State-sponsored hacker groups join forces to capitalize on COVID-19 pandemic

By Masahiro Yamada

The raging COVID-19 pandemic has revealed many active fault lines among nation states and segments of society. We have observed the tirades between the US and China, India and Pakistan, and other divisions that push for national supremacy. Not just in the conventional news media but in the underground forums across the dark web. Beyond the usual trading of illicit goods and services, the echoes of hacker groups have grown stronger over the course of the pandemic crisis. And one key observation stands out from the noise.

Suspected state-sponsored or affiliated groups are joining forces to amass greater firepower in their covert cyber criminal activities. These groups recognize the immense potential of partnership and the richer rewards that come with the ability to reach a wider base of potential victims. By increasing their malware distribution network, and synchronizing their mega-phishing campaigns, their ability to inflict pain on enemy states increases multi-fold.

The impact of collaboration is the increased velocity and effectiveness of cyberattacks against businesses and corporations; for example, the combined groups optimize their resources by sharing information on vulnerabilities of Internet-facing servers, appliances, and devices. By doing so, they circumvent the tedious process of port scanning, framework and application identification – the ‘prep work’ needed before malware infiltration – and move quickly toward reconnaissance and exploitation.

In March and April 2020, we decoded signals from the dark web showing hacker-teamwork in action.

Campaign:  VISION2025
Original operation: MISSION2025 (APT41)
Possible Joint-operations Codename: Stone Panda (APT10)
Target: Manufacturing companies in the US, UK, France, Italy, and Japan
Motivation: Exfiltrate supply chain and third-party information, PII, and logistics software architecture and design to cause brand and reputation damage
Potential TTPs: Vulnerability exploits, open proxy usage, TOR nodes, commodity malware.
Method: Launch reconnaissance campaign to collect vulnerable targets, gain access into them using custom-built exploit. Focus is on taking over administrative accounts using specialized malware implants

Campaign:  醒来 (Wakeup)
Original operation: MISSION2025 (APT41) and Gothic Panda (APT3)
Possible Joint-operations Codename: Stone Panda (APT10)
Target: B2C e-commerce companies, transportation, logistics, and research companies
Motivation: Exfiltrate supply chain and third-party information, PII, and logistics and delivery software architecture and design to cause brand and reputation damage
Potential TTPs: Vulnerability exploits, open proxy usage, unsigned fake applications, commodity malware
Method: Launch reconnaissance campaign to collect vulnerable targets, gain access into them using custom-built exploit. The focus is on taking over administrative accounts using specialized malware implants. Focus is on taking over administrative accounts using specialized malware implants

Campaign:  열한 일족 (Eleven Clan)
Original operation: Lazarus Group (APT38, Hidden Cobra)
Possible Joint-operations Codename: Reaper (APT37, Reaper)
Target: Communication technology companies, postal departments, cargo companies and telecommunication companies
Motivation: Exfiltration of personal, customer information, payment details and consignment information
Potential TTPs: SSH bruteforce, open proxy usage, phishing domains, android spyware, commodity malware
Method: Use of data exfiltration malware on web and operating system vulnerabilities to extract databases

Campaign:  просветление (Enlightenment)
Original operation: Fancy Bear (APT28)
Possible Joint-operations Codename: Turla
Target: Large energy, power, Infrastructure, chemical and manufacturing industries
Motivation: Brand and reputation damage and/or financial gain
Potential TTPs: IoT bot infrastructure, open proxy usage, TOR nodes
Method: Malware and Trojan implants

The sudden onset of the pandemic crisis has caught many governments and businesses off-guard. The usual business continuity and SOP (standard operating process) methodology has not catered for a disaster of such massive scale. When hundreds of millions of workers have to switch to working from home, networks, systems, business applications and even laptops and PCs present an unprecedented challenge to IT departments all over the world.

Cybersecurity leaders are struggling to enforce previously designed policies around software upgrades, patching process, identity and access management, and many others. Delays in any of these fundamental security operations open businesses to many known and unknown threats. With their the defense capabilities weakened, these businesses are vulnerable to state-actors who are using collaborated cyber-weapons to build initial foothold before extending their cyber-espionage as the pandemic crisis persist.

To survive the COVID-19 upheaval, organizations cannot continue in their state of inertia; they should swiftly adopt an agile and dynamic cybersecurity strategy to understand their threat landscape holistically. By incorporating cyber-intelligence, businesses can minimize and overcome the cyber risk presented by the arrival of the pandemic.

 

WANT TO DECODE THREATS AND DEPLOY THE BEST CYBER INTELLIGENCE STRATEGY FOR YOUR ORGANIZATION?

SPEAK TO OUR CYBER RESEARCH TEAM TODAY.

 

The future of cybersecurity: Building resilient targets that defend themselves

By Kumar Ritesh, Founder and CEO, CYFIRMA

Cyberattacks are expected to increase exponentially in volume and sophistication, yet defences remain rudimentary. Overwhelmingly, security efforts by most organizations focus on building strong defensive walls designed to keep malicious actors, viruses and programs out; the reality is that these defensive walls will only last until the attackers find a way to jump over the wall.

Organizations must move towards ensuring their systems, networks, environment and data are resilient and capable of self-defence.

Drawing references from biology

The battle between the virus and its target (in biological terms, the “host”) has been going on in biological organisms for millions of years. Through evolution, human beings have developed sophisticated defence systems that block external viruses and bacteria and at the same time monitor and attack internal threats. Just like the COVID-19 pandemic the world is witnessing right now, new virus strains will develop, and over time, the human physiology will develop antibodies to fend off attacks.

Our skin is the first layer of defence, acting as a sophisticated barrier much like a firewall. Skin prevents external threats and can repair itself after an attack. Its capabilities are complemented by the work of the immune system, which acts as a second layer of defence.

Our immune system is like a self-policing, machine-learning mechanism. It monitors the internal environment of the body; defines and learns what is considered normal cell behaviour; and when an anomaly occurs, reacts to it in real time.

The future of cyber security lies in self-defence systems

While the human body is unable to win every battle against viruses and foreign elements, its self-monitoring, learning and healing capabilities provide insight into how future cyber security solutions should work.

The self-defence system should be able to identify abnormal foreign elements, activities, programmes and mal-codes using adaptive machine learning based on an understanding of normal system, application and data flow behaviour.

The system should also be able to independently restore normal functionality by making foreign elements and malicious programs dysfunctional.

Self-Defence Systems Framework

I see four key elements as fundamental components of self-defence systems. These core elements are essentially the refining of an automated set of rules designed to monitor system behaviour, diagnose potential abnormalities, reactivate the system by removing malicious components and, finally, incorporate new normal / abnormal behavioural patterns into the system.

These capabilities are made possible by increasing the core elements of artificial intelligence, machine learning and predictive analytical technologies.

  1. Monitoring behaviour

Continuously check against baseline, enrich the decision engine with ‘inside-out’ and ‘outside-in’ intelligence to identify new threats

  1. Fault Diagnosis

Identification of the abnormal attribute and correlation of situations

  1. Revitalization

Revitalization with state-based revival model by making bad functions, unknown programs and foreign executables dysfunctional

  1. Acclimatize

Acclimatize and immunize by embedding new normal/abnormal patterns in decision-making engines

Technology that augments the four core elements

Using historical behaviour mapping and analysis, self-defence systems should make real-time recommendations for action to be taken in response to an external ‘abnormal’ event. This is also commonly defined as adaptive machine learning, which would involve:

  • Defining normal and abnormal status (system state capture)
  • Monitoring current system status (system health analysis)
  • Determining “WHO” and identifying the cause of incidents (suspected analysis)
  • Understanding “WHAT,” “HOW” and “WHY” of incidents (content and context)
  • Applying business intelligence to understand threats in the context of the organization’s industry (industry-specific threat co-relation)
  • Identifying and analysing potential systems gaps (asset vulnerability life cycle)

In addition, artificial intelligence should enable autonomous system remediation and acclimatizing of new patterns by:

  • Monitoring and neutralizing abnormal behaviour of all externally introduced files, functions, programs and executables (foreign element neutralization)
  • Creating a virtual environment for foreign elements demonstrating abnormal behaviour (real-time jail boxing)
  • Creating systems’ responses to potential attack scenarios based on threat intelligence (attack vector reply)
  • Monitoring all threats to systems’ assets with active risk mitigation model (threat modelling immunization)
  • Activating real-time risk alert for all applications (system distress management)
  • Co-relating intelligence gathered about systems’ vulnerability and assess the potential for any exploits (vulnerability and exploit correlation)
  • Assessing the possibility of threats based on threat actor behaviour analysis (threat predictive modelling)

In summary, the next frontier of cyber security solutions will most probably be self-defence systems that continuously find, respond to and recover from new threats. This type of system will reduce the risk of attack significantly; more important, it will reduce the attractiveness of an organization as a hacking target for threat actors.

CYBER-CRIMINALS VIOLATE IMPLICIT CODE OF CONDUCT TO PEDDLE COVID-19 VACCINE SCAMS IN THE DARK WEB

CYFIRMA Researchers revealed a significant change amongst hackers and scammers in dark web marketplaces where there was an implicit agreement to minimize peddling of fake vaccine, but observations over the past week showed a dire change in cybercriminals’ attitude and approach

CYFIRMA, a threat discovery and cyber intelligence platform company backed by Goldman Sachs, Zodius Capital and Z3 Partners, has observed a change in cyber criminals’ approach and attitude towards taking advantage of the current COVID-19 pandemic for financial gains.

While hackers and scammers have been leveraging the pandemic to push out malware and phishing emails as part of their cyber- attack campaigns to steal data from businesses and consumers, or to cause social unrest amongst various communities, there has been an understanding amongst hackers groups to not ‘cross the line of humanity’ by selling fictitious vaccines. CYFIRMA researchers observed that hackers are cognizant to the dangers of putting millions of lives at risk as families of those who have been infected by the COVID-19 virus would likely be desperately seeking a medical remedy. Any news of a vaccine availability could also send masses of people into a state of frenzy and cause major turmoil across many societies.

As witnessed in the dark web marketplaces, there are groups who are urging sellers not to peddle fake COVID-19 cures. A forum in the dark web called ‘Monopoly’ has written: ‘Any vendor caught flogging goods as a cure to Coronavirus will not only be permanently removed from this market but should be avoided like the Spanish Flu’. The forum post also stated the gravity of the pandemic and asked sellers not to use the crisis as a marketing tool.

There are also groups in the dark web encouraging community members to contribute towards COVID-19 medical research. A dark web forum, written in Russian, has urged gaming enthusiasts to lend their computers’ GPU (these are graphics processing units with extensive compute power usually used for video games and high performance computing workloads) processing power to an international network of distributed computers to help with sequencing the virus genomes and related research.

While there are groups in the dark web taking a moral stance against profiting from the pandemic crisis, there are many other scammers who have taken a vastly opposite point of view.

In the past week, CYFIRMA researchers have noticed a marked difference in the tonality and approach taken in the numerous illicit marketplaces. There has been an influx of groups selling cures and vaccines, and each one is designed to extract maximum financial benefit, and all playing on people’s fears and anxiety.

According to the WHO, the earliest date for a COVID-19 vaccine to be available would be in 12 to 18 months’ time. But this has not deterred the proliferation of hoaxes which have since accelerated.

Advisory from CYFIRMA:

“Our observations are telling us there are broadly two groups of cyber-criminals lurking in the dark web. There is the one group who is leaning towards a basic code of conduct where they believe the pandemic is not the usual events where they could leverage and profit from, and then, there is the nefarious group who has no qualms to put lives at stake for their monetary benefits. While we know the dark web is teeming with criminals, there has always been some unsaid understanding of where to draw the line. The tide is now changing, and it is important for everyone to understand that, and be extra vigilant – vaccine for the novel coronavirus can only be obtained from your medical authorities as it becomes available, do not become victim of these scams,” advised Kumar Ritesh, Founder and CEO of CYFIRMA.

WANT TO DECODE THREATS AND DEPLOY THE BEST CYBER INTELLIGENCE STRATEGY FOR YOUR ORGANIZATION?

SPEAK TO OUR CYBER RESEARCH TEAM TODAY.

State-sponsored Hacker Groups Expand Attack Mechanisms and Utilize Commodity Malware for Espionage  

By CYFIRMA Research

State-sponsored hacker groups have been active for the past couple of decades. These well-funded hacker groups work for governments to steal intellectual property, wreak havoc on essential services such as power grids, telecommunications and financial systems, and cause massive disruption to daily life. State-sponsored hackers also target commercial enterprises in their efforts to destabilize the economy and create social unrest. The more prominent state-sponsored hacks include the Sony Pictures cyberattack by North Korea’s Guardian of the Peace hacker group as a retaliation to the screening of ‘The Interview’ where North Korean leader, Kim Jung-Un, was portrayed in a negative light. Other prominent state-sponsored cyberattacks include the recent data breach at Mitsubishi Electric by suspected Chinese hackers, the campaign launched against Indian nuclear power plant to exfiltrate data by North Korean hackers as well as Iranian’s cyber espionage against Saudi Arabian oil companies.

All the attacks above carry a common theme – the hacker groups have deployed malicious software, which is sophisticated, modular and multi-faceted. The cyber-attackers could extract data, destroy data, and control important and sensitive operational technology and machinery. The malware was carefully designed and customized to create the intended damage.

Recent observations by CYFIRMA Research revealed a change in tempo and type of attack mechanisms amongst state-sponsored hacker groups. In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns. The hacker groups were all known to be state-affiliated and funded, and the attack mechanism of choice is simply commodity malware. As the name suggests, this sort of malware is designed from readily available tools which hackers can quickly re-jig and launch attacks. In the ensuing months, the number of state-sponsored attacks using commodity malware have continued to rise and following is a sample of campaigns observed:

March 2020

  • Campaign: 동쪽의일어나는행동 (The Rising Action of The East)
    Suspected group: Lazarus Group or associated group
    Target: Retails and consumer goods industry
    Motivation: Data exfiltration and extortion
    Observed commodity malware: Agent Tesla and Mirai bot.
  • Campaign: 现役军人11 (Active Army11)
    Suspected group: Stone Panda or associated group
    Target: Retail, supply chain transaction, ordering and invoicing systems, manufacturing, and product / IT companies.
    Motivation: Sensitive personal and financial data exfiltration.
    Observed commodity malware: Phorpiex and Emotet.
  • Campaign: Unknown
    Suspected group: Fancy Bear or associated group
    Target: Retail and consumer good companies
    Motivation: Financial gain.
    Observed commodity malware: Emotet.

Feb 2020

  • Campaign:모래종이(Sandpaper)
    Suspected group: Lazarus Group or associated group
    Target: Large imaging, printing, sharing technology companies, and their product globally.
    Motivation: Stealing of intellectual properties (IP), personal and customer information
    Observed commodity malware: Shlayer and Mirai bot.
  • Campaign:紅色撲克10(Redpoker10)

Suspected group: Sone Panda, Gothic Panda, or associated group

Target: Manufacturing / chemical & rubber, product / IT, sporting, tire, retail, cosmetics, critical infrastructure.
Motivation: Sensitive data exfiltration / intellectual properties.
Observed commodity malware: Razy trojan.

  • Campaign:颜料(Pigment)
    Suspected group: Stone Panda or associated group
    Target: Large global camera, imaging, productivity devices makers, chemical and iconic tech companies.
    Motivation: stealing of intellectual properties (IP) to promote local imagining/printing companies, causing brand damage.
    Observed commodity malware: Phorpiex.
  • Campaign:金色平静(Golden Calm)
    Suspected group: A Chinese nation-sponsored hacking group
    Target: 8 global electrical and equipment manufacturing companies

Motivation: Stealing of supply/inventory information, customer information, brand/reputational damage to Japan
Observed commodity malware: Necurs Bot and Bashlite.

  • Campaign:人类分裂(Mankind)
    Target: Large engineering companies, shipping and container technology, and electrical equipment-making companies, from Japan, Taiwan, USA

Motivation: Intellectual property and trade secret theft, reputational damage
Suspected group: Stone Panda or associated group
Observed commodity malware: Phorpiex, and Shade

Developing and emerging nations have also entered the fray, many trying to build cyber capabilities with limited know-how and skills. Utilizing readily available malware would provide easy entry into the world of cyber espionage. These emerging nations would leverage commodity malware for a start, and should they gain expertise over time, the attack mechanism may evolve to be just as sophisticated as the developed nations.

While the world tries to cope with the new players, the more mature state-sponsored actors have progressed to using deception techniques to create confusion. By leveraging on commodity malware, they are attempting to operate under the cloak of anonymity to avoid being identified as state-sponsored hacker groups. Commodity malware can, at times, fall outside the radar as security analysts deem them to be of low threat to the organization. When remediation actions are not taken immediately, hackers can install another malware for further intrusion. A simple commodity malware becomes a ‘Launch Pad’ and could result in a catastrophic outcome for the compromised organization.

The state-sponsored hacker groups have also started to collaborate, exchange information, and share attack mechanisms, as CYFIRMA Research has observed between Chinese Stone Panda and North Korean Lazarus hacker groups. By teaming to take down a common adversary, they increase efficiency and achieve their objective faster.

The accelerated pace which technology is progressing in the areas of artificial intelligence and machine learning as well as faster processing power of computer servers fuel the speed which malware can be replicated.

Despite the awareness of cybersecurity as a key domain in both government and business, the number of data breaches have not abated over time. In fact, the number of attacks and the cost of data breaches have been growing exponentially. Nation-state cyber conflicts are likely to escalate, and with it, collateral damage to commercial enterprises.

 

Our Recommended Remediation for Commodity Malware

To effectively prevent, detect, and respond to the malware attacks, we recommend the following actions:

  • Minimize the duration between compromise and remediation:
    Since immediate remediation is often difficult for internet-facing servers, resolution time between initial compromise and resolution should be measured and evaluated as a performance factor of the organization security posture.
  • Isolate compromised systems:
    If the complete remediation cannot be taken immediately, the compromised systems should be isolated neither from the Internet nor intranet until all investigation and remediation completed. In case that multiple compromised systems and investigation system requires network access to them, the isolated network, which is equal to air-gapped network having no connection to any other network, should be implemented during the investigation.
  • Prioritize targeted attacks using commodity malware:
    Even if detected malware on an internet-facing server is commodity and not causing damage, investigate all related events and remediate as soon as possible. Similarly, if commodity malware attached to a spear-phishing email that is fully targeted to a specific user or department, investigate all related events and remediate immediately.
  • Confirm no additional activity take by detected malware:
    Even if remediation actions are taken for commodity malware incidents immediately or automatically, make sure no additional activities that has not been taken care by the remediation actions. EDR, SIEM, and other behavior monitoring solutions should be utilized to confirm this.

WORKING FROM HOME IN THE TIME OF CORONAVIRUS

The coronavirus outbreak has forced businesses to make a safety-conscious yet an operationally hard decision- asking their employees to work from home in a bid to encourage social distancing. While telecommuting can translate into better productivity and lower costs, it also raises concerns about the security of critical corporate data, transmitting outside the safety perimeter of the office, across a multitude of devices, systems, and peripherals, most of which aren’t conforming to rigid security protocols. This is the perfect recipe for a potential data breach!

In this post, we will discuss the most challenging data security issues businesses must contend with when employees work from home through the coronavirus outbreak.

Challenge: Security of Cloud-Based Assets

Cloud computing may be the backbone of modern business yet managing online assets can be very complex when there is a wide network of external devices constantly accessing and sharing critical information.

Solution: Employ technologies like geofencing, and predictive asset management to command the flow of critical organizational data.

Challenge: Monitoring BYOD Policies, Mobile Devices, and Unsecured Networks

Many employees use personal devices and unsecured Wi-Fi networks for remote access. By hacking into a public and unsecured network, hackers can prevent employees from logging into their work accounts, under the pretext of “denial of service”. Used as a social engineering tool, the remote employee can be tricked into providing their login credentials, subsequently leading to the compromise of the victim’s systems, and the organizational infrastructure.

Last month, as part of its February 2020 Patch cycle, Microsoft released security patches for several critical remote desktop vulnerabilities, the most prominent ones were CVE-2020-0681, CVE-2020-0734, CVE-2020-0655, and CVE-2020-0660. If an attacker could successfully exploit any of these vulnerabilities, the result would have been the execution of arbitrary code on the targeted system. Depending on the vulnerability, this could result in the viewing, modification, and deletion of data, alongside the installation of applications and the creation of new users with admin-level privileges. Microsoft had marked these vulnerabilities as critical and concluded that their exploitation was “very likely”.

Solution: The organization can employ robust Bring Your Own Device (BYOD) policies and advise their workforce about the dangers of unsecured devices, networks, and common hacker strategies like “denial of service”. Additionally, the remote employee’s work device can be secured in advance with the necessary security software. Further, ensure that all systems are provided the latest applicable security patches to offset the dangers from the remote desktop vulnerabilities as listed above.

Challenge: Respecting the Duality of Personal and Business Data

When employees use the same device for work and personal use, there is a grave danger of threats impacting all data. For instance, if software downloaded for personal use from a shady website causes the employee’s laptop to crash, his work data would be lost too. Recovery of lost data depends on the backup solutions employed, and the remote worker diligently adhering to the backup policies.

Solution: From IT operational perspective, a robust cloud backup solution needs to be deployed. More importantly, employee cybersecurity awareness and training need to step up when working from home becomes the norm.  A vast majority of the employees simply lacked understanding of common security risks, as well as their own unwitting participation as enablers of such risks. Organizations must build a strong culture where every employee sees cybersecurity as his personal responsibility and comply with policies and protocols.

Will the COVID-19 outbreak facilitate a security-conscious work culture? The recent coronavirus outbreak and the need for social distancing have forced many organizations that weren’t earlier in favour of working remotely to embrace this concept and assist their workforce in working productively from home. This translates into the procurement/leasing of new equipment, migration of work environments from fixed peripherals onto mobile devices, and management of queries and troubleshooting. Aside from the IT and security teams, the procurement unit, and other departments within the organization and the supply chain must be adequately trained to understand security implications.

Challenge: Increase in phishing attacks, many using social engineering tactics to trick employees into revealing sensitive information and facilitating data breach

CYFIRMA’s CTI (Cyber Threat and Intelligence) team has observed a renewed wave of phishing attacks, aimed at those seeking information about the COVID-19 outbreak. A slew of impersonated websites, including those purporting to be associated with authoritative bodies like the WHO, are likely to host keyloggers that could lead to the exfiltration of critical corporate data. Additionally, impersonated VPN applications are being spread through registered domains, with hackers paying particular attention to the manipulation of VPN tools. Also, our research team and multiple security vendors have reported that threat actors are using fear tactics to spread malware, including LokiBot, RemcosRAT, TrickBot, and FormBook. Alarmingly, most consumer-ready antivirus solutions alone won’t be able to stop the hackers’ sophisticated attacks targeting the organization.

Solution: Building a fortress to protect an organization’s assets and data has now become a fundamental rigour. Unfortunately, this alone is ineffective in keeping out hackers and adversaries. Organizations must also look outwards and adopt an intelligence-centric approach to managing cybersecurity. This means receiving real-time cyber-intelligence that is harvested and analysed from the hackers’ trenches (deep/dark web, surface web, hackers’ communities, closed communities). Data collected would have to be analysed in a way that is relevant to the organization’s industry, geography and the technology that it is currently using. Only then can cyber-intelligence be accurate and predictive, and utilized effectively to fend off cyberattacks.

Security Operational Hygiene

Here are the basics which we recommend companies implement today, if they have not already done so.

Firewall and Antivirus: Solutions that match up to the organization’s size, scope, and scale, must be implemented on priority. Ensure that the firewall has built-in properties like high availability programs, robust anti-malware software, etc.

VPN Setup: When it comes to accessing secure data remotely, VPN is a prerequisite tool. Usually, business-grade firewalls have built-in VPN. Note that even the most sophisticated VPN can be overcome by risky behaviour from the end-user.

Employ Multi-Factor Authentication: Aside from the usual options, biometric authentication such as fingerprint technology or iris scanning technology can be deployed.

IDS and IPS Setup: Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are background programs that monitor your network and will alert you if any suspicious or malicious activity is detected.

Limit Information Access: Grant access to only such information that is necessary for the remote worker to complete his/her job. Employees should never be granted access to all the available critical data.

Data Security Specifications Document: Specify in writing the various do’s and don’ts when it comes to critical organizational information, its usage and circulation by the remote worker, and other policies. This should be a live document with periodic updates following your organization’s changing security landscape.

In Summary

The sudden onset of the coronavirus outbreak and the scramble to implement remote access have caught many organizations off-guard. By adopting the measures above, organizations can be confident prolonged telecommuting would not compromise their security postures.

Ensuring Cyber Resilience in the event of a Global Health Emergency | Outbreak of Corona Virus

The latest outbreak of the deadly strain of corona virus has infected thousands of people worldwide and spread to many countries. In light of the World Health Organization’s declaration of this outbreak as a global public health emergency, the disease’s rapid spreading is threatening to overwhelm the available medical remedies and personnel. Already, various nations including Japan and US are putting measures in place to manage the impact of the virus. Organizations are also starting to take a hit as the spread of the corona virus starts to cause disruption spanning the global economy.
With the risks realized from a potential worldwide pandemic outbreak, CYFIRMA’s Threat Intelligence team will like to recommend the organizations to start early planning for pandemic risk management and ensure their Business Continuity Plans (BCP) outline how they will prepare for a pandemic and continue to operate post the disaster.

As part of the planning, organizations need to:

  • Determine core services and what’s required to maintain external and internal touch points, e.g. the supply chain.
  • Determine staffing arrangements, like- telecommuting, cross-skilling, succession planning, etc.
  • Develop a sturdy communications strategy for employees, customers, suppliers and the different stakeholders.
  • Protect the health of their staff.
  • Develop contingency plans for unexpected developments.
  • Consider financial implications, such as – cash flow, insurance, cost increases due to contingency measures, etc.
  • Schedule how the plan will be tested and kept updated.

While devising the BCP for events such as pandemic outbreaks, organizations need to include the following:

  1. Risk management plan–for a pandemic, this involves identifying risks, assessing the impact of risks and developing ways to manage risks applicable to your business and organization.
  2. Business impact analysis – assesses how risks identified in your risk management plan might affect business operations. It identifies activities that are critical for your organization and prioritizes what must be done to maintain them.
  3. Incident response plan – outlines actions to limit the loss of life and property before, during, and immediately after a pandemic.
  4. Recovery plan – aims to shorten recovery time and minimize the organization’s losses following a pandemic. It sets time frames for the recommencement of normal business operations.

Expected threats in the wake of Corona Virus Spread

Business continuity planning comes with its own share of targeted threats as follows:

 

  • Cyber attack
  • Data breach
  • Unplanned IT and telecom outages
  • Security incident
  • Health & Safety incident
  • Interruption in utility supply
  • Supply chain disruption
  • Disruption in the availability of key skills
  • Acts of terrorism
  • New laws or regulations

Social Engineering Watch – Corona Virus themed phishing, ransomware/malware campaigns:

As reports about the latest corona virus outbreak flood the web, cybercriminals are expected to leverage these updates to deploy the widespread reports to mislead unsuspecting victims into opening bogus emails directed to them. These emails ultimately lead to phishing attempts through which the target’s information and passwords are extracted. In light of the increased chances of global health emergencies, there is a heightened chance of hackers leveraging the fears around the health emergency to their advantage and infect more people with malware.
CYFIRMA’s Threat Intelligence team will like to alert organizations about spam campaigns that could use the corona virus to bait users into clicking on malicious web links or attachments. This is what is primarily achieved via social engineering, wherein, especially in the case of a health emergency, cyber criminals could capitalize on the people’s fears of the deadly virus.
A popular instance of the same could be emails purporting to be from renowned health organizations such as WHO or National Health Commission, with a bogus attachment claiming to include corona virus safety tips or a bogus advisory about the status of corona virus in the country. As soon as the target user is misled into downloading the attachment, the file drops a malware onto the target’s system and circumvents the existing antivirus defenses.
It is ironical, and chilling, how a ‘real’ world virus can offer malicious actors the opportunities to exploit unsuspecting targets and create an equivalent negative impact spanning digital ecosystems.

Corona Virus Themed hoaxes:

In the wake of the outbreak, massive quantum of misinformation about the corona virus is doing the rounds, including bogus videos and websites citing incorrect (mostly exaggerated) number of people, and geographies, as impacted by the virus. False sources include, ironically, the Chinese state media and their government officials. Thus, aside from the graver issues, a less immediate danger includes the possibility of increased online hoaxes. Hackers can peddle bogus virus safety tips and cures as a cover story for advance fee scams, while their targets are more likely to fall prey to these advances in light of the global prevalence of this emerging outbreak story.

Remote Access threats:

Multiple pandemic business continuity plans identify telecommuting as a major component of response to a virus outbreak. Telecommuting can contain the disease spread, while allowing organizations to continue to operate. However, remote access communications may be carried over untrusted networks. Some of the remote access threats are as follows:

  • Hackers leveraging rogue wireless access points.
  • Breaching into poorly secured remote access client devices.
  • Deploying malware to harvest credentials and other sensitive data.
  • Potential risks accompanying vendor remote access.
  • Exploitation of rising VPN related vulnerabilities.

And many more…

The need of the hour – CYFIRMA’s differentiator

Threat actors are aggressively striving to piggyback on major events and virus/disease outbreaks to mislead potential victims and spread their malware for nefarious purposes. CYFIRMA’s proprietary AI and ML technology analyzes global threat indicators – including possible attack indicators wrapped around the spread of the deadly corona virus –and offers cyber threat visibility and intelligence aimed at keeping the organization’s cybersecurity posture up-to-date, resilient and ready against upcoming cyber-attacks.
In the wake of more corona virus pandemic, CYFIRMA’s Threat Intelligence team will like to advise users to carry out the following mitigative measures:

  • Be wary of unsolicited links or attachments, ads, offers, or anything that deploys “big news” as bait.
  • Ensure that your AV software is up-to-date, and it runs periodic scans to block potential intrusions.
  • Exercise extreme caution while opening access to business workstations for remote users. For reducing unauthorized access, organizations should incorporate appropriate steps to ensure that the right users are provided with remote access to connect to the workstations.
  • Create procedures, templates and guidelines for service continuity in the event of a pandemic outbreak.

CYFIRMA Advisory and Research also covers essential best practices applicable to securing remote access. Organizations are advised to adhere to these guidelines:

  • Plan out a comprehensive network security policy outlining classes of users, level of access allowed to each user class and devices allowed to establish connection with the enterprise network via a VPN.
  • Perform an inventory of their third-party vendor connections.
  • Run vulnerability scans on the external-facing hosts.
  • Ensure that updates are periodically applied to the OS, key applications, such as web browsers, email and instant messaging clients.

CYFIRMA’s product and service offerings provide targeted insights that can help make an organization’s cyber posture management resilient and robust in handling disasters and pandemic situations like the one presented by the corona virus outbreak.

Let’s keep the conversation going on Twitter, Facebook, and LinkedIn.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.