CYFIRMA’s Do you remember series!!-Snippets from Cyber Threat and Risk Predictions for 2019

AUTHOR

CYFIRMA

 

TOKYO/SINGAPORE, Dec 6, 2018:

CYFIRMA’s Do you remember series!!

Here’s today’s snippet of CYFIRMA ‘s Annual report and Cyber Threat and Risk Predictions for 2019:-

As we enter 2019, cyber-attacks and breaches will continue to increase in intensity and frequency. Based on CYFIRMA’s research, the following trends and shifts will take precedence:

o Hackers will unleash rejuvenated attacks by leveraging emerging technologies: In 2019, threat actors will show a greater affinity for emerging technologies by exploiting them handsomely. Multi-pronged cyber-attacks will be operationalized with increased usage of AI/ML. This will lead to breaches in humanoid systems alongside block-chain ecosystems and other autonomous systems.


CYFIRMA’s detailed cyber threat intelligence insights are what organisations and institutions need

CYFIRMA’s cyber analytics platform demonstrated its predictive capabilities by releasing 16 Early-Warning Threat Reports detailing imminent cyber threats to various technologies, across organizations, industries and countries, out of which 11 to date are active threats in the wild.


CYFIRMA’s Predictive and Prescriptive Cyber Threat Intelligence is UNPARALLELED

Read further @ https://medium.com/@cyfirma/cyfirmas-cyber-threat-and-risk-prediction-for-2019-128e0f4a179

CYFIRMA’s Cyber Threat Intelligence leverages the latest technologies, analytical methodologies and calibrated tools to future proof the organization’s cyber-security posture.

Reach out to us!!

#cybersecurity #cyberdefence #cyfirma #intelligence #predictive #relevant #prioritized #cyber #cyberwarfare #ciso

Do you remember!! – CYFIRMA – Medium

AUTHOR

CYFIRMA

 

Do you remember!! CYFIRMA has released its annual report and Cyber Threat and Risk Predictions for 2019. Here’s a snippet:-

“While 2018 was a year of financially motivated threat actors having a free run against individuals, organizations, institution and countries, we have noticed an increasing trend of state sponsors interested in arming threat actors to pursue defined geopolitical objectives. Cryptocurrency exchanges, healthcare companies, the energy sector, and traditional financial institutions were at the brunt of cyberattacks this year. What has been very interesting to witness is the shift in the hackers’ intention to use emerging technologies, increasing the difficulty to defend an expanding attack surface.”

Read further @ https://medium.com/@cyfirma/cyfirmas-cyber-threat-and-risk-prediction-for-2019-128e0f4a179

CYFIRMA’s PREDICTIVE, RELEVANT & PRIORITIZED Threat intelligence serve as a radar to detect malicious intentions before D-day by picking up conversations at the source- deep/dark web and other such platforms, thereby helping companies restructure their cybersecurity posture to correct vulnerabilities that will otherwise be exploited by persistent threat actors.

Reach out to us!!

#cybersecurity #cyberdefence #cyfirma #intelligence #predictive #relevant #prioritized #cyber #cyberwarfare #ciso

Last week a US based hospitality giant disclosed a breach of the reservation database of one of…

AUTHOR

CYFIRMA

 

Last week a US based hospitality giant disclosed a breach of the reservation database of one of its key properties, involving the hack of personal data belonging to over 500 million customers. Breaches of this kind highlight the fallibility of companies that are ‘reactive’ rather than ‘proactive’ when it comes to cybersecurity. With CYFIRMA’s Cyber Threat Intelligence, organizations can intently engage evolving threats rather than react to confirmed hits.

CYFIRMA’s approach includes listening into hacker conversations on the deep/dark web, and similar forums. Such nuances ensures that the organizations stay atop their specific IT environment, plug vulnerabilities, while data and reputations are left intact. Adding credence to this routine is the revelation from the reported breach that the hack originally began in 2014 and remained undetected until now. Hackers had avoided detection from one of the most affluent hotel chains in the world, for years, and siphoned off heaps of personally identifiable data.

CYFIRMA’s Cyber Threat Intelligence, detects the development/deployment of such threats before D-day, while PREDICTIVE, RELEVANT & PRIORITIZED insights help companies restructure their cybersecurity posture to plug exploitable vulnerabilities.

#cyfirma #threatintelligence

https://www.linkedin.com/feed/update/urn:li:activity:6475548321674031104

CYFIRMA’s Cyber Threat and Risk Prediction for 2019

AUTHOR

CYFIRMA

 

TOKYO/SINGAPORE, Nov 28, 2018: CYFIRMA releases its Cyber Threat and Risk Predictions for 2019.

Kumar Ritesh, CYFIRMA Chairman and CEO says “While 2018 was a year of financially motivated threat actors having a free run against individuals, organizations, institution and countries, we have noticed an increasing trend of state sponsors interested in arming threat actors to pursue defined geopolitical objectives. Cryptocurrency exchanges, healthcare companies, the energy sector, and traditional financial institutions were at the brunt of cyberattacks this year. What has been very interesting to witness is the shift in the hackers’ intention to use emerging technologies, increasing the difficulty to defend an expanding attack surface.”


Mr. Kumar Ritesh highlights the growing space for Cyber Threat Intelligence in 2019, and beyond!

CYFIRMA’s cyber analytics platform demonstrated its predictive capabilities by releasing 16 Early-Warning Threat Reports detailing imminent cyber threats to various technologies, across organizations, industries and countries, out of which 11 to date are active threats in the wild.

As we enter 2019, cyberattacks and breaches will continue to increase in intensity and frequency. Based on CYFIRMA’s research, the following trends and shifts will take precedence:

o Hackers will unleash rejuvenated attacks by leveraging emerging technologies: In 2019, threat actors will show a greater affinity for emerging technologies by exploiting them handsomely. Multi-pronged cyberattacks will be operationalized with increased usage of AI/ML. This will lead to breaches in humanoid systems alongside blockchain ecosystems and other autonomous systems.

o Tokyo 2020 Olympics will be a prime target for threat activities: Countries that are antagonistic to Japan will target the upcoming Tokyo Summer Olympic Games to cause reputational damage. The fact that these games will massively leverage on new-age technologies and digitalization will serve as a beacon for malicious actors.

o State-sponsored/ corporate-sponsored espionage will take centerstage: The next leg of the global trade wars will be fought online- involving state sponsored actors and intelligence agencies initiating corporate cyberattacks. In 2018, the North Korean, Chinese and Russian state-sponsored attacks on nations and organizations have made global headlines. In 2019, additional countries will join the fray in a bid to highlight their own political power and technological might to meet their proxy objectives.

o Hackers will place the highest value for personal behavioral data: Threat actors will exponentially leverage social engineering techniques to attack and mine behavioral data from individuals, societies, organizations and nations. Malicious actors will identify potential targets, recruit them inconspicuously, and exploit their access levels to penetrate government or corporate target systems in a seamless and highly camouflaged operation.

o Cloud security will be repeatedly attacked for vulnerabilities: In 2018, AWS and Azure cloud assets were a favorite target for hackers’ intent on disrupting the public cloud security layer to unearth an assortment of individual and corporate data. In 2019, this trend will continue as hacker communities reiterate their inclination to this favorite prize. Unfortunately, most organizations are still not trending towards employing a comprehensive security policy for their cloud-based data assets and footprints, inadvertently playing into the hands of these threat actors.

o Internet of Things (IoT) must contend with the hackers’ curiosity: In 2018, as many as 10 new variants of the infamous Mirai botnet were discovered, each employing the old attack vectors. Almost every IoT product manufacturer has exhibited device vulnerabilities, yet this industry is booming away. In 2019, renewed variants of legacy threats will be unearthed, and coupled with the lack of standardization amongst the manufacturers of IoT devices, cyberattacks on IoT sensors is going to ramp up at a never seen before scale. Further possibilities include, IoT weaponization, centralized collection units, and transaction ecosystems to support it all.

o Identity Theft will be an extremely common phenomenon: Globally, both individual and business data will continue to suffer enormous breaches courtesy of privileged attack vectors. Identity theft, as always, will continue to be the mainstay campaign for threat actors who will now intently look towards the east for their exploits. In 2019, expect Asia, and especially Japan, to be severely tested by this problem, almost on a daily basis.

o Multihomed malware attacks on the rise: In 2019, multihomed and multi-magnitude variants of crypto malwares, variety of banking trojans, ransomwares, etc. will expand into some of the biggest challenges to be faced by the cybersecurity professionals. 2018’s examples of SamSam and GandCrab, behavior mapping malware that showed uncanny adapting and evolution skills on the target system whilst mimicking legitimate software, offers some insights into what’s coming up in 2019, and beyond!

o Hackers will be drawn to the vulnerabilities posed by Supply Chain Systems: The latest trend is supply chain attacks with embedded malware. In 2019, increasing number of attacks impacting corporate strategies and supply chain systems are anticipated requiring additional layers in cybersecurity strategy and policy considerations. This could be the first of many upcoming corporate attack strategies by way of supply chain systems.

o DDoS attacks will not lose its potency or applicability: Distributed Denial of Service (DDoS) has always been a favorite with threat actors and the affection is only going to grow in 2019. Attributes such as the low campaign cost and associated rewards will continue to inspire hackers to plot and deploy DDoS attacks. Japan is and will continue to be one of the top 10 countries to be targeted by DDoS outbreaks.


The work is cut out: Modern industrial and business domains have a lot of catching up to do when it comes to cybersecurity, as highlighted by CYFIRMA’s Cyber Threat and Risk Predictions for 2019.

o GDPR based theft will gain the organizations’ undivided attention: In 2019, with organizations needing to adhere with GDPR, they are exposed to any non-compliance related eventualities. One of the facets being fines dished out for not complying, thus opening up avenues for hackers to exploit remediation and regulatory procedures. Data being playing field worth billions of dollars, even a small attack could cost organizations as hackers see opportunities to earn millions.

o AI and ML will power the next salvo of cyberattacks: As high as 70% of the companies will encounter botnet attacks with a flavor of AI/Machine Learning in the immediate future, with the cost of restitution running into an estimated USD 0.4 M per company. CYFIRMA’s research highlights the changing composition of these attacks- multi variant, altering behavior and multi-intent being the common signatures.

o State-sponsored cyberattacks on critical infrastructure will be the norm: Operational technologies like PCI, HMI, Control and Workflow Systems will be high on the cybercriminals’ bucket lists. CYFIRMA’s research has indicated that threat actors are developing new attack methods featuring complex malwares to accomplish tasks such as passive asset discovery and control instruction hijacking.

o The most common attack vector will continue to be Social Engineering and Phishing/Smishing: In 2019, organizations will finally figure out that employees are the weakest link in their cybersecurity posture. This will likely lead to the reassessment and redefinition of core internal security strategies, as the fact that the most prevalent attack vector isn’t the network, but the user becoming part of the conventional threat landscape.

o Cryptocurrency exchanges and trading platforms will need fortification: As institutional capital progressively flows into the cryptocurrency market, thefts will correspondingly increase. The growing necessity for cryptocurrency mining will lead to renewed attacks on mining resources and unsuspecting victims. Already, the Japanese cryptocurrency exchanges and trading platforms have enticed great interest from hackers based out of China, North Korea, Russia and Ukraine. More are likely to follow suit, soon!

Kumar Ritesh reiterates that “the cybersecurity landscape of Japan and South East Asia is changing dramatically, due to the aggressive involvement of state-sponsored hackers and an expanding attack surface. Nations will also continue to acquire and build their cyber warfare capability to strengthen their national interests. Digital proliferation will continue to outpace the speed with which defense mechanisms are being invented and applied to protect emerging technologies. Organizations need to balance the need for new technologies to enable business efficiency, expansion, and flexibility while defending against the increasing complexity and variety of new attacks created by emerging technologies.”

There’s more from where this came from. Follow us on Twitter, LinkedIn and Facebook and be in the know.

CYFIRMA Threat Update: The return of the Emotet malware!

AUTHOR

CYFIRMA

 

The Emotet malware is back. First reported across Europe in 2014, this sneaky banking Trojan has made a career out of evolving in line with current technologies and security systems. Now, concealed as emailed Thanksgiving greetings for employees or communication from financial institutions, Emotet is back with a new plugin. In recent attacks, this plugin was spotted siphoning off email subjects and about 16 KB off the email body.


The 2018 attack pattern of the Emotet malware

As threat actors evolve their methods, companies need to evolve their cybersecurity responses too. Active tools, like CYFIRMA’s cyber threat intelligence, is forever scanning the deep/dark web and other such forums for the slightest hints of a new malware, or the recycling of an old threat. Further, PREDICTIVE, RELEVANT & PRIORITIZED insights help companies correct and beef up their cybersecurity posture.

Emotet’s latest feature will allow for the creation of better phishing templates. Meanwhile, cyber threat intelligence would have foreseen this development and identified the chinks in the company’s cybersecurity posture that would need corrections. CYFIRMA’s tactical intelligence represents the cutting edge of cybersecurity initiatives today and is based on the complete understanding of the specific threats to specific industries and IT environments.

Looking for regular information about evolving cyber threats? Follow us on Twitter, LinkedIn and Facebook and be in the know.

CYFIRMA at the CSSC: Cyber Threat Intelligence for Japan, and beyond

AUTHOR

CYFIRMA

 

CYFIRMA would like to thank all the participants at the Control System Security Center conference (CSSC). It was an engaging and insightful discussion for the participants where CYFIRMA covered:

  • Trend of cyber threats on Critical Infrastructure and Industrial Control Systems.
  • Key issues and vulnerabilities we have seen in Operational Technology.
  • Current threat landscape of Japanese Critical Infrastructure and Industrial Control Systems.
  • What do we do at CYFIRMA and how we are helping organization with our Predictive Cyber Threat Intelligence.


CYFIRMA CEO, Kumar Ritesh, explaining the nuances of predictive cyber threat intelligence at the CSSC

Want to know more on how CYFIRMA can make a difference to your cyber security posture using Predictive, Relevant and Prioritized Threat Visibility and Intelligence, reach out to us!!

LinkedIn | Twitter

CYFIRMA Insights: Why Cyber Threat Intelligence is a Crucial Cybersecurity Tool in 2019?

AUTHOR

CYFIRMA

 

Cybersecurity will be a key corporate agenda in 2019. Globally, businesses have woken up to two game changing realizations in recent times:

1. The World Wide Web is a potent platform to generate brand recognition, streamline business and accentuate profitability.

2. Online threats in the form of malware poses a serious question to a business’s online infrastructure and offline credibility.


Cyber Threat Intelligence will lead a majority of the cybersecurity conversations in 2019, and beyond!

In this context, how can businesses stay a step ahead of these highly inventive and resourceful threat actors? The answer is cyber threat intelligence. As a brand, CYFIRMA’s primary differentiator is in its ability to listen into hacker conversations from the deep/dark web and other online forums that are frequented by malicious actors. Herein, CYFIRMA picks up the first hints of a malware in development, an obscure threat that is being rejuvenated and the specific domains and vulnerabilities that are being targeted. In simple terms, an informed heads-up!

By understanding the threat actor’s manifesto and gleaning the obvious and latent loopholes in a company’s cyber architecture, CYFIRMA can powerfully deploy cyber threat intelligence to identify and keep the threat of incoming attacks at bay. Predictive intelligence allows CYFIRMA to pick-up the most ambiguous threat signatures and associate them to known or masked vulnerabilities.

Breaking the cyberattack code in 2019

Threat actors are increasingly developing new tools and methodologies to attain their malicious targets of far reaching cyberattacks while remaining totally anonymous. At the other end of the spectrum, cyber defenders cannot afford to have just canned responses for every emergent threat event. The need is to anticipate an event before it actually happens.

In 2018, we witnessed a number of high profile data breaches involving some of the top companies on the planet. Facebook’s March disclosure of over 90 million compromised user profiles, athleisure giant Under Armour’s admission to the breach of 150 million users’ data through its compromised fitness app, are some of the prominent cyberattack instances amongst a string of regular occurrences across the world. And, by the looks of it, hackers are developing their malicious tools at an equivalent rate to how companies are setting up sophisticated cybersecurity solutions.

CYFIRMA’s core competencies lie in designing customized solutions that take into consideration a client’s specific security makeup. Identifying vulnerabilities that could be exploited by a resourceful threat actor allows the client to plug away the obvious landing points for the attack. Next, the intended victim is apprised of the various tell-tale signs of an impending cyberattack.

The success of an average cyberattack event is heavily dependent on the element of surprise. Most serious malware attacks propagate through entire systems in record time before they can be contained. Cyber threat intelligence ensures that this element of surprise is neutralized right out of the gate. Minus the strategic advantage, the threat actor is rendered ineffective and easily manageable.

The CYFIRMA advantage: PREDICTIVE, RELEVANT & PRIORITIZED insights

As cybersecurity gains a prominent spot in the company’s overall business strategy, thought leaders will have to zero-in on the solution that works best for their individual system. However, clear advantage will obviously nestle with those who are assertive, innovative and take the initiative, rather than just be reactive to a threat incident.

Cyber threat intelligence affords companies this advantage. By listening in to grassroot conversations over the deep/dark web and other such platforms, CYFIRMA pinpoints with a high degree of certainty the exact timelines when malicious tools are being developed, or deployed, and the profile of domains and business sectors that are likely being targeted. Further, the report specifies best practices and fixes that will plug targeted vulnerabilities and save the intended victim from costly damage control manoeuvres at a later date.

In Summation: It’s a matter of when, not if!

Threat actors are getting bolder and the tools of their trade are getting more sophisticated by the day. Additionally, malicious entities like malware and viruses do not differentiate, rather a modus operandi resembling a typical carpet-bombing run ensures that vast business segments will be impacted through a single, well-coordinated outbreak. Unfortunately, mainstays like firewalls and anti-virus programs offer little resistance against such evolving threats.

But, the cavalry does march in to the rescue. In cyber threat intelligence, companies will find a new-age approach to cybersecurity that is in sync with the modern business world’s evolving need for data protection and process management. And, in CYFIRMA, an experienced partner to help reconfigure the company’s core cybersecurity posture.

Sounds like a plan? Let’s take the conversation forward.

CYFIRMA’s Cyber Awareness Series: Consumption of Cyber Threat Intelligence

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

Effective consumption of Cyber Threat Intelligence plays an important role in the integration of threat intelligence program into an organization. To better prepare and protect against imminent cyber-attacks, organizations need to look at the application of threat intelligence to its strategy, governance, process, procedure, controls, and people.

Here is our attempt to define how Cyber Threat Intelligence should be applied and processed at THREE levels i.e. Strategic, Management, and Tactical.

For each level of intelligence, we have defined:

Time Horizon: Minimum review frequency

Consumer: Who should consume threat intelligence within an organization

Impact: Which elements of a process should be reviewed based on threat intelligence

Decision Point: What should trigger the review process

Interrogatives: Which level of threat intelligence provides answers to who, why what, when and how

Cyber Kill Chain: Narratives of each level of threat intelligence mapped to cyber kill chain

THREE level of Cyber Threat Intelligence:

Strategic: Risk-weighted threat intelligence applied to an organization’s overall business strategy enhancing its ability to proactively and continuously optimize the security posture based on its risk profile

Strategic intelligence should enable organizations to perform:

・ Identification of active and imminent threats, risks to the organization’s industry and brand

・ Determination of cyber risk profile and mitigation actions

・ Prioritization of cybersecurity investments and initiatives based on risk to critical people, processes and technologies

・ Qualification of cybersecurity risks relevant to the organization

・ Optimization and maintenance of the organization’s security posture

Management: Integrate insights on threat actor campaigns, attack mechanisms, and tools into the organization’s internal policy/processes for Cyber incident response, patch management, configuration management, release management, etc.

Management intelligence should enable organizations to perform:

・ Implement reliable and effective decisions for security processes, policies, and response

・ Assess the organization’s attack surface, threat, and vulnerabilities

・ Improve and maintain the efficacy of security controls

・ Updates to the organization’s overall risk register, including risk prioritization

・ Update information security compliance matrix based on threat actor profile, method, and activities

Tactical: Proactively respond to cyber threats, support detection and response to improve organization’s cybersecurity posture by using malicious IP, malware signatures & mutex, phishing domains, botnet command and control centers

Tactical intelligence should enable organizations to perform:

・ Formation of correct rules and policies to blacklist, detect and restrict malicious traffic

・ Detect infiltration and system infection

・ Detect, contain and remediate threats

・ Prevent phishing emails from reaching end-users

・ Protection against sensitive data leak

・ Application whitelisting/blacklisting

・ Real-time updating of AV malware signatures

・ File integrity, desktop/endpoint monitoring

CYFIRMA’s Cyber Awareness Series: Cost of security controls, implementation time, resource requirements, and review cadence

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

Cybersecurity Economics: While difficult to calculate the ROI of security controls, the damage caused by its absence can be catastrophic. Organizations must:

– Balance the critical drivers for installing effective security controls in an organization: cost, time and resources required for implementation, maintenance and a regular review cycle.

– Target the controls at People, Processes, and Technology as the critical parameters determining the design and operational effectiveness of the security controls.

Here’s our view on:

・ Security control costs

・ Implementation time

・ Resource requirements

・ Review frequency of control logs and configurations

While there is no fit-for-all approach as customization will be required based on strategic goals, risk tolerance, budget, organization size, user and site spread, and business complexity-our suggested approach to implementing an effective security controls program is universal.

Early Warning: CYFIRMA has detected Tokyo Olympics 2020 themed spear phishing and SMS/text-based smishing campaign

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

CYFIRMA’s cyber intelligence research center has discovered a potentially new Tokyo Olympics 2020 themed spear phishing and SMS/text-based smishing campaign.

Olympics events have always attracted the attention of a broad range of threat actors, ranging from the ones seeking notoriety to state-sponsored agents seeking to harm the reputation of the host nation by disrupting key infrastructure and services. Additionally, there is an increasing number of financially motivated cybercriminals who seek to profit from selling counterfeit tickets or distributing ransomware through phishing campaigns to unsuspecting recipients. Even though the 2020 Tokyo Summer Olympics is expected to be a memorable sporting and cultural display, the true convergence of sportsmanship and digital innovation, this event is increasingly attracting the participation of threat actors who also want to make their mark on one of the world’s greatest and most public event.

MOTIVATION:

The Tokyo Olympics 2020 Themed Spear Phishing/Smishing Campaign analysis indicates that threat actors are seeking to exfiltrate data including Personal Identifiable Information and even bank login details. Financial gain appears to be the prime motive of these threat actors. Their secondary agenda, however, appears to be causing reputational damage to the host nation and specific target enterprise through successful Business Email Compromise (BEC) and conversation hijacking attacks.

SPEAR PHISHING CAMPAIGN:

Our analysis suggests that the spear phishing campaign appears to be part of a broader Business Email Compromise (BEC) and conversation hijacking attacks. As part of this campaign, we suspect threat actors intend to send customized phishing emails to targeted enterprise users, offering free tickets to the 2020 Tokyo Olympics and misleading unwitting users into clicking malicious links. Additionally, in their endeavor to ensure a higher hit rate, hackers have been orchestrating to run a false advertisement, offering a US$600 gift hamper to ‘lucky’ participants.

A significant part of the hacker discussions focused on implanting data stealing or interceptor malware executable, delivered via email attachments or downloaded through malicious links clicked by the unsuspecting user.

Following are the details of the Spear Phishing Campaign Mails:

・ Fake-Sender Email Addresses which might be used to send malicious phishing email:

wintickets@tokyo20yelo[.]com

freetokyo2020@oci-tokyo2020[.]com
event2020live@gmail[.]com

freetickets[.]tokyo20@outlook[.]com

freetickets[.]tokyo20@gmail[.]com

・ To: Employee/contractor in the organization

・ Subject: Free Tickets To Tokyo Olympics (Fun) or Free Tickets Olympics

・ Potential fake URLs which might be leveraged by attackers as part of the spear phishing emails to dupe users:

www[.]kennicwa-tokyo2020.io/bolde12[.]exe

www[.]ticket-sales.com/index[.]htm

www[.]20gamestokyo[.]net/emp[.]asp

http[:]//livetokyo2020[.]net/media-ch[.]asp

http[:]//freeloaderstokyo[.]com/fill-form[.]html

Potential malicious payload, which can search the compromised end-point for sensitive data and exfiltrate to the remote hacker-controlled Command and Control Server.

Suspected Outlook 2013 and 2016 address book stealing malware

363866ac0141d2f0d6e38703ec085c6c

2139c711f37a62a60f4d7e7d23b84168

・ Suspected Interceptor malware

0b262b2d4620be8362ce951b9a6371dd

SMS/TEXT BASED SMISHING CAMPAIGN

CYFIRMA’s cyber intelligence research center has also observed threat actors discussing malicious links being delivered to users via a SMS/Text based smishing campaign. Cyber-criminals are suspected of delivering fake URLs to unsuspecting users. These URLs are offering the same free tickets to Tokyo Olympics 2020 or a chance to win US$600 gift hampers upon completion of registration post clicking these URLs.

Following are the details of the Smishing Campaign Messages:

・ SMS Details: Unknown at this stage

・ Originated from: Unknown at this stage

・ Potential fake URLs which might be leveraged by attackers as part of the smishing campaign to dupe users:

www[.]ticket-sales[.]com/index[.]htm

http[:]//freeloaderstokyo[.]com/fill-form[.]html

http[:]//tokyogames[.]net/contact-bankdetails[.]htm

http[:]//2020tokyogame[.]cn/gtui/gifthamp[.]js

MITIGATION MEASURES:

・ Block IOCs (Indicators of Compromise) such as malicious URLs, IP Addresses, SHA fingerprint, Hashes under firewalls, proxies, endpoint, spam and phishing security control

・ Apply appropriate anti -phishing and spam control with stringent email policy

・ Do not open emails or URLs from untrusted sources. Always verify sender email address before opening any emails coming from a source outside the organization

・ Be careful while clicking on the link mentioned in the emails/SMS.

・ Establish a Cybersecurity Awareness and Training (CSAT) Program and run regular checks, educate employees to download applications from trusted Appstore only

・ Implement Network Segmentation-Limiting communication between services and systems on the organization network level helps contain an infection and keeps a malware or a persistent threat from spreading

・ Configure Anti-Virus/IDS (Intrusion Detection System) repositories with the identified hash signatures associated with the threat to protect all endpoints

・ Build an APT-IR strategy, which is agile and proactive, keeping in mind business goals and priorities

CYFIRMA’s Cyber Awareness Series: 2018-19 Prioritized Cyber Security Controls

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

Cybersecurity is a journey, not a destination; where cybersecurity controls have been traditionally defined as safeguards to protect, avoid, detect and respond to cybersecurity risks. However, the modern-day needs require cybersecurity controls to be more-continually evolving and adapting to a by-the-minute changing threat environment.

Organisations need to have a cybersecurity controls roadmap to integrate the right, effective and efficient cyber controls applied at the people, process, and technology layers of an enterprise to have the best chance of achieving an optimized security posture.

Here’s our view on the 2018-19 prioritized set of cybersecurity controls staggered in 3 stages:

01 Build foundation cybersecurity controls (12 months)

02 Improve by adding layered defense at people, process, and technology (18-24 months)

03 Optimize to drive efficiency (24-36 months)

Early Warning: A New GDPR Non-Compliant themed phishing campaign noticed in dark web

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

CYFIRMA’s cyber intelligence research center has discovered a potentially new GDPR Non-Compliant themed phishing campaign which distributes a Data Stealing malware in an attached infected Word document zip file. After the malicious file is executed, it then downloads an executable (AssessGDPR.exe) that enables the attacker to exfiltrate data from the infected system.

Our analysis points to a yet-to-be-named Eastern Europe or Russian threat actor group connected to this phishing campaign.

This campaign is being directed towards the following industries:

Financial and Insurance, FMCG, IT Services, Appliances and Business product, telecommunication, electronic and consumer goods companies.

Indicators of attack and compromise:

Our analysis indicates that the attackers will use a carefully scripted phishing email attempting to exploit a user’s susceptibility to GDPR non-compliance issues, demanding immediate actions to be undertaken by the target organization. The email will have a Zip file with the filename “[GDPR instructions.doc.zip]” as an attachment containing a malicious macro allowing the attacker to communicate with its remote server, triggering the download of the data-stealing malware in the form of an executable file: “[AssessGDPR.exe]”

1. GDPR Instructions.doc is a Microsoft Word document attached to the phishing email containing an embedded macro allowing the hacker to read contact details from the user’s address book and search for documents with confidential and sensitive keywords, and then further downloads a second malicious executable file, AssessGDPR.exe.

2. AssessGDPR.exe is data-stealing malware which once installed on the target system, exfiltrates data to the attacker’s command and control server. A visual prompt of “You are Compliant” is displayed to the user after the file is executed. Attackers use these common diversion techniques to distract the attention of the user while the malicious activities on the target system are being undertaken in the background.

Fake Sender Email Addresses which might be used to send malicious phishing email:

nochange@gdpr-rules2018[.]com

actnow@gdrpupdate[.]co[.]uk

non-compliant@cyber-risk2376[.]net

emea-gdpr@euro[.]com

GDPRCompliance@boker[.]net

GDPR-check@eurp[.]co[.]uk

non-compliant@cyber-risk2376[.]net

nochange@gdpr-rules2018[.]com

Potential fake URLs which might be leveraged by attackers as part of the phishing emails to dupe users:

http[:]//compliancechecker-gdpr18[.]com

www[.]gdpr-maker[.]com

www[.]avoid-gdpr[.]co[.]kr

http[:]//gdpr-lockdown[.]com

www[.]gdp-1844[.]net/publish[.]asp

www[.]cyber-risk2376[.]net/validatenow[.]exe

http://checkitnow18[.]net/gdrp-check[.]exe

www[.]gdrp-2018-compliant[.]co[.]uk/18form-updat[.]xls

C&C IP addresses can be used to send the phishing emails, facilitating download of malicious executable and sensitive data collection from infected systems:

77.94.35.168

210.52.109.22

77.94.35.131

77.94.35.168

193.206.239.215

Potential malicious payload, which can search the compromised end-point for any document marked as ‘confidential’ and ‘sensitive’ and exfiltrate email address book.

Suspected Data exfiltration malware

51801EA54CC24857858B1B4325D18721

AB09DD54C5D39D150B1B5E5ACDE0F141

Address book exfiltration malware

3bd07212d1e1573f66bd7ea12b025214

006cc1d3984b2b810295e63b11835016

Recommendations:

・ Monitor or Block malicious malware files and C&C IPs via web proxy servers, AV solutions, firewalls, phishing controls and email gateways

・ Block IOCs (Indicators of Compromise) such as malicious URLs, IP Addresses, SHA fingerprint, Hashes under firewalls, proxies, endpoint, spam and phishing security control

・ Do not open emails from untrusted sources-Always verify sender email address before opening any emails coming from a source outside the organization.

・ Configure Anti-Virus/IDS (Intrusion Detection System) repositories with the identified hash signatures associated with the threat to protect all endpoints.

・ Build an APT-IR strategy, which is agile and proactive, keeping in mind business goals and priorities

・ Establish a Cybersecurity Awareness and Training (CSAT) Program and run regular checks, educate employees to download applications from trusted Appstore only.

・ Implement Network Segmentation-Limiting communication between services and systems on the organization network level helps contain an infection and keeps a malware or a persistent threat from spreading.

・ Apply appropriate anti phishing and spam control with stringent email policy

About CYFIRMA

CYFIRMA defends against cyber attacks by supplying organizations with real-time threat intelligence that enables them to take a more proactive security approach. By aggregating, correlating and analyzing information from hundreds of thousands of sources on the open and dark web, CYFIRMA, helps companies anticipate what types of attacks are most likely to occur and provide the most effective response. CYFIRMA is a business division of Antuit, a global analytics firm.

CYFIRMA’s Cyber Awareness Series: Cyber Security Controls-a Primer.

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

In today’s increasingly sophisticated threat landscape, how do organizations know that they have adequate cybersecurity controls in place?

For appropriate cyber security posture, organizations need to apply the three main cybersecurity pillars (technology, people, and process) to organize cybersecurity controls.

Within each pillar, individual cybersecurity controls should be further prioritized by industry, organization size and maturity, and very critically, budget.


Cybersecurity Control Overview

Ransomware attacks on the rise again: ‘LetsDance’ is the new play

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

 

CYFIRMA’s cyber intelligence research centre have detected a suspected new ransomware campaign variant named ‘LetsDance’ targeting financial, retail, manufacturing and critical infrastructure companies. Our analysis highlights a North Korean threat actor group called TENJACKAL behind this campaign.

TENJACKAL is a financially motivated group first observed beginning of last year carrying out website defacement, malware and phishing campaigns in the United States, Brazil, Japan, Australia, Thailand and other South-East Asian countries. The members of the threat group are known to use existing malcodes, ransomware and malwares, repurposing them to create new attack strains.

We are seeing multiple Ransomware variants with a dramatic change in their attack nature and target selection, commodity ransomware campaigns are being replaced with customised campaigns targeting particular industries.

The LetsDance Ransomware uses a 3 stage attack technique called Incursion, Snitch and Encroachment (ISE Framework) to infect, propagate and demand pay.”

Spear-phishing, and the use of watering holes (fake websites) are predominant techniques used by LetsDance in the incursion stage of the attack.

LetsDance: 3 Stage Attack Tactic (Incursion, Snitch and Encroachment)

Attack Stage:

1 (Incursion): Attackers leverage a trojan designed to collect connected IT asset information (software, applications and version details)from the host network, and email IDs from the address book of the infected system. The malware is implanted on the targeted system when users are lured to visit a fake, infectious website via malvertisements or email invitation link to a user’s interest-specific website. Once the malware gets installed on the system, it communicates with the below command and control (C&C) servers for instructions and exfiltrates the information collected from the targeted entity.

Stage 1 malicious payload and C&C servers:

Malicious Payload:

9EC604D732759BB8B00312123AB262DD

C&C servers:

175.45.179.72

175.45.177.203

31.176.200.154

2.93.238.236

2 (Snitch): Collected system, applications and software details are analysed on the exploit server and based on potential vulnerabilities, the exploit attempts to gain access to the system. Parallel instructions are sent to the infected system to create and send misleading emails to all addresses from the stolen address book for further infection. A customized malicious payload is implanted onto the infected system to search all drives, directories, and subdirectories and then collects the file details and its attributes (size, extension, version, and specific strings such as “confidential”, “secret”, “sensitive”, “architecture”, “blueprint”, “usernames”, “passwords”, “credentials” etc.). This information is sent to another set of C&C servers for downloading customized encryption payload and webpage redirect malware onto the targeted system.

Stage 2 malicious payload and C&C servers

Malicious payload:

DC829558124F0E82CC7436BAD267A787

6B412B4CFA75F8DE31934F7AB653D36F

7CEDD997E8A9681A74D7F5ED46380D11

C&C servers:

199.16.146.87

175.45.177.109

175.45.177.35

2.93.238.98

175.45.177.101

2.93.238.209

3 (Encroachment): Once the encryption payload is downloaded onto the system, it encrypts all of the files and folders and changes the desktop background with a a message from the attackers.

Suspected encryption payload:

BCDEB71E0E6528311E63FCC3DFB44938

67989DFC5B16B52FD02BEBF25431AF09

BB6B7E38990C1549714E4FFC53622076

Along with the encryption payload, the C&C servers also drop a malicious program which redirects the user to a suspected webpage for payment.

Suspected webpage redirect malware:

F27A339786631136D2D5B5511A381E88

Strategic, Management and Tactical Recommendations:

Maintain multiple copies of data, files, folders to reduce the downtime in operations in case of a ransomware attack

Monitor or Block malicious malware files and C&C IPs via web proxy servers, AV solutions, firewalls, phishing controls and email gateways

Block IOCs (Indicators of Compromise) such as impersonating domains, malicious URLs, Host Names, IP Addresses, SHA fingerprint, Hashes under firewalls, proxies, end point, spam and phishing security control

Do not open emails from untrusted sources-Always verify sender email address before opening any emails coming from a source outside the organization.

Configure Anti-Virus/IDS (Intrusion Detection System) repositories with the identified hash signatures associated with the threat to protect all endpoints.

Build an APT-IR strategy, which is agile and proactive, keeping in mind business goals and priorities

Establish a Cybersecurity Awareness and Training (CSAT) Program and run regular checks, educate employees to download applications from trusted Appstore only.

Implement Network Segmentation-Limiting communication between services and systems on organization network level helps contain an infection and keeps a malware or a persistent threat from spreading.

Agile, Dynamic and Transitional Cybersecurity Strategy

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

Cybercriminals have evolved from being isolated, loosely organized and amateur in nature, to become sophisticated, innovative and highly organized threat actors. This requires organizations to keep up to date with a rapidly evolving cyber threat landscape, recognize and continue to adopt new cybersecurity controls to defend their critical assets.

Organizations have tended to always misunderstand cybersecurity strategy as a point-in-time activity to perform risk management. I have seen organizations create their cybersecurity strategy and operating it over multiple years. In reality, cybersecurity strategy has to be dynamic, regularly updated with a security posture t is that is always in transition (i.e., improving).An organization’s cybersecurity strategy should never be fixed, even though the strategic goals may remain constant over an extended period.

To create and adapt to a living and dynamic cybersecurity strategy, in view of a rapidly evolving cyber threat landscape, here are my recommendations:

・ Develop an agile and dynamic approach to cybersecurity. This approach should enable the organization to adjust their cybersecurity strategy according to the latest threats, attack surface, and risks. This should also be combined with an “outside-in” perspective, where the external threat landscape is continually monitored and evaluated against an organization’s cybersecurity processes, technology, and people. All potential risks to the business should be assessed, evaluated and mitigated by periodic evaluation of the cybersecurity strategy.

・ Create a vision, mission and business objective against an evolving adversary; a business-centric approach should be adopted, that has an impact on organization’s security posture and its capability to defend itself against external and internal threats on a continuous basis.

・ To address the risks of evolving and new external threats, it is unrealistic and economically unfeasible to materially change the security infrastructure every time there is a new class of threats. However, having an “agile” and “transitional” cybersecurity strategy that can be re-evaluated for its efficacy and a continual review of cybersecurity controls (which is tactical in nature) on a quarterly basis is possible and helpful.

・ Adopt the “Security First Approach.” Evaluate all business initiatives and changes to current business objectives with a cybersecurity lens, from the outset. With this approach, all new and changing business processes and applications will have a better chance of being secure and reduce the “retrofit” cost of implementing security protocols ex-post facto.

If your cybersecurity strategy incorporates the above considerations, I believe it will be fit for its intended purpose of maintaining and optimizing an enterprises’ security posture while balancing the practical reality of limited resources and time.

Each organization should assess what their needs are, how it intends to conduct its business activities and what changes they bring to their current risk posture.

Cybersecurity is not an add-on to information technology. It is a fundamental pillar and part of the foundation of a business that must be considered with all other core functions to maximize a business’ ability to meet its strategic goals.

Company executives need to ensure that the security architecture being developed reflects the needs of the business, the people executing the cybersecurity strategy are certified professionals with a mindset of balancing business goals and risk. They also need to ensure that technology products and third-party cybersecurity services being employed are aligned with the strategy.

An Agile, Dynamic and Transitional Cybersecurity Strategy is the need of the hour!

If “the only thing constant is change,” why would you want to have a static cybersecurity strategy?

Cyber Risks to our ‘Digital Shadow’ could be more significant than to IT Assets and Financial data

AUTHOR

Kumar Ritesh, Chairman and CEO, CYFIRMA

The current GDPR debate on how companies should protect personal data they collect is attracting much attention. However, there is an even more potentially dangerous risk to all of us: the protection (or lack thereof) of our behavioral data. Our ‘Digital Shadow’ is a goldmine for hackers to potentially access and exploit. Behavioral data touches everything we do, from how we behave, react and respond online to what we use and where we are in the physical world through everyday appliances, wearables, and any other digital application and system we touch.

An ever-growing number of wearables, tracking applications, connected home appliances are making our lives more convenient and comfortable. Smartphones, laptops, coffee machines, fridges, fitness trackers and wearable health monitors, home security solutions, and our cars constitute now a rich treasure trove of behavioral data. These devices collect information about everything we do, every second of the day with the utopic goal of tailoring and improving services to make our lives easier.

In today’s world, your ‘Digital Shadow’ is not just limited to personal information, photos, interests, social preferences, purchasing habits, where you like to go, a social map, and a calendar of activities. It now covers the entire gamut of your physical and emotional state. Our relationships with our family and social circle are now constantly tracked and monitored. Patterns of anger and joy, what we eat and when, lighting and room temperature preferences, what time you wake, sleep, exercise, including how. Whom you talk to and why, your transport patterns, travel speed, room temperature preferences, room lighting, reading habits, even how your heart rate and body reacts to different situations including times of stress, sadness and happiness.

The creation, storage and use of our ‘Digital Shadow’ will increasingly be a rich honeypot targeted by hackers. This type of data will allow an even higher resolution of personal profiling of targets for cyber attacks. Technology to make our lives easier is resulting in the unintended consequence of enabling threat actors to even more accurately predict our behavior in any situation.

This is very troubling.

We don’t need a vivid imagination to extrapolate where this risk takes us. Cybercriminals will have the ability to search for susceptible targets to be used as their mules, likely recruited unwillingly to penetrate and access a target corporation’s or government’s systems and data for any number of illegal and nefarious objectives. We will see more and more future cyber-attacks targeting such behavioral data, not limited to company IT assets and financial data, as consumer technology continues to be more tightly integrated into our lives.

Despite the sinister implications of our increasingly connected lives, trying to prevent progress is an unrealistic goal to these security dangers. Regulators, who have already started tackling the issue of more rigorous protection for consumer data collected by business, will also need to consider how to regulate and control the collection of personal behavioral data, its classification, how it is stored, and transmitted, as we inevitably approach a digitally tethered world.

Consumers, too, have an essential role to play in understanding how much of a Digital Shadow they have. Awareness and education of how these devices work, what information they collect, and how they are used, to make us potentially vulnerable to malicious hackers is a personal responsibility we all have. Even today, many people still don’t fully appreciate the extent of how much personal information is collected through the daily use of everyday electronic devices.

The last missing element of a comprehensive approach to this problem is the source of the technology itself. Manufacturers also need to be made responsible for what they are creating and releasing into the world. They have a critical role to play in the protection of consumers, in the same way, they are approaching the issue of traditional personal data protection. At the same time, companies who collect behavioral data need to understand the sensitivity of the information they gather and ensure that the appropriate security controls are in place when obtaining or using that data, subject to the law.

We are a long way from regulators, consumers, and companies coming together to address this issue of our ‘Digital Shadow,’ but the debate needs to start as soon as possible.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.