware found in free games and software. Retrieved from https://www.digitalinformationworld.com/2019/01/anatova-ransomware-targeting-gamers-skilled-hackers.html

Scammell, R. (2019, January 23). Watch out for anatova, a new ransomware targeting gamers. Retrieved from https://www.verdict.co.uk/anatova-ransomware-gamers/



Friday, March 22, 2019

Woesnotgone Meadow; March 21, 2019


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Most towns of a certain size have some form of a Chamber of Commerce. Although the Meadow does not have a vast number of businesses, there are quite a few. Jerry is the president and keeps everything running smoothly. Our little municipality has not been targeted for an attack, thankfully. Other Chamber of Commerce departments have not been that lucky. The Ann Arbor/Ypsilanti Regional Chamber of Commerce is located in the southeastern section of the lower peninsula of Michigan. They manage all of the usual tasks a chamber of commerce would.

On January 8, 2019, their computer system was successfully attacked. The attackers used well-known Emotet malware. This iteration allowed the attackers access to customer names, mailing addresses, and emails. The attackers, fortunately, did not have access to banking information, accounts, credit cards, security codes, or passwords.

 Emotet is a curious piece of malware. This is coded to especially evade detection, embed itself into the system and multiply. If the malware detects it is in a sandbox, it is coded to remain dormant. This is also polymorphic, meaning each time it is downloaded, the malware changes slightly, to evade a standard anti-virus signature. As this was designed so well, it is no wonder this is still in use over the last five years.

To remediate the issue, and get the Chamber back up and running, they had to start somewhere. The Chamber began researching what happened with this and on January 24, 2019 sent a notice to its members regarding the successful attack and compromise. In the least, this is an opportunity to learn from this and improve training for the staff. As a reminder, any training does not need to be bland, and not encourage the users to become bored.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Afana, D. (2019, January 24). Malware hits ann arbor/ypsilanti chamber, member information safe, officials say. Retrieved from https://www.mlive.com/news/ann-arbor/2019/01/malware-hits-ann-arborypsilanti-chamber-member-information-safe-officials-say.html

Stockley, M. (2019, January 25). Fighting emotet: Lessons from the front line. Retrieved from https://nakedsecuriyt.sophos.com/2019/01/25/fighting-emotet-lessons-from-the-front-line/


Saturday, January 5, 2019

Woesnotgone Meadow; December 10 2018

Woesnotgone Meadow
December 10, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

The Meadow has a number of people who enjoy asking questions about the various topics seen across the news channels. These persons are not much for introspection. These topics could be focused on technology, farming, or the new coffee crop.
As the residents ask each other these questions, there is also another source for the back and forth question and answer questions.
Quora, the knowledge sharing website, experienced a minor issue this year. Quora was founded in 2009 by two former Facebook employees and is located in Mountain View, CA.
Compromise
The compromise was manifested by the unauthorized access to one of the Quora systems, discovered on November 30, 2018. There is not a mass amount of information regarding the attack vector or method for others to learn from. Only the general actions were noted. Quora has noted their teams believe they have found the root cause for the breach, and allegedly have taken the appropriate steps to address the issue. The investigation though is still on-going.
Affected Users
This was not a small, incidental compromise. This affected approximately 100M of the Quora users. To remediate this, the company logged out the potentially affected users. Quora also contracted with a leading digital forensics and security firm to assist them with the investigation.
Data Exfiltrated
The attackers were able to secure data from Quora for their uses. This included the name, email address, encrypted password, and user imported data from the linked websites. These were expected to be Facebook and Twitter. The attackers also were able to secure details on the user’s non-anonymous activities on Quora (e.g. questions, answers, and up- and down-votes). Although this data was stolen, most of the data would have been accessible publicly.
As noted, the passwords were encrypted. Seemingly, this would be the perfect situation. Quora however did not detail the format of the encrypted passwords. This could have been weak. These could have been hashed instead, however, this could have been weak or without being salted.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Acharya, B. (2018, December 3). Quora says 100 million users hit by security breach. Retrieved from https://www.reuters.com/article/us-quora-cyber/quora-says-100-million-users-hit-by-security-breach

Woesnotgone Meadow; 12 11 2018

Woesnotgone Meadow
December 11, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Most people in the Meadow enjoy the occasional donut at Margie’s Donuts. In between the convenient space on Main Street, the company, and heavenly scents from the kitchen, people come and go. People have the option of paying with cash, or credit card. Margie just started an awards program for the clients who purchase a dozen at a time.
That reminds me; Dunkin’ Donuts has a reward program also (DD Perks). This service had an issue recently.

Secondary Risk with Compromise
 There are a vast number of compromises with the different industries and varied number of affected users. The range of affected parties may vary greatly from hundreds to hundreds of millions. Nearly all the compromises have a common thread. The breach and compromise yield data for the attackers and these have very usable data (e.g. username and passwords for the respective company). Clearly this is bad for the client or user, however, there are longer-term effects for them also. There is the temporary loss of revenue, sales, and fines. Other areas more difficult to measure may be loss of standing in the community, and market share.

The attackers use this data in various ways. One in particular is to take the login data and attempt to use this with other login portals at other companies. This is a popular and surprisingly efficient attack due to the users tending to reuse their passwords and usernames with other web portals. This is easier for them, and unfortunately, also for the attackers. This works with Attacker A using the credentials from other breaches to try and access the users accounts. The attackers may know what these are, or create a list from an educated guess. The attackers, in substance, are stuffing the credentials used for one website into another. This process, if manual, would take a significant amount of time, dependent on the target. With this, however, being automated, and adjustable, this is an efficient attack. As for the adjustments, if Dog1 were to fail, the system could modify this password guess to Dog2, Dog3, etc. This attack has become more notable in the news recently.

Data Security Breach
The breach was discovered on October 31, 2018. Dunkin’ Donuts communicated the issue to its customers involved with the DD Perks program. The unauthorized third party had accessed the DD Perks system without authorization. The third parties had used the client’s usernames and passwords to log into their accounts. This data was acquired through other company’s security breaches. The attackers were able to automate the attack. The successful account manipulation was done through this credential stuffing. Dunkin’ Donuts were notified of the issue by one of their security vendors. It is notable that most of the attempts were not successful.

Data
The data would vary for each user. This was due to the clients sharing different data, based on their comfort level. In general, the minimum data accessed would have been their first name, last name, username, 16-digit DD Perks account number, and the DD Perks QR code.

Remediation
Dunkin’ Donuts forced a password reset for the customers. They also replaced the DD Perks account number, along with working with law enforcement.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
CBS Philly. (2018, November 2). Dunkin warns customers of data breach. Retrieved from https://philadelphia.cbslocal.com/2018/11/28/dunkin-warns-customers-of-data-breach/
Cimpany, C. (2018, November 29). Dunkin’ donuts accounts may have been hacked in credential stuffing attack. Retrieved from https://www.zdnet.com/article/dunkin-donuts-accounts-may-have-been-hacked-in-credential-stuffing-attack/
Dunkin’ Brands. (2018). Security update. Retrieved from https://www.dunkindonuts.com/content/dam/dd/pdf/Security_Update.pdf
Jimenez, T. (2018, November 29). Dunkin’ donuts to data breach affects DD perks members. Retrieved from https://kywnewsradio.radio.com/articles/news/dunkin-donuts-data-breach-affects-dd-perks-members
O’Laughlin, F. (2018, November 29). Dunkin’ warns customers of data breach. Retrieved from https://whah.com/news/dunkin-warns-customers-of-data-breach/

6abc. (2018, Novembe 28). Dunkin’ donuts warns customers of data breach. Retrieved from https://6abc.com/technology/dunkin-warns-customers-of-data-breach/4785174/

Friday, January 4, 2019

Woesnotgone Meadow; December 9, 2018

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, we have the usual life events for the residents. These include birthdays, anniversaries, occasional weddings, and other events we publish in the Gazette. Our local jeweler, Margie’s Bling, is our main source for gifts given with an open heart for these occasions. A recent issue with Jared and Kay Jewelers showed the Meadow there can be issues even with a simple jewelry purchase.  

Data leaks are occurring at a greater rate than in prior years. The individual leaks themselves appear to be allowing more data to escape. The combination of this tends to be a bit scare and a rather significant, growing issue. On the bright side, these tend to be remediated rather quickly on average. The data are not all handled in the same manner though. When these are not fixed immediately, the user’s data may be present to be exfiltrated and used or sold.

Related to this, Jared and Kay Jewelers had a bit of an issue. When a customer purchases the jewelry online, they have the option to have the receipt emailed to them. This is handy and may be a benefit. The client receives a link in an email for this receipt. The attack focusses on the link. After the attacker was to post the modified link in the web browser, they were able to access another client’s data (e.g. name, billing and shipping addresses, email address, phone number, the items ordered, total cost, tracking link, delivery date, and last four digits of the credit card number). All of this would be very useful and marketable on the dar web. The attacker could also use a quicker, more direct method to be unjustly enriched. They could complete an automated search for packages within a driving distance of their location. Any packages being delivered in the future could be picked up by the unauthorized person after delivered and prior to the recipient actually picking up the package from their porch.

They could also social engineer the business since they know all of the relevant information the customer service representative would ask. They could also social engineer the client, with the same information used for the prior attack. A simpler attack would involve the plain phishing attack for all the clients the data had been gathered on.

Jared’s parent company, Signet Jewelers, was notified of the issue. This problem only affected the Jared and Kay Jewelers client, not the other entities owned by Signet Jewelers (Zales and Piercing Pagoda). After a few weeks, there was no resolution to the issue. KrebsOnSecurity was contacted in mid-November 2018. At this point, Signet Jewelers thought it was pertinent enough to address. The CISO noted the issue was fixed for the future orders at that point. They did not understand the issue also applied to past orders. This was later fixed. The issue was with the coding not taking cybersecurity into account.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Bradley, B. (2018, December 3). If you’ve ordered jewelry from these sites, your information may have been exposed. Retrieved from https://www.komando.com/happening-new/516632/jared-kay-jewlers-data-leak

Krebs, B. (2018, December 3). Jared, kay jewelers parent fixes data leak. Retrieved from https://krebsonsecurity.com/2018/12/jared-kay-jewelers-parent-fixes-data-leak/