Quantum Computing and Who is Leading the Cyber Arms Race

Why is the NIST worried about quantum computing when it’s going to take some time for it to become a reality? How is quantum computing disrupting the world of cyber? Does China lead the quantum technology race?

Traditional computers perform calculations with standard ‘bits’ that exist in states of 0 or 1, whereas quantum computers use ‘qubits.’ These quantum analogs of the ‘bit’ exist in a superposition of all possible states, allowing for a significant, even exponential, advantage in computing capabilities. Bits function similarly to switches in that they can be either up or down, on or off. Qubits, on the other hand, are more like dimmer dials in that they can have an infinite number of different values between on and off, along with other computational functionality.

Quantum computing is fundamentally different from the laptops and smartphones on which we depend on today. Instead of ever smaller transistors, quantum machines operate on particle physics principles and excel at solving complex statistical problems with multiple variables. Even though quantum computing is not a complete reality today, it is capable of adding significant value to areas like medical research, artificial intelligence, weather forecasting, military affairs, and cyber security. Ironically, it also creates a significant cybersecurity threat, potentially requiring a change in how we encrypt our data.

Recognizing this fact, many private sector companies and nation-state research institutions have begun to invest in R&D. Many experts in this field believe that the advancement of quantum computing technologies will not follow the typical smooth progression curve. Companies and countries that have begun to invest in and develop plans to achieve quantum supremacy in their operations have a much better chance of capitalizing on the future market during this early development phase.

Who is leading the race – Where does China stands?

Considering the potential impact of quantum computers in the future, many governmental institutes and private agencies have funded research and development in quantum computing technologies. Despite the fact that many market-ready and mature technologies, such as artificial intelligence and blockchain, exist, quantum computing has attracted the interest of global superpowers, particularly China and the United States.

Companies in the United States such as IBM, Google, Honeywell, and Amazon are making significant investments to achieve quantum computing supremacy, whereas China has placed quantum information science at the center of its national security strategy, capturing the attention of the Chinese top leadership. China’s supreme leader Xi Jinping has emphasized the strategic importance of quantum technologies to national security, particularly cybersecurity. The “All-of-government” approach is being used by China to develop quantum technology, clearly, the nation has recognized it to be a strategic national priority.

Various available data points show that China recognizes the importance of quantum supremacy in realizing its dream of becoming a global superpower capable of displacing the United States, and believes that this competition will be a marathon, not a sprint. China has consistently funded basic and applied research in this scientific domain since the 1990s, primarily through China’s National High-Technology Research and Development Plan. Since the 11th Five Year Plan, China has made quantum computing a strategic priority (2006).

China’s Five-Year Plan and Quantum Computing

  • The 11th Five-Year Plan (2006-2010): Incorporated basic research on quantum communication as a key research direction while launching a major research program on quantum control.
  • The 12th Five-Year Plan (2011-2015): The “Quantum Control Research National Major Scientific Research Plan” was introduced as a special topic.
  • The 13th Five-Year Plan (2016-2020): Prioritization of quantum information science, including ‘quantum control’ in the category of ‘basic research related to national strategic requirements. Here, the Snowden leaks played a significant role in policy formation. This further emphasized research on quantum control, quantum information, quantum communication, quantum computing, and quantum navigation.
  • The 14th Five-Year Plan (2021-2025): Explicitly mentions Quantum Information as a key development focus to become a science and technology powerhouse.

In its 14th Five Year Plan, China ranked quantum computing second only to AI as a top technology priority. Recognizing its significance, the CCP committed to ongoing funding support for Quantum Computing research and development. Around USD 15 billion in funding has been announced for leading institutions such as the National Laboratory for Quantum Information Science and the Beijing Academy of Quantum Information Sciences to develop some of the world’s top quantum research facilities.

Highlights of China’s Quantum Computing program

  • In recent years, China has filed more patents for quantum-related technologies compared with the other mature economies.
  • China’s Jiuzhang Quantum Computer can perform a calculation in 200 seconds that would take more than half a billion years on the world’s fastest non-quantum computer.
  • China built a quantum cryptography key distribution network spanning 4,600 kilometers and connecting eastern population centers to China’s western borders. Exchanged secret cryptography keys enable sending an encrypted message over the conventional telecom networks.
  • Chinese researchers claim to have achieved notable advances in quantum radar, sensing, imaging, metrology, and navigation, which enable greater precision and sensitivity.
  • Most active Chinese organizations in Quantum Computing are as follows.
    • Chinese Academy of Sciences
    • University of Science and Technology of China
    • Tsinghua University
    • Ministry of Education China
    • Alibaba’s Shanghai Quantum Lab

China’s Quantum Timeline

In 2015, Xi Jinping included quantum communications in his list of major science and technology projects that are prioritized for significant breakthroughs by 2030, given their importance from the perspective of China’s long-term strategic requirements.

  • 2016 – Launched a quantum communication satellite called Micius.
  • 2017 – Invested USD 10 Billion in a National Laboratory for Quantum Information Sciences, tested a 2,000 km quantum pathway from Beijing to Shanghai, and launched a quantum communication that sent test messages from China to Austria.
  • 2018 – Achieved quantum entanglement of 18 qubits, surpassing the previous world record of 10 qubits.
  • 2019 – Claimed to have built the fastest computer in the world – 10 billion times faster than Google’s computer.
  • 2020 – Claimed to have built a quantum computer able to perform certain computations nearly 100 trillion times faster than the world’s most advanced supercomputer.
  • 2021 – China’s ‘father of quantum computers’ Pan Jianwei claimed that the newly developed photonic quantum computer Jiuzhang 2, as well as the new superconducting quantum computer Zuchongzhi 2, are significantly faster than Google’s quantum computer.

Threats Emerging from Quantum Computing Progress

Apart from the numerous benefits of quantum computing, there are a few negative consequences as well.

Cryptography

Because quantum computers can process data at an exponential rate, they pose significant cyber threats to existing cryptosystems. However, current quantum computers lack the hardware required to break this algorithm. Many applications, including web browsing, online payments, digital signatures, and email, rely heavily on asymmetric encryption schemes like the RSA algorithm. The RSA algorithm is based on traditional computers’ inability to find factors of the product of two large prime numbers. A quantum computer with 4000 qubits and 100 million gates is estimated to be required to crack a 2048-bit RSA key. Other public-key encryption schemes, such as Diffie-Hellman and ECC, are rendered ineffective in the face of a quantum computer. On the one hand, this will disrupt the encryption ecosystem; on the other hand, it will reveal potentially sensitive information from previously exfiltrated encrypted data from various historical cyber-attacks by nation-state groups and cybercriminals.

Cyber warfare

In future warfare, technological superiority over the number of soldiers in the armed forces will determine victory. Quantum sensing has the potential to be used in a variety of technologies with direct military applications. Quantum radar, in particular, can detect targets that conventional radar cannot detect, and quantum navigation uses quantum properties to create a precise form of positioning system that may eventually replace GPS. Such technologies, when combined, could be critical to China’s future military capabilities, as well as a key focus of technological competition with other rival countries such as the United States.

The realization of quantum radar, imaging, and sensing would improve domain awareness while potentially undermining rival countries’ investments in stealth technologies or even allowing submarine tracking, particularly in the South China Sea, thereby proving a strategic advantage in the geopolitical battleground. Collectively, these advancements support the Chinese People’s Liberation Army’s (PLA) continued development as a leader in these new technological frontiers of military power.

Espionage

China can use cyberespionage to undermine global technology and academic organizations’ quantum research in order to quickly close technological gaps and achieve quantum computing supremacy. If China succeeds in becoming a leader in quantum computing, the leveraging of such massive computing capabilities could provide a strategic advantage, putting sensitive information systems at risk around the world, particularly in the United States and rival countries.

Do we need to worry?

As China strives to become a global superpower, it has recognized the importance of quantum supremacy in that endeavor, and as a result, quantum technology has captured the attention of the Chinese leadership at the highest levels. Furthermore, the PLA is actively engaged in developing quantum technology as a strategic enabler to bridge the gap between its military capabilities and those of potential adversaries.

The PLA’s interest in quantum technology reveals its intent to use advances in quantum technology in adversarial activities. Because China is known for its offensive cybersecurity capabilities and collaboration with cybercriminals and nation-state actors, quantum supremacy by China could have a devastating impact on rival nations such as the United States and Southeast Asian countries.

In any potential conflict with China, a rival country’s use of stealth would be critical, allowing naval vessels to approach the Chinese mainland and aircraft to penetrate Chinese airspace, putting Chinese operational assets at cyber risk. As a result, quantum radar would be a hugely disruptive force in the PLA’s arsenal of anti-access/area denial or “counter-intervention” capabilities. If deployed, quantum radar could not only undermine competitors’ stealth advantages but also increase the potential costs of war by forcing them to accept higher operational risk and nullifying billions of dollars spent on stealth coating for platforms operating in the Pacific Ocean.

When China achieves quantum technology supremacy, it will gain a first-to-market advantage. This may assist China in including backdoors enabling surveillance in the technology or equipment supplied, as seen in Chinese telecommunications vendors Huawei and ZTE in the 5G wireless network equipment.

Military affairs, espionage, supply chain manipulation, and offensive cyber activities will take center stage as China strives for quantum supremacy and the status of a global superpower.

Importance of Post Quantum Cryptography (PQC)

Today there is no quantum computer capable of managing the hundreds of thousands to millions of qubits needed to handle the sort of factoring that would crack current cybersecurity. But looking at the angle of a quantum computer as a strategic priority for national security, in another 10-15 years quantum computers will be a reality. They will be capable of disrupting the current cryptography ecosystem. Quantum computers in the hands of rogue nations and cybercriminals will be nothing less than a cyber disaster. In organizations that store or transmit data with long shelf life, or entities whose cybersecurity systems have a long lifecycle, the risk of quantum computing is imminent. For example, data that are being encrypted today by a quantum-vulnerable algorithm, such as RSA, can be intercepted by an adversary now, for decryption later, when the quantum computing technology is available to do so. Thus, these sectors, specifically the financial, insurance, or government sectors, must act now, by integrating post-quantum cryptography into their security infrastructure to avoid compromise of their long-term certificates or encryption keys. Scientists and forward-thinking policymakers are already working on quantum cryptography to stay ahead of critical transformation to secure sensitive data and avoid its access by cybercriminals.

NIST invited proposals and algorithms for Post Quantum Cryptography (PQC) in 2016 and released its encryption criteria and guidelines for public submissions. Initially, 69 viable candidates from around the world were submitted. NIST chose the first set of encryption tools designed to withstand an attack by a future quantum computer after careful cryptanalysis. The organization expects to have a draft standard by 2024, if not sooner, to be added to web browsers and other internet applications and systems.

Conclusion

Quantum computing will have an impact on everything from apps to internet search, web development, cybersecurity, and beyond. It is prudent to stay ahead of current technological trends so that when new features are released, we have the knowledge and tools needed to weather the start of the modern technological era.

If cybercriminals use quantum computing before we adopt PQC, they will be able to deduce someone’s encryption key and use it to impersonate the person, forge transactions, forge digital signatures, find and print data, and extort or disclose the harvested data.

When it comes to China’s role in quantum computing, Chinese leaders recognize quantum science and technology’s strategic potential to enhance the economic and military dimensions of national power. These quantum ambitions are inextricably linked to China’s national strategic goal of becoming a science and technology superpower. Instead of relying solely on the absorption of foreign technologies in its pursuit of indigenous innovation, China intends to achieve truly disruptive, even radical, innovation in strategic emerging technologies. Data points discussed reveal that China’s bet big on quantum computing has achieved significant milestones.

What is going on with Lapsus$?

What’s going on with Lapsus$

By Adam Parsons, CYFIRMA Cyber Threat Intelligence

 

 

Lapsus$ has hit the headlines recently partly due to the mega-corporations that they appear to have successfully hacked and partly due to the claims that they are or were led by a 16-year-old.

Indeed, there have been a number of arrests, most recently a 16-year-old and a 17-year-old appeared in court in the UK charged with a number of cyber offenses. However, as the above post on their telegram chat group shows they have no intention no of stopping.

The telegram channel was their only official communication method where they have published stolen data, and in at least one instance, held a vote on who to attack next.

The group chat is used to share stolen data (not linked to Lapsus$), tools and requests for hacking help. However, the channel is not quite a wild west…there are rules:

  1. No porn
  2. Not too much trolling
  3. No spam

But outside of these rules anything goes…

The channel is not just for English speakers, there are a significant number of users communicating in Portuguese. This is potentially a throwback to the first few public victims of Lapsus$ being the Ministério da Saúde do Brasil (Ministry of Health of Brazil) and latterly Portugal’s Impresa media group.

Given that the rise of Lapsus$ has coincided with the downfall of Raidforums, a popular entry-level hacking forum, it appears that the Lapsus$ chat has attracted a significant number of like-minded individuals.

The telegram group still bears the name of its initial victim (https://t.me/saudechat), we can assume that it was initially set up to share the stolen data from the Ministério da Saúde do Brasil. That has long since passed, but still, the attacks keep coming even after what many thought would be arrested that would bring about their downfall. Likewise, the doxing of one of the supposed main members of the group has also not stopped their progress.

Given the naming of the telegram channel, we can assume that their ongoing activity was not planned. One would expect that they are making it up as they go along, thinking barely one step ahead. This may be one reason law enforcement is having such problems shutting them down. There is no plan, victims are targets of opportunity and profit is not the main motivation.

It has been reported that members of the group originate from the Sim Swapping world, a relatively small sub-section of the hacking community that is specifically focused on illegally obtaining control of phone numbers and subsequently control of their linked social media accounts. These social media accounts have then been used in several high-profile scams often involving crypto. Alternatively, sim swaps have been used to gain control of specific users’ social media accounts due to a unique Twitter or Instagram handle that can then be sold in online forums. Much like Lapsus$, individuals arrested in sim swapping are largely of a similar youthful age.

This might explain the brazen attacks against mega-corporations and so far their lack of interest in regularly using these attacks for financial gain or at least it does not appear to be their main motive. Hacks of Okta and Microsoft are by far more valuable than even the most high-profile Twitter handle. The reasons for these attacks are quite bizarre. The hack of Nvidia was followed by a demand to remove all Lite Hash Rate (LHR) limitations to its Graphics Processing Unit (GPU) hash rate that prevents faster crypto mining activities. It also wanted Nvidia to publish the base codes of its GPU drivers as open-source, making them publicly accessible and openly modifiable forever. Neither of these demands would directly benefit Lapsus$ and seem more targeted at pleasing their fans and enhancing their reputation amongst the community.

 

How are they doing….what they do!

There have been a number of in-depth reports on how Lapsus$ has evaded the defenses of their victims. Researching the group, we discovered how incredibly simple some of their methods were.

The technical skills and social engineering techniques bear resemblance to those used in the sim swapping world, which is after all where they first got started.

Lapsus$ group put out a call on their telegram channel to employees at potential victim companies, as seen below:

 

Whilst this was widely mocked in cybercriminal communities for the lack of hacking prowess it takes to recruit insiders to simply give you access, it has been reported that this was in fact the reason Microsoft fell prey to the attack. Lapsus$’s approach may seem less sophisticated compared with advanced threats groups, but as we have witnessed, they are a force to be reckoned with. Given that Lapsus$ appears to have used this technique as early as November 2021, we can easily assume that it has been more successful than reported.

Aside from this, Lapsus$ techniques are a throwback to their sim swapping days and revolve around social engineering techniques.

 

Lapsus$’s methods – they seem so easy

 

Sim swapping involves obtaining control of a victim’s phone number by tricking the phone service provider to transfer the phone number and therefore control to another device as per the above illustration. This method requires a significant level of knowledge of potential questions posed by the phone service provider and their requisite and often personal answers. Lapsus$ likely makes use of openly available data through social media and previously breached data to answer these questions.

Once the number has been transferred, threat actors can then get access to most if not all the victim’s linked accounts through password resetting via the transferred phone number where the phone number is used as a method of recovery. Email accounts often hold valuable information, including account details, passwords and answers to security questions. Lapsus$ has also been reported to deploy Redline malware, a password and session token stealer.

There is another avenue much like sim swapping where it requires the threat actor to make a call impersonating the victim. The hacker will call the employee’s IT department and attempt to have their password reset. Depending on the security stance of the organization, this often requires answering numerous questions which are personal to the victim.

Once the victim’s password has been obtained, there is another line of defense.

Multifactor Authentication (MFA) or 2-factor authentication (2FA) comes in many forms as it is an additional security measure should a password be leaked or otherwise obtained by an unauthorized party. MFA requires the approval or authentication on an additional device to grant access.

Once an employee password is known, the group would need to pass MFA. Should they have access to the victim phone number and MFA is linked to the compromised number, access can be obtained. If this is not the case, then there are a number of other methods that can be used.

Spamming employees with push requests and automated calls to get MFA approval is one such method. Lapsus$ even brag about this technique on their channel “Call the employee 100 times at 1 AM while he is trying to sleep, and he will more likely to accept it. Once the employee accepts the call, you can access the MFA enrolment portal and enroll another device”

Whilst bombarding an employee with MFA requests creates a lot of noise and could potentially alert the victim, there are other stealthy methods at play. One such method involves sending MFA push requests a few times a day, hoping the employee’s guard drops momentarily.

Opting for more advanced MFA such as FIDO2 provides a higher degree of security. FIDO2 requires the authentication to be performed on the device that is used to log in, making remote logging in on any other device ineffective.

Of course, awareness by employees of these techniques is key. Suspicion should immediately be raised if an unrequested MFA notification is received. Likewise, IT staff must remain vigilant to suspicious password resets requests. Staying updated on what is shared online on social media and awareness of any personal data that has been leaked will help avoid becoming a victim.

 

So what’s next from Lapsus$?

As we have seen, law enforcement coming down on Lapsus$ has not stopped the group’s activities. We can assume a leadership group is controlling the telegram channel rather than an individual. One would expect that it is a point of pride that the channel stays up despite law enforcement action. The group has a plan to use Element.io instant messaging platform as a backup should their Telegram channel shut down.

In the meantime, the channel continues to grow, as Lapsus$ have triumphantly noted that their telegram chat group now has over 30,000 members. Should the leadership group be taken down, it would not be out of the question for one of these members to form their own Lapsus$ franchise if they have not already done so. The added humiliation of a multinational corporation being hacked by a group most associated with teenagers doing it for the ‘Lolz’ would make the Lapsus$ name an attractive brand.

APTS have imaginative animals as their mascot, Hacktivists have Guido Fawkes masks, will malicious teenagers use the Lapsus$ name as their logo?

If we were to illustrate a picture of the Lapsus$ group based on their history and current trajectory, we should draw a multi-headed hydra, each head laughing as Law Enforcement arrests teenager after teenager, and the regrown heads hack their way through the sophisticated defenses of company after company……just for the Lolz.

 

A New World Order in the Making – Observations on the Latest Geopolitical Development and the Impact on Cybersecurity

A New World Order in the Making – Observations on the Latest Geopolitical Development and the Impact on Cybersecurity

 

Ongoing Ukraine – Russia conflict could well be the straw that finally breaks the camel’s back. Slowly but surely battle lines are being drawn, awkward allegiances abandoned, muscles are being flexed, and old compromises and conflicts are being scratched back into existence. While Russia is being increasingly cut-off from the global community, it is finding allies in its own backyard with established resentment towards the current world order where the United States and its allies are considered the global pack leaders. Especially, the United States, with its status of being a Mecca of capitalism, and the self-appointed global policeman, has historically often been at odds with Russia. With the United States and its affluent allies in Europe, Asia, the Americas, and Africa clearly enjoying an economic advantage and thanks to pacts like the North Atlantic Treaty Organization (NATO), a higher grade of collective military security, their domination is configured to remain unchallenged. However, in recent times, some so called ‘antagonistic’ nations have started leveraging the unlimited reach and anonymity of the internet to level the playing field.

 

Recent Seeds of Dissent – A New Axis of Power in Asia

In June 2021, after critical infrastructure installation in the United States bore the brunt of suspected Russian cyberattacks in the previous months, US President Joe Biden “informed” Russian President Vladimir Putin that certain critical infrastructure should be “off-limits” to cyberattacks. Immediately, security analysts decried the futility of Biden’s efforts – that the idea of creating safe zones and ethical practices for online conduct is an improbability. A month later, the US and its allies – including NATO, the European Union, Australia, Britain, Canada, Japan, and New Zealand – accused China of instigating a global hacking spree. China fought this accusation – terming the claim as “fabricated” and asserting that it opposes all forms of cyber-crime. Further, the Asian powerhouse claimed that the US had got its allies to make “unreasonable criticisms” against China. Russian officials have repeatedly denied carrying out or tolerating cyberattacks.

Aside from communism, Russia and China have a lot of things in common. An unsure bilateral relationship with the US is definitely a Top-5 item on this list. As if to forge an alignment amid their status as ‘suspect’ countries in the US and its allies’ collective radar, China and Russia announced in June 2021 the extension of the China-Russia Treaty of Good-Neighborliness and Friendly Cooperation. This could be interpreted as two regional powers building an Asian stronghold, importantly, there are also wider benefits: Russo-Chinese relations will be unsettling for the US and its Western partners, complicating strategic calculations, especially in terms of their strategies for the Asian continent.

 

Russia and China’s Recent Spying Spree

A reportedly Russian hacking campaign involving SolarWinds – a supply chain attack on the latter’s IT performance monitoring system called Orion – resulted in the compromise of at least nine US government agencies and thousands of organizations around the world. This was followed by a far-reaching campaign exploiting a vulnerability in Microsoft Exchange Server to break into victims’ email inboxes and later propagate laterally across the organization. This was allegedly led by the suspected Chinese hacker group Hafnium. The collective toll of these espionage campaigns is still being assessed and according to researchers, it may never be conclusively affirmed. A wealth of the world’s intellectual data was tapped into, siphoned off, and the perpetrators and their alleged benefactors may have walked away scot-free.

Aside from financial motives and a sneaky way to benefit the organizations in their own country to match up to the evolving international standards, these exhaustive intrusions can be viewed as a means to question the status quo. Especially, challenging the US and European countries’ standing as global superpowers, champions of capitalism, and influencers to many Asian countries that are drawn by the former’s appeal and are not ready to view the realignment of power in favor of local behemoths Russia and China.

 

Appeasement Fueling Confidence?

As of now, the Western powers are playing nice. NATO had underplayed the aforementioned situation by noting that its members “acknowledge” the allegations being leveled against China by the US, Canada, and the UK. Meanwhile, the European Union (EU) “urged” China to control “malicious cyber activities undertaken from its territory” – an ambiguous statement that implies that the Chinese government was itself innocent of directing the espionage. While the US has been much more specific – formally attributing intrusions such as the one that affected servers running Microsoft Exchange to hackers affiliated with China’s Ministry of State Security – the retaliation, according to official sources, could include economic sanctions and an executive order from the President to harden the federal government networks against future attacks. These sanctions, just as the many imposed before them, were not expected to be effective deterrents.

Could appeasement or leniency prove to be a roadblock here? While there is a line of thinking in the US administration that the usual sanctions are unlikely to force Russia or China onto the negotiation table, the fear is that calling these countries outright could elicit a strong cyber response. Many believe that the Russian and Chinese intrusions resulted in more than just espionage. Back doors have clearly been planted and the same can be leveraged at a future date for more destructive purposes, including modifying or wiping out critical data.

By all accounts, the next big war will be fought in cyberspace. US’s cyberattack on Iran’s missile system, the Russian company Internet Research Agency’s intrusion to spread misinformation through the US presidential elections, the ‘routine’ cyber compromise of mega-corporations leading to distinct societal impact, are all early hints that the powers-that-are have begun to consider the cyber route as a potent weapon. How long before the niceties are abandoned completely and a full-scale war – arising from accusations, sanctions, and isolation of problem entities, as is currently the case – will be underfoot?

 

Cybercriminals and ‘Rogue’ Governments – Hand in Glove?

In October 2021, in response to the growing menace of ransomware attacks and to collaborate more on cyber intelligence, heads of governments and think tanks came together in what could be described as the unprecedented first step towards a global collective against cybercrime. The endeavor was spearheaded by the United States and involved 30 nations (including Japan) while ominously excluding both Russia and China. In a possible response to this and similar developments, CYFIRMA researchers monitoring a dark web forum observed ransomware operators unite as one against the US and its allies’ interests and potentially target them. Details of the post are provided below:

Loosely translated to English: “In our difficult and troubled times, when the US government is trying to fight us, I urge all affiliate programs to stop competing. Unite and start to destroy the state sector of the United States, show this dementia old man who is the boss who is the boss and will be on the Internet. While our guys were dying on honeypots Sachkov from rude aibi squeezed his own … but he was rewarded with higher and now he will sit for treason, so let’s help our state fight such ghouls as cybersecurity firms that are sold to amers like state structures of the USA, I urge you not to attack Chinese companies, because where do we need to worry if our homeland suddenly turns its back on us, only to our good neighbours – the Chinese! I believe that all zones in the US will cope all blacks will go and f**k this f***ing Biden in all the cracks, I myself will personally make efforts.”

The above post very clearly indicates the following pointers:

  1. Potential collaboration between Chinese and Russian threat actors and/or Ransomware operators.
  2. Chinese threat actors using Ransomware-as-a-Service (RaaS) with various ransomware operators.
  3. Attacks on US interests could include the US & its allies like NATO, Japan, etc.

This isn’t an isolated incident. In the recent Ukraine-Russia conflict, the infamous Conti ransomware gang has fully backed Russia and promised retaliation if the West targeted Russian critical infrastructure. These examples highlight a deep nexus between organized cybercrime and governments willing to wield this strategic weapon, while simultaneously enjoying total immunity from possible repercussions via plausible deniability. While China, Russia, and North Korea are the most visible examples of this phenomenon, the trend is finding a lot of takers, especially in Asian countries. From Vietnam, South Korea, Pakistan, to India, everyone is eager to exploit cyberspace for their own agenda where real-world alignments and standings can be ignored in favor of who can compile the most potent and evasive malware code.

 

The New “Democratic World Order”

In modern-day geopolitical equations, every real-world conflict is likely to trigger the unleashing of more unresolved resentment. While Russia has tried to justify its stand on the Ukraine conflict on the world stage, it has found few supporters. Meanwhile, China has assumed a neutral position yet for observers, it is staunchly behind its closest Asian ally. Experts also note that the outcome of current Ukraine – Russia conflict, especially how the world governments respond and try to de-escalate this situation, could inspire China to handle its own ‘issues’ relating to Taiwan, Hong Kong, and disputed assets in the South China sea. On the sidelines of the Ukraine situation, Russia has already started talking about drafting a new “democratic world order” with China. With the availability of such a platform, other marginalized nations like North Korea and Iran – themselves alleged connoisseurs in the cybercrime game – are likely to join in and further divide the world into two distinct factions.

 

Sources:

 

RaidForums Users – Where is their Next Home?

RaidForums Users – Where is their Next Home?

 

Requiring no introduction, the RaidForums(RF) was the leading and most popular hacking forum residing on the surface web. This online community of opportunistic cybercriminals – notorious for leaking valuable data from databases, credentials, credit card information to the latest vulnerabilities & exploits – abruptly come to a closure. Whether it was a seizure by a law information agency or a compromise by a competing threat actor group, no one has come forward claiming the responsibility and little information has come to light concerning its abrupt disruption. Even the question of whether it is a permanent takedown of RF is left unanswered. As a result, defenders and most importantly the intelligence community are only speculating based on events that took place during its disruption. Without dwelling too much on “who” was responsible, as intel analysts, we are more interested to understand “where” the RF users have migrated to carry out their illicit activities.

While there are some obvious choices for threat actors used to operate through RF, our intelligence has revealed there are certainly new ones that have emerged that look forward to grabbing the opportunity and becoming the RF alternative.

 

The Old and Obvious Ones

XSS & Exploit: Both these Russian-speaking forums garnered similar reputation and popularity on the dark web as RF on the surface web. While arguably, RF can be considered a less technically skilled community compared to XXS and Exploit, we see it as the best fit for RF users to migrate to both of these forums. Soon after the closure of RF, conversations around these forums being flooded with RF users start to brew, especially in XSS. However, it certainly does make up for an interesting turn of events as both of these forums are primarily home to Russian users and RF members – before going down – were engaged in multiple anti-Russian activities.

Telegram: For a couple of years in the making, Telegram has emerged as the go-to place for cybercriminals looking to buy/ sell stolen data and engage in related conversations. While this platform may not provide forum-like features, its popularity among cybercriminals is exploded in recent times. This can be attributed to factors like guaranteed privacy, providing a low barrier to entry as compared to DDW forums, eliminating the need to register/ host/ maintain a domain, and support for automation. Given the bad track record of Telegram to tackle the illicit activities that take place on its platform, it becomes an easy alternative for RF users.

 

The Similar Ones

Likes of Nulled, Cracked, Eternia, Eleaks, and others: These forums can be considered most similar to RF in terms of technical skill-set and the style in which they operate. The users who were already active on RF are most likely to, if not active, have an account on these similar forums. Reportedly, an increased number of posts have been observed in some of these forums after RF went down.

 

The New Ones

DarkNetWorld: With the tagline “We love illegal” the forum DarkNet World came into existence soon after the RF incident took place. For defenders, the forum looked like a promising replacement for RF as one of its admins used the pseudonym “Omnipotent” – also used by the RF founder. Possibly suspecting an action from law enforcement for being affiliated with RF, the DarkNet World was quick to clarify that there was no relation with RF. While people behind this forum have been successful in getting the attention in absence of RF, most consider it to be just an exit scam. Most recently, suspecting an FBI investigation, the maker of these forums hosted the FBI’s seizure page and their motive in doing so remains unclear.

Breached: AKA “BreachForums” is visually a replica of RF and run by a former member of RF who goes by the pseudonym of “pompompurin”. The forum is a straightforward alternative to RF, however, not affiliated with RF in any way – the makers claim. The forum appears to come into existence around mid-March, although its domain has been registered for quite some time. The admin “pompompurin” also states that in an event where RF returns in an official capacity the domain will redirect to RF. As an initial observation, we don’t see Breached as a replacement of RF – neither it is aiming to be one. It appears that “pompompurin” has re-purposed one of his old domains to create a temporary community that was loyal to RF like him. At the time of our observation, Breached is close to 1800 members strong and we have started to see RF-like activities.

 

Parting Thoughts

During our analysis, it was found that the seizure page for DarkNetWorld was fake. Also, on their telegram channel, DarkNetWorld has said that their new page is now redblackhat.com, which when checked by CYFIRMA’s threat intelligence team, looks exactly like darknetworld.com. At this point, it is worth mentioning that its reputation has taken a significant hit.

Lastly, we would like to highlight that there is the possibility that the Raid forums page as was and is now, has the potential to be a phishing page.

 

Look Inside Ransomware Gang Through Conti Leaks

Conti gang is one of the largest cybercrime syndicates in the world. Third-party blockchain analysis of their bitcoin wallets estimates up to USD 200 million of annual revenue. Recently leaked chat logs of the group provide unprecedented insight into the life and operations of the gang. From asking leave approval to internal cybersecurity or TTPs used in attacks, these leaks are sure to be studied by analysts for weeks and months to come. Our research team at CYFIRMA has focused mainly on extracting IOCs and TTPs but has also observed interesting insights about the gang’s inner workings.

How are they organized?

After the arrest of REvil members, the Conti gang is now dominating the scene of so-called “big game hunting” groups (focused only on large companies with above USD 100m in annual revenue). Insights into their leaked conversations confirm what threat researchers, including at CYFIRMA – as part of our 2022 Predictions [https://www.cyfirma.com/cyfirma-cybersecurity-predictions-2022/] – have suspected and speculated. Top cybercriminal gangs are organized and operate as a business within their little industry of cybercrime. This includes outsourcing, for example, initial access brokers, typical HR problems, physical offices, and of course, performance reviews.

With the RaaS business booming, the need for reliable talent from low-level programmers to highly skilled pentesters has grown as well. In leaked chat logs, there are conversations of dedicated HR personnel and promotions of referral programs with bonuses. Particularly fascinating and shady is the practice of abusing legitimate headhunting services to hire employees who have no idea who they really are working for. The pressing matter appears to be talent retention as the pay is not too great, working hours are grueling and work is a repetitive cycle of monotonous tasks at Conti “company”.

Also discussed are operational issues of inconsistency and struggle to maintain its infrastructure. Domains, VPNs, and other services are not being properly tracked and renewed on time, causing issues for networks of compromised hosts calling said domains and so on. High turnover of employees also seems to cause human errors in the malware itself, where simple misconfigurations result in unsuccessful breaches and loss of profit.

 

How do they operate?

Before we jump into hacking and tools used, it is noteworthy to mention the use of business intelligence by Conti to learn about their victims. They are particularly interested in reported revenue and information about available cash or if an organization has ransomware/cybersecurity insurance. They also look for contacts of executives or board members in order to harass them and force out the ransom. Two paid tools that were specifically mentioned were ZoomInfo and Crunchbase.

Another interesting observation is shopping for all sorts of cybersecurity products. Naturally, they want to protect themselves against being hacked by the competition or law enforcement, so they buy Antivirus products and EDR solutions for their defense. At the same time, they are buying licenses of all major cybersecurity products to test their own malware and TTPs to keep it functional and stay at least one step ahead in this never-ending cat and mouse race.

The final point is their suspected collaboration with Russian government agencies. While there is still no concrete evidence even with these leaks, there are mentions of the FSB agency and Conti allegedly attacking an organization to gather information for FSB.

 

How do they attack – TTPs?

From extracted IOC and TTPs by CYFIRMA, there is a clear absence of any initial access materials implying heavy reliance on initial access brokers and affiliates to take care of this side of the business. From the snippet below it appears that Conti’s focus is on the speed of lateral movement and access to emails.

The snippet of GitHub repositories mentioned in leaked Conti chat logs

Download the links Conti Ransomware_Mar 2022_GitHub.

While there are a lot more TTPs and CVEs that the CYFIRMA research team extracted from the leaks on GitHub and beyond, this snippet illustrates some of Conti’s favorites. It is clear that they are not trying to re-invent the wheel, rather relying heavily on existing and readily available tools. Their coders focus on locker code and botnet networks.

Combining the previously leaked playbook of Conti, with these recent chat leaks, we can quite clearly see preferred protocols and systems to exploit and tools used for it. Once initial access is obtained, usually, from 3rd party brokers, Conti is well equipped to establish persistence and move laterally for maximum damage in the shortest amount of time possible.

Here are observations of the CYFIRMA research team.

  1. Native OS commands, tools, and PowerShell have become a universal way to execute the most or even entire attack flow. They are already present in victims’ networks increasing crucial speed and detection evasion. Nearly all tools leveraged are being used in their PowerShell versions, including Mimikatz and PowerSploit.
  2. Heavy reliance on Cobalt Strike and its malleable C2 configuration. A large portion of observed GitHub repositories were all dedicated to Cobalt Strike and its configurations, including better menu options for the framework.
  3. SMB and RDP are protocols of choice for lateral movement in Conti’s arsenal of tools for both scanning these protocols and directly exploiting their vulnerabilities. Conti has been particularly quick to adopt the latest vulnerability SMB and RDP exploits, such as PrintNightmare.
  4. In the initial stages of an attack, Conti seems to prefer the Kerberoasting attack if a large volume of more than 3k hosts is discovered. They refer to bots and shares dumping continuity/stability as it is hours long process during network discovery and enumeration.
  5. Mimikatz, UAC Bypass, and Zerologon are a privilege escalation holy trinity with some help of NTDS dumps. These tools and TTPs appear to be a reliable toolkit that works for most of their victims. There are a whole plethora of other mentions, but these and especially PowerShell Mimikatz are the gold standard for the gang.
  6. As no surprise comes the frequent presence of MS Exchange RCE exploits. If attackers could pick one data set to extort the victim for money, it would be the email.
  7. When it comes to data exfiltration, usage of the Mega.io platform with the “rclone.exe” tool has been the top choice of the gang for some time. We have also found the DNS Tunneling PowerShell tool “Invoke-DNSteal”.

 

Conclusion and look into the future

It has been very insightful to see the Conti gang’s preferred methods and tools and how they operate. Like anyone else, they like to stick to what works and incrementally make changes to ensure it keeps working without drastically changing any part of their playbook. From a threat research and defense perspective, this provides valuable information on what to focus on. Notable is the universal adoption of OS native tools and PowerShell, which is very likely going to evolve further into living off the land.

From the organizational perspective, their somewhat impressive and unexpected “ordinary business” structure still has major problems and clearly struggles with issues of efficiency and consistency. However, we can expect that these will get ironed out and consequently, the gang will continue to get better and more dangerous to organizations around the world.

Finally, many are speculating if this is the end of Conti. And it likely is not. They have had leaks before and from the size of their operation, it seems they are almost too big to fail. There is also a suspected connection to the Russian government which makes the discontinuation of Conti even less likely. If it comes to the worst, they are most likely to go with the time-proven strategy of taking a break and coming back stronger than ever with a re-brand.

 

 

Ways to Prevent Cyber Crime Even as IoT Technology Becomes Increasingly Prevalent in 2022

Ways to Prevent Cyber Crime Even as IoT Technology Becomes Increasingly Prevalent in 2022

As we move towards a “smarter” world, the adoption rate of IoT (Internet of Things) and IIoT (Industrial Internet of Things) has grown exponentially. A leading market research firm predicts that the IoT platform market, alone, is all set to grow by USD 12.52 billion by 2025. When it comes to the IIoT data collection and device management market, 39% of the growth is expected to originate from North America alone. Since Growth is very quick, it is very important to avoid Cyber Crime through IoT.

While, on the one hand, these facts and figures highlight the potential of these technologies – on the other hand, the sheer numbers reflect the huge treasure trove of data these devices hold. This also means that the footprint of potential access points for cybercriminals will grow exponentially.

We have found the most powerful way to avoid Cyber Crime:

Secure your Mobile Device with DeFNCE

To put things into perspective, towards the end of 2021 a botnet named BotenaGo targeted millions of routers and IoT devices with 33 exploits which is the most powerful way to avoid Cyber Crime. With a rather low antivirus detection rate, the malware manages to evade defense solutions successfully. What this attack resulted in for businesses was not only potential loss of critical data and finances but also operational disruption and possible dent to their hard-earned reputation.

According to our threat intelligence team, botnets are just one of the many ways in which cybercriminals launch attacks. Denial of Service (DoS), Man-in-the-Middle, Ransomware, Privilege Escalation, Brute Force, Firmware Hijacking, Data Encryption, Eavesdropping, and most of all Physical Attacks are other ways in which threat actors target IoT and IIoT devices.

As per our cybersecurity predictions, in 2022 we will continue to see an increase in business adopting of IoT/IIoT devices and increased number within our homes. We will also witness the attacks on IoT/IIoT and its continued convergence of OT devices, edge computing devices – where data is operated on as close as possible to the point it is collected, as well as a centralized cloud infrastructure that is vulnerable.

Here are some ways to protect your infrastructure:

Move beyond the traditional model of security awareness towards improved simulation and training exercises that mimic real attack scenarios, account for behaviors that lead to compromise, and are measured against real attacks the organization encounters.

Block exploit-like behavior. Monitor endpoints memory to find behavioral patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new. This will be able to provide effective protection against zero-day/critical exploits and more, by identifying such patterns.

Minimize network exposure for all control system devices and/or systems and unless there is a business requirement make sure they are not exposed to the Internet.

Locate control system networks and remote devices behind firewalls and isolate them from the business network.

IoT device owners should keep their software and applications up to date and use complex, unique passwords for accounts associated with their devices. Further, they should avoid connecting to vulnerable devices from untrusted networks, such as public Wi-Fi.

IoT device manufacturers should apply controls around Web APIs used to obtain Kalay UIDs, usernames, and passwords, as this would decrease attackers’ ability to access the data, they need to remote access target devices.

Get Agile Digital Risk Discovery and Protection with DeTCT

 

Cyber Threat Landscape Expands with State-Sponsored Cyber Attackers

Cyber Threat Landscape Expands with Collaboration Between State-Sponsored Groups

By CYFIRMA Research

 

As Ukraine faces hybrid warfare, it is clear that the era of state-sponsored cybercriminals is close to its zenith. For the uninitiated, a state-sponsored cyber attack is a form of defense strategy adopted by nations to target governments, critical infrastructure, as well as the civil society of hostile states.

One incident which is oft-quoted as the best example of a state-sponsored cyberattack is the Stuxnet attack on Iran which was discovered in 2010. This weaponized digital attack against industrial control systems (ICS) was reportedly launched by Israel’s Unit 8200, U.S. Central Intelligence Agency, and the National Security Agency (NSA).

Fast-forward 2022, CYFIRMA’s cyber threat intelligence team has observed state-sponsored groups evolving, innovating, and enhancing their capabilities in the use of malware, ransomware, and TTPs (tactics, techniques, and procedures). It is suspected that these groups have managed to enhance their internet hacking strategy by collaborating with other cyber threat actors, sharing, and benefitting from their experiences and skills.

25% of the campaigns tracked by our team were seen to be launched by the Russian ransomware groups who hired state-sponsored groups affiliated to China (and vice-versa) through the RaaS model (Ransomware-as-a-Service). At the same time, close to 20% of the campaigns highlighted that North Korean hacking groups were hired by Chinese groups under the HaaS (Hacking-as-a-Service) model, making Cybersecurity even more challenging.

So, two aspects have gained prominence in the digital threat landscape with this constant collaboration between state-sponsored groups. The first aspect, undoubtedly, is how cyber warfare is no longer something you see only in a sci-fi movie. It is rather the new uncomfortable reality. Governments across the globe understand how instead of ragging wars across boundaries, crippling the very economy, infrastructure, and manpower of the enemy nation is far more lethal, far more cost-effective, and most of all the best non-violent way to tackle the enemy nation. Though the shift to cyber kinetic does throw light on the violent face of cybercrime, most state-sponsored groups are non-violent in their online crimes.

 

Defense and Deterrence: The Two Building Blocks of a Potent Strategy Against State-Sponsored Groups

 

As per our Cyber Threat Intelligence Team, the collaboration amongst state-sponsored internet threat actors is expected to increase in 2022. Realizing the political agenda of their state masters is the primary goal of these cybercriminals. At the same time, one can not ignore how these groups have built a rather profitable business model by availing of RaaS and HaaS. For instance, our monitoring of the dark web forums highlights that several Chinese cyber threat actors including state-sponsored outfits are hiring North Korean groups as part of HaaS for exfiltrating sensitive details from organizations in return for financial benefits.

Therefore, it is safe to conclude that state-sponsored digital threat actors will find more ways of collaborating across boundaries to further the geo-political-economic agenda of their state masters, and at times also justify their domestic authoritarian policies for wider adoption.

The best way to tackle this condition is to build a viable defense and deterrence strategy. This would mean thoughtful investments in cyber intelligence infrastructure and the global collaboration of nation-states against such cyber attacks. At an organizational level, here are some critical recommendations to protect the critical infrastructure against such internet crimes:

  1. Implement a holistic cyber security strategy that includes controls for cyber attack surface reduction, effective patch management, active network monitoring through next-generation cybersecurity solutions, and ready to go incident response plan.
  2. Establish a robust plan to identify assets by leveraging a Risk-based approach along with the Defence-in-Depth (DiD) method as part of the organization’s cyber security strategy to minimize the cyber risk exposure of vulnerabilities to an acceptable level for an organization.
  3. Implement network traffic or cybersecurity monitoring, cybersecurity incident detection, notification, and alerting by leveraging SIEM (Security Information and Event Monitoring) solutions.

 

DeCYFIR is a Powerful Cyber-Intelligence Platform with Six Threat Views on a Single Pane of Glass for Complete Understanding of External Threat Landscape

Six pillars of cyber threat views include attack surface discovery, vulnerability intelligence, brand intelligence, digital risk discovery and protection, situational awareness and cyber-Intelligence.

DeTCT automatically discovers your digital footprint, proactively monitors the web and social media platforms 24/7, and secures your digital ecosystem.

DeFNCE is your trusted Cyber Defence tool for individuals and businesses. With DeFNCE you can Protect your device & digital footprint, Discover leaked personal data and Stay secure.

 

Understanding Cyber Risk Related to Mobile Apps | Android Banking Trojan – Red Alert 2.0

Understanding Cyber Risk Related to Mobile Apps | Android Banking Trojan – Red Alert 2.0

 

The malware, Red Alert 2.0, tricks users into downloading it by hiding in third-party app stores as fake versions of legitimate applications such as WhatsApp, Viber, and updates for both Android and Flash Player.

Once a user downloads one of these malicious apps into his or her devices and opens it, a popup overlay will appear prompting the user to enter their login credentials. The credentials are sent to the attacker’s command-and-control (C&C) server.

Red Alert 2.0 will block incoming calls from banks, presumably to block verification attempts. The malware also intercepts SMS text messages, sending messages to the attackers for future use. By disrupting the device’s actual communication capabilities, the attackers can maximize the time spent on malicious activities.

 

Distribution Vector

 

The malware is distributed through fake versions of legitimate applications or games via Google play store. Like the above image, the Easy Rates Converter application is a fake app which the application itself is clean. But once the application is installed on the mobile device it contacts its C2 server and requests the user to update the flash player to install an additional payload.

 

Once the user installs the flash player, it requests the user to activate the device administrator.

After the installation of the flash player, it is redirected to Play Store.

 

If a user were to suspect the app to be fake and proceeds to uninstall, the additional payload would still remain in the device.

 

On-Screen Phishing Overlay

The payload gathers information about the device and sends it to the C2 server. The C2 server provides the list of applications that the malware should target.

Whenever the victim launches the target application, the malware will create an overlay of the legitimate application and request the user to provide credentials as shown below.

 

Code Analysis

The app, when installed on the device, will request the user to install an additional payload as shown in the below image.

The list of permissions for the Application is as shown in the figure above. Suspicious indicators include permissions for Internet and permission to install packages.

The highlighted code shows the app trying to contact C2 to download and install the additional payload.

Capturing the network activity on the device, we could see the application establishing a connection with C2.

The application requests for the payload.

Once the payload is installed in the app, it gathers all information from the victim’s device and sends it to the C2 server.

The C2 server evaluates and sends the list of applications the payload should target.

The payload opens an overlay page of the target application to steal credentials and other sensitive information like account details.

 

If you’d like to understand the cyber risk related to mobile apps, pls reach out to us at [email protected]

 

Top 3 Ransomware Entry Points Used by Cyber Criminals

Top 3 Ransomware Entry Points Used by Cyber Criminals

 

In the past 2 years, ransomware attacks have grown by leaps and bounds with the average ransom demand surging from roughly USD 10,000 to a whooping USD 100,000. While there is a lot of discussion around whether companies should pay the ransom or not, based on our cyber threat intelligence and monitoring of the deep and dark web – we bring you a comprehensive list of the common entry points for ransomware into an organization.

During our analysis, we found that the top ransomware groups continue to use emails to start their attack chain. But unlike in the past, emails are just steppingstones used indirectly to launch a lethal attack. According to CYFIRMA researchers, the most common and often-exploited entry points for ransomware groups are as follows:

Phishing for Access to Remote Services

To gain access to the remote access services like RDP/ VPN servers, the threat actors resort to phishing activities to get hold of the credentials. There are several instances, wherein, these groups also employ the credential dumps available on dark web forums. Before the rampant use of phishing, cyber criminals would leverage downloaders as the initial payload. It is since 2020, that there has been a spike in the volume of phishing as an initial payload for a ransomware attack.

One of the recent reports reveals that close to 260,642 phishing attacks in July 2021 took place in the US alone. Given that humans are the weakest links in a cybersecurity framework, CYFIRMA Cyber Threat Intelligence (CTI) suggests organizations consider advanced threat intelligence capability to complement their email security solutions. For an organization, a robust email security strategy should include:

  • a) Full-scale visibility of email threats being faced;
  • b) Implementation of solutions that can correlate and analyze such threat data;
  • c) Understanding of who and what is being targeted;
  • d) Identify steps to counter email threats; and
  • e) Mark external emails with a banner denoting the email are from an external source to assist users in detecting spoofed emails.

 

Leveraging Vulnerable Systems

Vulnerable systems are another low-hanging fruit for ransomware attackers. Some of the most frequently exploited vulnerable internet-facing services include SSL VPN (Fortinet, Citrix, Pulse, SonicWall, etc.), Microsoft Exchanger Servers, Telerik UI-based web interfaces. To overcome all kinds of prospective cyberattacks (ransomware or otherwise), CTI suggests:

  1. Implementation of an advanced endpoint protection solution (EDR) that provides detection/prevention of malicious activities that do not rely on signature-based detection methods.
  2. Updating all applications/software regularly with the latest versions and security patches alike.
  3. In case of running a vulnerable version at any point in time, disable all VPNs (SSL-VPN or IPSEC) until the following remediation steps have been taken:
  • a) Immediately upgrade to the latest available release
  • b) Regardless of the upgrade, reset user password
  • c) Consider all credentials as potentially compromised and initiate an organization-wide password reset
  • d) Contact users to reset their passwords explaining the reason.
  • e) Leverage third-party credential leak monitoring services.

 

Exploit Emails to Deliver Malware

Ransomware attack groups are also known to deliver vicious malware into their target’s infrastructure. And it is through emails that these groups execute malware implants. Hackers’ modus operandi include attaching malicious .xls and .doc in the emails. When unsuspecting victims open these documents, macros will execute, run payload, and load malware on the computers.

According to CTI, organizations should:

  1. Establish a robust plan to identify assets by leveraging a risk-based approach along with the Defense-in-Depth (DiD) method as part of the organization’s security strategy to minimize the risk exposure of vulnerabilities to an acceptable level for an organization.
  2. Create a strategy of layering security controls in the organization to make it difficult for adversaries to carry out reconnaissance, exploiting a weakness in the system and potential exfiltration of data.

As per researchers at CYFIRMA, ransomware attacks are all set to evolve constantly in the upcoming years. We predict that

  1. Operational technology is the next target for ransomware attackers;
  2. IoT will be used heavily as the entry point for ransomware; and
  3. Ransomware attacks on third-party software are all set to grow.

 

Additional Reading:

Double Extortion Ransomware Attack-The Achilles Heel for Organizations (cyfirma.com)

Counter Ransomware Evolution with Zero Trust in 2021 – CYFIRMA

TECHNICAL ANALYSIS OF SMOKELOADER MALWARE

Risk Score: 8

Confidence Level: High

Suspected Malware: SmokeLoader Malware

Function: Mainly act to download other malware and as Information Stealer.

Threat actor Associations: Association with Russians

Other Malwares related to SmokeLoader: Dofoil

First Seen: August 2011 but also recently seen in October 2021.

Target Industry: Multiple

Target Countries: Multiple

 

SmokeLoader is primarily a loader, and its main objective is to download or load a stealthier or more effective malware into the system. First detected in 2011 and its functioning is highly complex, and it increases its capability by adding new tactics/techniques regularly and constantly evolving with time. You may guess the advancement of the SmokeLoader from the fact that it was the first malware that used the “Propagate DLL Injection Method” when just its POC was released by researchers.

SmokeLoader variants are used for the purpose of information stealing, botnet, backdoor as well. SmokeLoader has also been used to install/load cryptominers, ransomware, banking trojans, and point of sale (POS) malware. The functionality of the malware changes with the attack type or target and depends on the modules used by attackers as the SmokeLoader is modular in nature.

Earlier, the SmokeLoader was sold on dark-web portals by the name SmokeLdr and since 2014, it is sold only to Russian-based threat actors.

The SmokeLoader is distributed through malicious documents like word or pdf documents send either through spam emails or targeted spear-phishing attacks. Once the victim downloads and opens the malicious document, the malware drops to the system and in the next stage injects malicious code into a compromised system process like explorer.exe and starts its malicious activity in disguise as a legitimate process.

 

SmokeLoader has been evolved over time and has the following capabilities:

  1. Act as a downloader for other malware like ransomware.
  2. Stealing confidential information.
  3. System and Network Reconnaissance.
  4. Multiple advance anti-debugging and analysis detection techniques.
  5. Anti-Sandbox, Anti-VM, and Anti-Hooking techniques.
  6. Code obfuscation techniques to thwart analysis.
  7. Decrypts code prior to execution and encrypts again after execution.
  8. Capability to encrypt payloads and network traffic.
  9. Implementation of Propagate DLL Injection method to compromise legitimate processes like explorer.exe.
  10. Provide Persistence.
  11. Command and Control Functionality.

 

Initial Analysis:

File Details: As shown in Figure1, the following are the details related to the malware SmokeLoader.

File Type: Windows PE-32 Executable

MD5: 6a8f92ba4df2ba5415cd1fd97fcb87da

SHA256: fa611609c25485e53c73a059ae49eb25b8650727b0cf0d62ae4f72642e1b3d49

Subsystem: GUI

Compilation Time: March 2021

Figure1: Basic Information

Figure1 above shows the basic information related to our malicious file, its hashes, it has Microfoft Visual C++ code and is a 32 bit PE executable. Further, the subsystem is GUI and has a compilation time of March 2021 which is quite recent.

Figure2: Sections

Figure2 above shows the sections present in our malware. All are looking quite normal imported by the malware except .rotuge section which is a suspicious ad when we checked it as shown in Figure3 given below. It is all empty which gives us an indication that may be used by malware later to store and access some code here.

Figure3:

Figure4: Libraries

Figure4 above shows the libraries used by the malware, kernel32.dll used for core functionality such as access and manipulation of memory and gdi32.dll used for displaying and manipulating graphics.

Figure5: Imports/APIs

Figure5 shows above the APIs imported by the malware and indicates towards all the capabilities which we have mentioned earlier can be present int the SmokeLoader.

 

MITRE Attack Techniques:

Sr. No. Tactics Technique
1 Initial Access(TA0001) Spam Emails
Spear Phishing
2 Execution(TA0002) Shellcode
Scheduled Task
3 Persistence(TA0003) Windows Registry Key/Startup Folder
4 Privelege Escalation(TA0004) Windows Registry Key/Startup Folder
5 Evasion(TA0005) Obfuscation
Process Injection/Process Hollowing
6 Credential Access (TA0006) Credentials from Web Browsers & Files
7 Discovery(TA0007) Files and Directories Discovery
8 Command & Control(TA0011) Web Protocols

 

 

AvosLocker is Turning the Double-Extortion Ransomware Scheme Lethal

Subscribe for Latest Updates

AvosLocker is Turning the Double-Extortion Ransomware Scheme Lethal

By CYFIRMA Research

The world of ransomware double-extortion schemes is changing. The extortion model, which started back in 2019 by the operators of the Maze ransomware group, is now being improvised into an even more profitable money-making model. AvosLocker, a RaaS (ransomware-as-a-service) group, has revamped its website by creating a system through which they plan to auction data of the victims who refuse to pay the ransom.

Typically, in a double-extortion ransomware model, if a victim does not pay the ransom, threat actors release sensitive files for free on the dark web through “leak sites”. But by adding the auction feature, AvosLocker is changing the landscape of this type of ransomware attack.

 

AvosLocker: A Ransomware Group Which Can Cause Havoc

Recently, a report quoted AvosLocker among three other emergent ransomware groups which have the potential to create havoc in the cyber world with their targeted attacks.

The modus operandi this ransomware group starts with data encryption and moves on to adding its own extension “GET_YOUR_FILES_BACK.txt” to each of the folders having these encrypted files. Based on the discussions on dark web forums, CTI observes that the group is looking for affiliates, at the same time just like its competitors AvosLocker does provide technical support to its victims which providing the decryption tool.

While a small section of the threat intelligence fraternity believes that given that AvosLocker carries less than 10 attacks in a week and thus the auction feature should be taken lightly; we can not deny the fact that the group has launched some major attacks in Belgium, Spain, Lebanon, UAE, UK, and the USA.

Recommendations

Prioritize resources (based on classification, criticality, and business value) and understand the true scope and impact of a potential ransomware event. It is an important factor in contingency planning for future ransomware events, emergency responses, and recovery actions allowing an organization to prioritize the response and recovery activities.

Implement competent security protocols and encryption, authentication, or access credentials configurations to access critical systems in the organization’s cloud and local environments.

Consider using security automation to speed up threat detection, improved incident response, increased visibility of security metrics, and rapid execution of security checklists.

Employ User and Entity Behavior Analytics (UEBA) in tracking, collecting, and analyzing user and machine data to detect threats within an organization.

Implement least privilege access in the system to locations that could potentially have critical information and be targeted by ransomware.

For a further discussion, reach out to [email protected].

Subscribe for Latest Updates

 

Dridex is Back – This Time on Your Slack

Dridex is Back – This Time on Your Slack

A modified version of the banking trojan Dridex – named DoppelDridex – is being delivered via payloads staged on Slack and Discord CDNs. To launch this malware, several campaigns are leveraging attachments with the Excel 4.0 sheet-style macros to fetch the initial payload that is hosted on domains of popular messaging CDNs such as discordapp[.]com and files.slack[.]com. As these sites are usually ‘allowlisted’ by several network-based control or proxies, several threat actors find them to be attractive launchpads to stage payloads.

DoppelDridex and Threat Groups

TA505

This financially motivated threat group is active since 2014. CTI suspects the group to have Russian origins. Apart from providing initial access development to other threat actors, TA505 is notorious for its Big Game Hunting operations. While several threat actors had distributed Dridex malware, it was this group which was the first one to use this trojan in its campaign back in July 2014.

Target Countries: Canada, Germany, South Korea, UK, USA

Target Industries: Enterprises across Industries, Government Agencies

DoppelSpider

Another suspected Russian ransomware group, DoppelSpider has been active since 2019. CYFIRMA Researchers suspect this threat actor to be responsible for operating DoppelPaymer and DoppelDridex. Researchers have observed this group has been regularly leveraging Slack as well as Discord to drop DoppelDridex.

Target Countries: Austria, Canada, Chile, China, France, Italy, Germany, Japan, Mexico, Qatar, Saudi Arabia, South Africa, Spain, Sweden, Switzerland, UAE, UK, USA

Target Industries: Aviation, Healthcare, Financial Services, Manufacturing, Media, Telecommunications, Others

Grief Ransomware

This ransomware-extortion threat group first emerged in May 2021. It is known to maintain a public leak site where it posts stolen victim data. Threat Actor TA505 is also suspected of leveraging Grief Ransomware to carry out various campaigns/malicious activities.

Till date the Grief Ransomware has targeted the following industries:

  • Education – US
  • Government – US
  • Manufacturing – European Nations, Canada
  • Hospitality – UK
  • IT Services – France
  • Pharmaceuticals – Italy
  • Food & Beverage – France
  • Agriculture – Croatia
  • Online Retail – UK
  • Healthcare – US
  • Advanced Technology – Portugal

Recommendations

Integrate CTI feeds with existing SIEM solutions to allow faster detection and alerting of malicious activities. Enrich threat intelligence by combining local monitoring, internal and external feeds.

Assess and deploy alternatives for the deployment of an advanced endpoint protection solution that provides detection/prevention for malware and malicious activities that do not rely on signature-based detection methods.

Implement identification and prioritization of cyber risks and PII/CII/PIFI (personally identifiable information/ customer identifiable information/ personally identifiable financial information) through risk assessments, vulnerability assessments, and system reviews.

Ensure software and applications are being inventoried, allowing the organization to keep track of software name and version, installation, last patch date, and current known vulnerabilities. This will help organizations support scheduling updates and removing vulnerable utilities that ransomware could exploit and significantly reduce the attack surface.

Immediate action must be taken to isolate the ransomware to minimize the damage to the data, to prevent the spread of infection to other systems and networks, and to minimize the impact on the mission or business.

Minimize business impact by being open and transparent in case of a ransomware event to restore confidence among stakeholders. Restoration activities must be coordinated with internal as well as external parties (coordinating centers, ISP, system owners, victims, other CSIRTs, vendors, etc.)

 

What to Look for When Choosing An Attack Surface Management Tool

What to Look for When Choosing An Attack Surface Management Tool

Attack surface management (ASM) is one of the most essential components of IT security. Any software, hardware, SaaS, and cloud assets that store an organization’s data and can be accessed by the internet make up the attack surface. These all become points of entry for a cybercriminal attempting to steal data. In the past, a company could perhaps profess to have control and awareness on all of its attack surfaces. ASM has long been used to address cyber risk.

Today, protecting an organization’s data has become ever more complex. Companies building applications work with third-party vendors who in turn work with more third-party vendors. For one SaaS product or webpage, hundreds of indirect vendors could be involved. Covid has further exacerbated the situation.

In the months following March 2020, the US saw an intense spike in cyber attacks. Employees are now working from home and using their own internet connections to handle sensitive company data. The use of cloud applications, virtual desktops, sharing of devices with family members can all present security concerns.

Companies were not prepared to keep a remote workforce secure. Many processes and procedures like mortgage approvals have not been designed to be done from less-secure home environments. Many organizations improvised and the results were less than secure. Furthermore, a new government call for data disclosure around the pandemic may force companies to re-evaluate the security of that data. All of these factors have created an expanded attack surface. To protect against malicious attacks, the right ASM is essential for this process.

Pre-Covid ASM

Before the pandemic, companies were certainly facing many cyber threats. ASM was developed to address these threats and ensure asset and data security. In order to keep an asset secure, it must be known. All the assets belonging to an organization must be uncovered and accounted for. ASM is a strategy for doing this and ensuring these assets are secure. In pre-covid days, managing an attack surface would require the following:

  1. Uncover Known assets: Accounting for assets such as a corporate website, servers, and dependencies running on them, such as SaaS applications.
  2. Uncover Unknown assets: Discovering forgotten IT infrastructure, also known as shadow IT, that has been outside of the purview of an IT security team. This could include development websites or marketing sites.
  3. Uncover Rogue assets: Threat actors may have already spun up malicious infrastructures such as malware, typo squatted domains, or a website or mobile app impersonating your domain—all of these need to be discovered.

ASM usually involves several phases—discovery, inventory and classifications, risk scoring, monitoring, and malicious asset and incident monitoring. A decent pre-Covid ASM would uncover all your internet-facing assets as well as those managed by third parties. These would include:

  1. Web applications, services, and APIs
  2. Mobile applications and their backends
  3. Cloud storage and network devices
  4. Domain names, SSL certificates, and IP addresses
  5. IoT and connected devices
  6. Public code repositories such as GitHub, GitLab, and BitBucket
  7. Email servers

Post-Covid ASM

As the threats presented by the expanded attack surfaces of the Covid world grew, all the above was not enough to keep cybercriminals out. From email or Gmail phishing addresses to malicious apps disguised as Covid tracing tools, remote employees have been targeted by cyberattacks. Between third and fourth-party vendors and remote workers, ecosystems have become highly exposed to numerous threats.

The pandemic world posed new and unique security risks to organizations. Companies had to respond quickly to the environment with increased security. As we settle into the ‘new normal,’ there is an opportunity to improve data security further. Many companies are taking a zero-tolerance policy when it comes to poor IT security and actively working to improve the IT hygiene of their employees and infrastructure.

ASMs must become even more sophisticated than the cybercriminals they are attempting to thwart. To protect an organization in the new normal, an ASM needs to be able to do the following:

  1. Have the ability to uncover the risk presented by third-party and fourth-party vendors.
  2. Uncover your data/assets on the dark web. This includes data leaks and assets being discussed by cybercriminals.
  3. Be able to find exposed datasets on the open and deep web, such as open S3 buckets, public GitHub repositories, FTP servers, etc.
  4. Have the ability to risk-rate each attack surface by correlating the exposed asset against industry, geo, tech, or unique ways of rating that are more relevant and accurate.
  5. Have the ability to evaluate threats by looking at an attack surface against vulnerabilities. Doing this increases accuracy significantly and saves time. It is critical to take action before a hacker does.
  6. Use attack surface discovery not just as a ‘detection’ tool but also as a tool to understand a threat actor’s ‘attack path.’
  7. Identify weaknesses not just in technology but also in people and processes. It should evaluate whether your employees and various stakeholders have the training and know what to do to prevent cyberattacks. The ASM should also evaluate the configure process, asset discovery, operational processes while including other IT departments.

The pandemic has brought with it expanded opportunities for cyberattacks. The ‘New Normal’ requires organizations to adopt new tools. It has also brought with it many opportunities to institute new security tools to combat these attacks. Attack Surface Management is one of these tools. However, the previous standards for ASM no longer apply. Organizations must continuously assess threats and have visibility over all assets, third parties, and remote workers. ASM must work in tandem with vulnerability and patch management platforms and be guided by cyber-intelligence to provide continuous monitoring of digital risk profiles. Attack surface discovery, vulnerability intelligence, brand intelligence, digital risk protection, cyber situational awareness and cyber-intelligence should be integrated into a single pane of glass to give cyber defenders a solid hold over new and emerging cyber threats.

 

CYFIRMA Technical Research on Leviathan_CobaltStrike

Leviathan_CobaltStrike

Cobalt Strike is a penetration testing tool that allows an attacker to deploy an agent named ‘Beacon’ on the target machine. The beacon includes a variety of functions like command execution, keylogging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning, and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit.

MD5 |113b04ecf632492b3a91ec4ac3129798

SHA-1 | a983cbdbd8a3caf954282b36b37433eabe4d5374

SHA-256 | d4770c15dd2c804322a1a623b6ce36739684d0e9ced380013d45ef90c38f2e9d

Risk Score: 10
Confidence Level: High
Suspected Malware: Cobalt_Strike
Function: Backdoor
Threat actor Associations: Leviathan
Target Industry: Multiple

CYFIRMA’s Threat Discovery and Cyber-Intelligence platform, DeCYFIR, has flagged the file as ‘Suspicious’ due to the factors illustrated in this report.

The file was analyzed in DeCYFIR and below are findings based on the analysis:

The malware was seen to have multiple suspicious TTPs as shown below:

Usually, the Cobalt Strike beacon injects itself into any running process to evade detection and stay persistent.

It was found to be blocking or disabling the system security services to execute the malware flawlessly. This sample was trying to find out the firewall service and terminate it.

The DLL file has 2 export functions:

Anti Debugging function IsDebuggerPresent() is used to identify the presence of the debugger by returning a non-zero value.

The kernel32 UnhandledExceptionFilter() is also used as an anti-debugging parameter to detect debugger.

The function GetCurrentProcessId() is used to get all process id along with ThreadId, the GetSystemTimeAsFileTime() to obtain current time. The GetTickCount() will take time as parmeter to make malware idle.

GetStartupInfoA is used to retrieve the content of the STARTUPINFO structure from when the calling process is created.

GetUserNameA is used to retrieve the name of the user associated with the thread. To retrieve the name of the local computer GetComputerNameA API is used. The malware extracts the name of the files in the current directory.

HttpOpenRequestA is used to create an HTTP POST request handle.

HttpOpenRequestA API is used to send the request to an HTTP server.

The malware queries the server to determine the amount of data available using the InternetQueryDataAvailable API.

MITRE ATTACK Techniques:

 

THREAT INTELLIGENCE Common Infrastructure Indicators – FIN11 Group Campaigns

EXECUTIVE SUMMARY

Russian Cybercriminals – FIN11 Group is suspected of leveraging common target infrastructure indicators (IoCs) across two major campaigns attributed to them known as EmB0 and Topaz Stone, which are tracked and monitored by CYFIRMA in DeCYFIR.

Based on our research and analysis, we observed multiple similarities between the campaign’s target industry & geography, TTPs (Tactics, Techniques, and Procedures), threat actor’s motives, the malware used, along with shared infrastructure and indicators.

The potential collaboration with North Korean hackers as part of hacker-as-a-service (HaaS) and Chinese hackers under ransomware-as-a-service (RaaS), is also suspected post the detailed analysis that was carried out.

The widespread primary motive of both these campaigns appear to be to the exfiltration of sensitive information, Customer information for financial gains.

CYFIRMA recommends using the reported IOC details for measures against this campaign and threat hunting within your environment.

CYFIRMA Risk Rating for this Research is Critical.

FIN11 GROUP CAMPAIGNS

CYFIRMA observed several similar target infrastructure indicators shared between two major campaigns suspected to be carried out by the Russian Cybercriminals – FIN11 Group.

The two campaigns are EmB0 and Topaz Stone. Following are the details of both the campaigns:

Campaign 1

  • Campaign Name: EmB0 is suspected to be launched on 12 April 2021.
  • Target Industries: Critical Infrastructure, Electricity Supply, Water Management, Transportation, Logistics, Equipment Making, Supply Chain.
  • Target Geographies: USA, Japan, South Korea, Taiwan, European Nations, South-East Asia.
  • Motivation: Exfiltrate design, supply chain information, sensitive information, Personally Identifiable Information (PII), Customer Identifiable Information (CII), Financial Gains.
  • Method Discussed by Hackers and their Interest: Exploiting vulnerabilities, Implanting specialized malwares and ransomware, Lateral movement into the organization.

Campaign 2

  • Campaign Name: Topaz Stone aka камень топаз is suspected to be launched on 1 February 2021.
  • Target Industries: Financial Institutions, Trading, Financial Regulatory Bodies, FinTech, Supply Chain.
  • Target Geographies: Thailand, Singapore, India, Australia, USA, Japan, South Korea
  • Motivation: Exfiltration of sensitive information, system information, financial and customer information for financial gains.
  • Method Discussed by Hackers and their Interest: Malwares, Custom-built exploit, keen on taking over administrative accounts using specialized malware implants.

Similarities between both campaigns:

Following are the similarities observed between both the campaigns:

COMMON TARGET INFRASTRUCTURE

Following are the common target infrastructure indicators observed between both the campaigns:

HYPOTHESIS – POTENTIAL TTPs

Based on our quick research and analysis of the target infrastructure indicators leveraged by the threat actor, the following malware details are observed:

Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities. A set of threat actors named UNC2546, UNC2582 with possible ties to FIN11, Clop, and Ryuk ransomware gangs. The backdoor was suspected to be used in Accellion FTA attacks. Dewmode could download files, delete footprints on the target asset from commands executed by the malicious user remotely.

Ryuk Ransomware: Ryuk is a highly sophisticated type of ransomware that is being used to target organizations all over the world since its discovery in August 2018. With its payloads being found in roughly one out of every three ransomware attacks over the last year, Ryuk is one of the top ransomware-as-a-service (RaaS) groups to amass a fortune of at least USD150 million. The use of worm-like capabilities by developers of Ryuk ransomware suggests that the ransomware operators are evolving in their attack techniques with the motive of cyber espionage and financial gains.

Based on the Attack Mitre framework, the following techniques and tactics are suspected to be used by Dewmode malware/Ryuk Ransomware potentially leveraged by FIN11 Group as part of the campaigns:

INSIGHTS

  1. The Russian cybercriminals have been observed to be very active and have targeted multiple organizations in the past. Our findings show their clear interest in potentially targeting organizations across multiple industries, geographies, and leveraging the common infrastructure indicators during the campaigns.
  2. The primary intent of these hacker groups in targeting foreign organizations appears to be to exfiltrate sensitive details to be sold in the grey market or to potential competitors for financial gains.
  3. CYFIRMA observes clear indicators of Russian cybercriminals suspected of expanding their attack surface and targeting multiple geographies and industries. It is suspected that the cybercriminals and ransomware operators could be operating under the guidance of their masters in carrying out these campaigns.
  4. CYFIRMA observed clear potential indicators of Russian Cybercriminals: A) Collaborating with Chinese Threat Groups and Ransomware Operators under Ransomware-as-a-Service (RaaS model), and B) Possible collaboration with North Korean Groups as part of Hacker-as-a-Service (HaaS model).
  5. Based on the initial analysis of the indicators, it appears the threat actors are interested in exfiltrating data for financial benefits.
  6. We strongly recommend organizations be prepared against potential cyberattacks by the FIN11 Group and other potential Russian Cybercriminals.

RECOMMENDATIONS

  1. Build and undertake safeguarding measures by monitoring/blocking the IOCs and strengthen defences based on the intelligence provided.
  2. Webservers and application servers need to be updated/patched to prevent attacks such as remote code execution (RCE), which could lead to data exfiltration, data breach, etc. This may also need to be done as needed if critical exploits exist, and a patch and/or workaround is available.
  3. Configure network defence systems such as intrusion detection systems (IDS), intrusion prevention systems (IPS) for real-time alerts.
  4. Deploy an advanced Endpoint Detection and Response (EDR) engine as part of the organization’s layered security strategy.
  5. Limit the unsuccessful login attempts with account lockouts and progressive delays into the login process to make it effective.
  6. The use of CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is effective against automated bots.
  7. Restrict the logins to a specific range of IP Addresses.
  8. Implement Multi-Factor Authentication (MFA) to reduce the risk of potential data breaches.
  9. Make the root user inaccessible via SSH by editing the sshd_config file and implementing ‘DenyUsers root’ and ‘PermitRootLogin no’ options.
  10. Move to a non-standard port for SSH instead of using the default port 22 and edit the new port line in the sshd_config file.
  11. Move to a non-standard port for SMB, RDP instead of using the default ports.

 

Cyberthreats to SMBs in APAC – Part-3: The Cyber-readiness Gap

By Mihir Bagwe, Snr Technical Writer @ CISO Mag

The Cyber-readiness Gap

Here’s a quick recap of what we read in the first two parts of this series. We saw how SMBs have become the mainstay of economies in the APAC region. However, in the second part, we saw the byproducts of this booming sector as the cyberthreat landscape for SMBs continued to surge. But businesses paint a different picture altogether. They feel they are well equipped and prepared to take on the cyber threat “Goliath”. But are they? Let’s see…

Putting in place a dedicated cybersecurity team is just the first of many challenges that an SMB owner faces, but it is a prime one. It begins with educating themselves about the importance of cybersecurity for their business in the first place, then finding the right talent, and then shelling out an extra bit on the recommendation of tools and technologies that they suggest. This can burn a big hole in the SMB owner’s pocket and often is regarded as a reason why they overlook having cybersecurity personnel on board.

Most of these businesses are either bootstrapped or have limited funding, but this does not leave them with much of an option for cybersecurity budgets. Moreover, there is already a “demand and supply” crunch for cybersecurity. Meaning, cybersecurity demands three core components, skilled people, process, and technologies, which are all scarce at the moment. But it is also the only way SMBs can build a cybersecurity culture in their business.

People

At a time when the cybersecurity talent pool is most required, estimates state that unfortunately, up to 3.5 million cybersecurity jobs will go unfilled this year according to Cybersecurity Ventures. The uptake of formal cybersecurity education at the university level has seen a gradual increase over the past few years. But what needs to be understood is that it takes time to educate and train highly skilled professionals, and then a bit more time for them to gain practical work experience. But this talent is mainly absorbed by industry heavyweights and the SMBs are often left high and dry with an under-skilled workforce, which at times only has theoretical knowledge rather than the practical set.

The solution to this Problem
  1. Technology is important, but it is the people who use it. Train them to abide by basic security principles.
  2. Cross-train your employees.
  3. Build a security first consciousness within your company.

Process

Policies, processes, and procedures help companies to stay in control of their cybersecurity architecture. And although there are various frameworks around the globe like NIST in America and SMESEC in the European Union for SMBs of these respective regions, there does not seem to be any formal cybersecurity framework specifically designed for SMBs in the APAC region. This is the need of the hour and we hope formal bodies are listening to it. In the meantime, what can SMBs in APAC do?

The solution to this Problem
  1. Have an acceptable yet comprehensive user policy.
  2. Create a playbook for different security scenarios and for different business modules too.
  3. Conduct a periodic external IT audit.
  4. Keep your employees and management updated on the latest cybersecurity news.

Technology

For an SMB owner, cybersecurity can cause technological headaches. The Internet of Things (IoT) is one of the most exciting components of the evolving technology landscape. We are seeing the arrival of tools that can communicate seamlessly with other machines for simplifying the way we live and work. IoT is gradually becoming more ubiquitous and helping especially small businesses grow at a faster pace.

For example, a coffee shop owner who had to pay for manhours of a person to simply take orders from its customers and serve them has now introduced tablets on their tables. QR codes on tables and restaurant apps have also now become the new norm in a society that is more aware of hygiene and social distancing. Tablets and apps offer two key benefits. First, it improves efficiency in the kitchen. The time for taking the order from the customer and conveying it to the kitchen is next to negligible. This helps coffee shops and restaurants to dish out to their customers in lesser time than before. Secondly, the self-service culture aided by digital technologies means recruiting fewer people to wait on tables, and this can bring in significant cost savings for restaurant owners.

However, one of the most pressing issues with such technologies is the security considerations it comes with. As the number of IoT and new-age devices increases, the risk of “rogue” technology is now higher than ever. For this reason, SMBs need to keep fine-tuning their cyber defense technologies, but the lack of people and process capabilities to do this often hampers their technology efforts.

The solution to this Problem
  1. Defend against known malware by using a comprehensive antivirus solution.
  2. Endpoint security is of utmost importance. So have one for ALL your endpoints. The cost is equivalent to that of an antivirus solution. So, this is a viable investment.
  3. Have a data backup solution.
  4. Use two-factor authentication for all endpoints and systems of your small business. This should include owner’s as well as employees’ mobile and laptops.
  5. Be aware of your cyber and digital risk profile.

In APAC the most commonly used security tools of SMBs include web application firewalls (WAF), cloud access security broker (CASB), and software and application scanners for detecting respective vulnerabilities. The ability to discover digital risks and their impact on business operations remains elusive.

Digital risks include uncovering attack surfaces where hackers can find their way in as well as the continuous monitoring for vulnerabilities that exist in the various technologies which SMBs have implemented. The once-a-year pentest would not be sufficient if businesses want to ensure they are protected 24/7.

Businesses that are not equipped to detect data leaks or breaches would continue to put their business at risk. The “head in the sand” mindset will not work if they want to take a proactive approach to stem out attacks and put a stop to hackers’ pilferage.

As competition heats up on the business front, the need to ensure the brand is not hijacked or negatively impacted is of utmost importance. This means business owners need to be equipped with the knowledge of any brand impersonation and infringement and these issues could show up as lookalike domains, fake social media accounts, and more. All of these digital risks can easily translate to a direct business impact if left unattended.

To help SMBs overcome their cybersecurity challenges, CYFIRMA has built a solution that can help businesses build a stronger defense against cyber threats.

Learn more about CYFIRMA’s Digital Risk Discovery platform, DeTCT, here.

 

Cyberthreats to SMBs in APAC: Part-2 The Looming Cyberthreats to SMBs

By Mihir Bagwe, CISO Mag

In the first part of this series, we have already seen why small and medium businesses (SMBs) are the backbone of modern economies and hold the lion’s share in the majority of APAC’s GDP. But the pandemic has impacted the growth of SMBs and owners today have to re-strategize their businesses and operations. And this has become the catalyst for rapid digital transformation. However, with some pros, come some cons and digital risk tops the list. So, let us discuss what challenges do SMBs have to face from threats in the digital world.

Let’s take a dive into some of the latest facts and figures related to cyberthreats and attacks aimed at SMBs.

The Numbers Game

As per a global small businesses survey, almost 25% of small businesses feel that their cybersecurity protection is inadequate.

A PwC survey stated that of the total number of reported cyberattacks that took place in the APAC region during the last year, 75% of them were specifically targeted at SMBs.

57% SMBs sustained cyberattacks in the past 24 months with 76% of them suffering more than one attack.

44% of the SMBs reported a data breach in the past 24 months.

Nearly 60% of the data breaches reported by SMBs in developed markets of Australia, New Zealand, and Singapore, were due to third parties.

The average detection time of a cyberattack in APAC is 54 days.

As per Cisco’s “2020 CISO Benchmark Study,” 46% of SMBs with < 1k employees had 5-16 Hours of Breach-Related Downtime.

83% of data breaches against SMBs are financially motivated.

52% of the SMBs surveyed in APAC for the “SMB State of Cybersecurity” report, agreed to lack of in-house skills necessary to properly deal with security issues.

Since the beginning of the pandemic, 86% of SMBs now place cybersecurity within their top five priorities of their organization.

As per an Infrascale report, globally 83% of the SMBs felt they were prepared for a ransomware attack. However, 46% have been targeted successfully, and a staggering 73% have made ransom payments.

Of the above, 43% percent of SMBs paid ransom ranging between $10,000 to $50,000 and 13% said they were forced to pay more than $100,000.

In APAC, more than 30% SMBs suffered damages between $50,000 to $250,000, while another 9% sustained damages of more than $1 million.

Reportedly, 22% of SMBs switched to remote work without having a full-proof cybersecurity threat prevention plan in place.

These numbers certainly suggest that the cyberthreat landscape for SMBs is growing alarmingly and is very concerning, to say the least. But what are the exact threats? How do they intrude on the networks in the first place? How much bearing does it have on your pocket? Let us dig deeper.

Cyberthreats to be wary of

The end goal of a cyberattack is to explicitly steal and exploit the customer, employee, financial data, or the intellectual property of the targeted business. But there is an order to this chaos. Notably, SMBs are at a higher risk of the following threats in the immediate future:

Our Old Nemesis – Malware

It is a malicious code or software that is specifically designed to damage, disrupt, steal, or in general inflict some of the other “bad” or illegitimate action on data, hosts, or networks, on which it is injected. This is regarded as a top threat because in general, 70% of Asia Pacific’s SMBs have experienced an incident of an exploit or malware evading the intrusion detection system adopted by them.

How to Avoid Malware Damages?

The National Cyber Security Centre’s “Small Business Guide for Cybersecurity,” suggests that SMBs should adopt a “defense-in-depth” approach. This means using a layered defense mechanism that has several mitigation steps at each layer. However, it notes that the most important mechanism that SMBs need to have in this case is a real-time digital risk assessment and protection mechanism or platform. Smaller businesses need to proactively keep track of their digital footprint for validating attack surfaces, vulnerable systems, and data leaks. The quicker they can detect their threats, the better armed they are to plug the gaps and deflect them.

The New Cartel in the Digital Space – Ransomware

As per a “Beazley Breach Report 2020”, 62% of ransomware attacks were targeted at small businesses. This is a stark reminder to the people who believe in the myth that “ransomware gangs only go after larger companies since SMBs do not offer anything valuable to them.” Now let’s figure this out. Like the big players, SMBs also store data, which includes credit card numbers, protected health information (PHI), personally identifiable information (PII) and even biometric data in some cases. For cybercriminals, this is equivalent in value to GOLD. They can pilfer and use this data to take out loans, steal identities, make wire transfers and complete other scams.

Another reason why ransomware is a serious threat particularly to SMBs is the fact that this type of attack can mean the end of the road for a small business. One such example of an SMB calling it a day due to a ransomware attack is that of the Heritage Company. It was asked to pay-up if it wanted to get its systems back online. After weighing its options, the Arkansas-based telemarketing firm paid the ransom. But that did not end the nightmare. Its system had been trashed, and two months later it still failed to recover its data. The company restructured to stop the bleeding but to no avail. Eventually, it was forced to shut down as it could not take any more financial drain.

How to stop ransomware in its tracks?

Follow these four easy steps:

  1. Install quality endpoint protection which includes web and email protection.
  2. Take regular offline backups to make sure all key data can be reliably restored.
  3. Train your employees to spot latest forms of ransomware delivery methods.
  4. Install a real-time tracking solution that can monitor your employees’ credentials, customer PII, and other critical data on the open and darker side of the internet – the hackers’ forums, dark web, and bin sites.
The Regulars – Phishing and Business Email Compromise

In the Asia Pacific, phishing remains one of the top three cyberattack types suffered by SMBs. One in every three SMBs has reported facing this attack in the past year.

Through the cycle of the ongoing pandemic, phishing scams have only seen an uptick. In the initial days, it leveraged COVID-19 testing and the associated anxiety, and now vaccine-related phishing scams are bursting through the roof.

Another popular type of attack that scammers have been successfully adopting in recent years is business email compromise (BEC). In a BEC attack, cybercriminals first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds/wire transfers, and deleted accounting trails. However, the recent traits in a BEC attack have found scammers posing as HR specialists recommending vaccines to their employees and exploiting the emotions of their victims.

Both phishing and business email compromise attacks are now getting sophisticated, persuasive, targeted, and are very well disguised. They will keep coming at you no matter what. Because the weakest link in your business security is…YOU! To mitigate the human threat, we need to work on changing cyber user behavior.

How to Prevent a Compromise through a Phishing Email?

Follow these steps:

  • Train your employees to identify phishing emails. ALL of them!
  • Run periodic phishing simulations to test their vigilance and keep them better prepared.
  • Keep following steps 1 and 2 again, and again… and again.
  • Consider incentivizing employees who act responsibly and report phishing attacks.
  • Counsel those who repeatedly fail or ignore internal phishing drills.
Proliferation of mobile, IoT and BYOD devices

Since the onset of the pandemic, mobile and BYOD (bring your own device) devices have been deemed as saviors for business continuity. The relatively recent developments such as Internet of Things (IoT) devices, biometrics, and the use of personal mobile devices for work have been quickly and broadly adapted by SMBs. However, these new endpoints and revolutionary technologies such as IoT appear to be one of the major factors driving these cyberattacks towards SMBs. Why? Because security technologies and practices tend to lag in these areas.

Companies may be aware of this, yet many feel helpless.  In APAC, the most vulnerable endpoints in an SMBs operational ecosystem were identified as desktop and laptop computers (44%) with an equal weightage given to web servers (44%). These numbers suggest that SMBs are aware of their weak links, however, it is alarming to note that only 53% of SMBs have antivirus solutions in place.

Mobile devices, IoT, and BYOD are currently the weakest link for not just SMBs, but businesses of all sizes. But the scale tilts further for small businesses because their entire business ecosystem is thriving on these devices.

So, how to keep your devices protected?

Follow this simple three-step process:

  1. Use a strong password and multi-factor authentication.
  2. Have antivirus or anti-malware software installed on all your mobile devices.
  3. Update all devices with the latest security patches and software versions.

The attack surface for SMBs is growing at an unprecedented rate as newer IoT devices and technologies keep taking center stage. It is now becoming increasingly difficult to track and keep an account of your entire digital footprint, more so because of a resource crunch (both money and manpower), that majority of the SMBs are currently facing. To address this issue and keep a track of your entire digital footprint, you may take help from an able hand like CYFIRMA’s DeTCT.

CYFIRMA’s DeTCT can uncover the digital risks profiles for SMBs and help them detect the following:

  1. Gain awareness of the potential attack surfaces including forgotten systems and applications in which hackers can find their way in.
  2. Fake identities of your business executives – these can be fake social media profiles, fake email IDs. These are signs of potential phishing campaigns where threat actors can impersonate persons of authority to trick other employees or even potential clients into clicking malicious emails.
  3. Look-alike domains and websites – created to deceive users into believing fake content or divulging personal/financial information.
  4. Your IP addresses, employee credentials, customer personally identifiable information are mentioned and thrown into underground forums, dark web, bin sites. This means threat actors have found a way to breach your defenses and have exfiltrated important data.
  5. Vulnerabilities in your system, software and applications which if left undetected and unattended would leave the door wide open for hackers.

For more information on CYFIRMA’s DeTCT, click here.

 

Stay tuned for Part-3: The Cyber-Readiness Gap

 

SMBs – the Backbone of Growing Economies

SMBs – The Backbone of APAC Economies

If you are a small or medium-sized business (SMB) and still surviving the wrath of the ongoing pandemic, then pat your back, and take a bow. Not many have survived, but you did. You already are a winner!

These unprecedented times have tested the mettle of all business sizes around the globe. But this cannot hold truer than for the small and medium-sized businesses. We say so because when it comes to the Asia-Pacific region, SMBs hold a market share of more than 90% (in some countries this goes up to 98%) of businesses and employ a whopping 50% (the number goes above 90% in some Asian countries) of the total workforce.

SMBs in the APAC region contribute nearly 17% to the national GDP. However, this number shoots up three times in the higher income countries like Malaysia and Singapore, where their contribution is nearly half of the country’s annual GDP (40 to 50%).

COVID-19 Pandemic Gives a Wobbly Wheel

The number mentioned above has taken a beating since the beginning of the pandemic though. As per Facebook’s ongoing research collaboration with the Organization for Economic Co-operation and Development (OECD) and the World Bank, 1 in 4 (24%) Global SMBs have reported closures by February 2021 and an astonishing 55% decline in sales.

These numbers, however, increased while speaking about the condition of businesses in the APAC region. The report stated that 61% of small-medium businesses reported a drop in sales volumes and an overall 45% of the workforce faced the axe due to the COVID-19 pandemic. This trimming of the workforce and the need to paddle harder through troubled waters of the pandemic has led to an increase in the adoption of digital tools in SMBs.

However, this embrace of digitization has aroused the interest of major cybercriminals groups who until now were only interested in the big-ticket names. A 2021 Data Breach Investigations Report shows that 46% of all cyberattacks targeted globally were aimed at SMBs. This means the number has exactly doubled in a year where it was hovering around the 28% mark previously. The reason? Mass digitization wave owing to the pandemic.

Digitization Drive of SMBs

Since the onset of the pandemic, stringent lockdowns were imposed around the globe. This made the situation precarious for SMBs as they struggled with multiple challenges such as disruptions in logistics, restrictions on labor mobility, overall declines in demand or market orders, and a subsequent drying up of cashflow. The challenges are uneven across the industries. For example, export firms suffered more than others, due to a decline in external demand and a lack of key raw material supplies, whereas those in the manufacturing sector reported more problems with supply chain disruptions.

However, in the face of adversity, SMBs found an ally that would help them get through this torrid time and not only help them recover but also leapfrog competitors who are digital laggards. Yes, we are talking about the ally named “Digitization” – the use of digital technologies and digitized data to impact how work gets done, transform how customers and companies engage and interact, and create new (digital) revenue streams.

According to the “2020 Asia Pacific SMB Digital Maturity Study”, based on a survey conducted by the International Data Corporation, 94% of SMBs in APAC say they have become more reliant on technology to ensure business continuity during the pandemic, while nearly 70% say they are accelerating the digitization of their businesses to cope with the situation.

Digitalization cannot happen without digitization – the conversion of business processes and data from analog to digital.

Evidently, SMBs have started using or have increased their usage of digital tools at some point in the customer lifecycle, since the onset of the pandemic. The biggest advantage of the digital medium is that it helps them immensely to reach their customers directly. It seems easy, gives great ROI but like all services, it comes with its own set of challenges, and cybersecurity is one of them.

The digital risk faced by SMBs is immense and can be categorized into two broad areas – the lack of cybersecurity awareness and the shortage of cybersecurity resources. This has resulted in the inability to recognize cyber risk and thus unable to plan and implement mitigation strategies. The basic understanding of attack surfaces can be sorely lacking when business owners are uninformed of how cybercriminals could compromise a network and steal data. Every system or application that is somehow connected to the Internet can turn into entry points for hackers with malicious intent. By rapidly moving their processes into digital formats and connecting to third-party systems, SMBs would have added many potential attack surfaces overnight. Furthermore,  not fully understanding how the software supply chain works, SMBs can be easy targets for enterprising cybercriminals.

In many instances, SMBs would not even be aware that they have been compromised, that data related to their businesses, partners, and customers would be floating in dark web marketplaces and sold over and over again. Not knowing they have been breached, these business owners would not be able to take action to strengthen their defense.

Without adequate IT and security resources, SMBs would be exposed to vulnerabilities which they would be unable to mitigate. These could come in the form of expired certificates, weaknesses in their operating systems and applications, unpatched software, and more.

SMBs could also be in the dark should hackers impersonate their domains, companies, websites, social media profiles. These are all signs of phishing attacks and scams in the making.

The threats associated with SMBs are growing by the day. The lack of basic cyber hygiene can hinder SMBs’ growth and threaten their long-term business viability.

And before the problem escalates, we would recommend SMB owners onboard a technology partner that can help them gauge their digital exposure so they would have a pulse on their digital risk profile and can start to take actions to close cybersecurity gaps.

One such technology partner would be CYFIRMA’s DeTECT.

DeTCT helps businesses remove the blind spots in their cyber risk profile and arms them with critical information of data leaks, breaches, and impersonation related to the business. Equipped with this knowledge, business owners can implement the right solutions confidently and accelerate their business growth.

For more information on CYFIRMA’s DeTCT, click here.

Stay tuned for Part-2: The Looming Cyberthreats to SMBs

 

Double Extortion Ransomware Attack – The Achilles Heel for Organizations

It was in 2019 when America’s security staffing company, Allied Universal, was hit by a cyberattack, that Double Extortion Attacks came into the picture. Fast forward 2021, just like WFH (work from home) amidst the COVID-19 pandemic, even double extortion ransomware attacks have become the new normal. Simply put this technique involves:

  1. Stealing of confidential data and encrypting the victim’s files; and
  2. In case the victim refuses to pay the ransom, to expose the data online

No doubt that double extortion attacks boost the threat actors’ chance of making profits, but it also highlights the various ways in which cybercriminals are improvising on their attack arsenal. Even in cases where data backup is available, it is the kind of pressure and potentially serious consequences – like reputation damage – which makes these attacks highly potent and dangerous. One best example of this case is the REvil group. Rather than simply leaking the data online, the group prefers to monetize the stolen data by auctioning it on the dark web – thereby increasing the pressure on its target.

Ransomware operators have traditionally relied on operational disruptions and reputational damage to force victims to pay the ransom. However, their tactics are consistently improving. Some operators are attempting to build trust with the victims by adhering to a set of “principles” and providing “guarantees”. Another approach may involve “Ransom DDoS attacks” (RDDoS) where the RDDoS attackers use the threat of taking down the organization’s network or other such aggressive approaches.

Ransom Distributed-Denial-of-Service (DDoS) attacks begin with a ransom note served to the targeted organization about an impending attack. This could be accompanied by a demo attack to prove the attacker’s intent and capability. If the targeted organization chooses to ignore this ultimatum, they could be inundated with attack traffic generated by either their botnets or by a DDoS service they hired. Such attack traffic is likely to target layers 3, 4, or 7 in the Open Systems Interconnection (OSI) model, ergo the Network Layer, Transport Layer, or the Application Layer. As a result, the targeted application or service slows down to a crawl or crashes completely. Usually, after their point has been proven, the attackers will renew their ransom demand.

In a world where downtimes equate to financial losses, the threat of RDDoS is likely to garner the potential victim’s undivided attention. Process-driven industries are attractive targets for ransomware attackers as a break in the supply chain and ecosystem would cause significant disruption, prompting the victim to pay the ransom rather than face reputational damage, loss of business, and the impending costs associated with recovery operations.

At present, ransomware operators are suspected to follow a 4-layer approach of targeting organizations which includes:

  1. Infiltrate into the target organization’s network;
  2. Exfiltrate and encrypt data;
  3. Demand ransom and “Name & Shame”; and
  4. Leave behind their footprints in the targeted organizations to come back and attack again.

The double extortion attack, thus, is not only a milestone in the ransomware landscape – rather it is a clear indicator of how mature the cyberattack strategy has grown. Evolving from plain opportunistic attacks to a well-studied, planned, and executed maneuver – these attackers are pushing cybersecurity personnel to up their game.

New Cyberattack Strategy Through Old Attack Vectors?

To say that phishing, or rather spear-phishing (to be precise) is the primary way in which double extortion attacks are executed would be true and at the same time quite an understatement. If one were to look into the modus operandi of most double extortion attacks, there is a glaring pattern and a common denomination that is being exploited. These attacks usually thrive on the vulnerability of the on-premises devices – with internet-facing systems being their prime target. For instance, since the end of 2019, almost every VPN (virtual private network) vendor has suffered severe vulnerabilities. With VPNs being directly exposed to the internet and providing access to internal resources, it has emerged as an ideal target for double extortion attacks.

Some of the vulnerabilities affecting the VPN devices actively exploited to inject ransomware are CVE-2019-11510, CVE-2018-13379, CVE-2019-1579, CVE-2019-19781, CVE-2020-2021, CVE-2020-5902.

Apart from VPN concentrators, internet-facing systems like RDP (remote desktop protocol) is also providing double extortion opportunities to threat actors. While opening up the RDP connections directly on the internet is insecure, with the ongoing pandemic this was the route most organizations resorted to providing remote access to their internal resources. The extent to which this move exposed businesses to cyberattacks can be gauged from the FBI’s Private Industry Notifications to K-12 schools warning them about the risks of ransomware attacks leveraging open RDP connections.

DDoS – The Newest Trend in Double Extortion Ransomware Attack

Distributed denial of service (DDoS) attacks is the latest trend leveraged by ransomware groups to execute double extortion. With the COVID-19 pandemic and the subsequent WFH scenario, the DDoS attacks have made a major comeback. Not only has there been a rise in its frequency (surpassing 10 million attacks in 2020 as against 8.5 million in 2019), these attacks emerged more lethal and powerful. For instance, in September 2020, the SunCrypt ransomware adopted DDoS as an added tactic for double extortion. The surge in bitcoin prices in recent times is yet another reason why this tactic is used by ransomware gangs.

Thus, from being a seasonal event, DDoS extortion campaigns have morphed into an integral part of the threat landscape for organizations targeting nearly every industry since mid of 2020.

The trend is expected to continue given the growth in the use of connected and Internet of Things (IoT) devices.

DarkSide Ransomware – Exposing the Sinister Aspect of Double Extortion

Human-operated ransomware, DarkSide works on ransomware-as-a-service (RaaS) business model – with ransom demands ranging from $200,000 to $2,000,000, depending on the size of the compromised organization.

This ransomware group follows the double extortion tactic – meaning not only do they encrypt the user’s data, but also exfiltrate it and threaten to make it public in case the ransom demand is not met. The first step of their attack method is to harvest the clear text from the victim’s server, after which they encrypt it and demand ransom. Darkside ransomware group then make a backup of this data in its own servers.

The group prefers high-value targets such as banking and financial institutions as these are deemed as repositories of customers’ personally identifiable financial information (PIFI).  For instance, the recent attack on Banca di Credito Cooperativo (BCC) in Rome was conducted by the DarkSide ransomware group. The attack affected the operations at 188 branches causing serious distruptions to the bank.

Similarly, the American subsidiary of a prominent Japanese manufacturer, Komari, was targeted by the DarkSide ransomware gang in March 2021. The incident resulted in the exfiltration of critical data including personal data of clients, details of agreements, information about company activities, etc.

Apart from leveraging the double extortion tactics, the modus operandi of DarkSide also reflects the growing trend of Ransomware-as-a-Corporation (RaaC). When it comes to its tactics, techniques, and procedures (TTPs) the operation of this group is similar to Maze, NetWalker, Sodinokibi, and DoppelPaymer. What differentiates the DarkSide ransomware group from other threat actors is  its targeted attack methodology, highly customized ransomware executables for every target, and a communication process which is highly corporate-like.

Apart from making headlines for its aggressive attack tactics, the group gained attention for its ‘ethical’ principles which executing an attack. The DarkSide operation is never targeted towards vulnerable and critical bodies like hospitals, schools, and even governments – a silver lining in the era of double extortion ransomware attacks?

The Possible Solution?

Organizations recovering from ransomware attacks must determine how the malware was able to enter their network, even before they start thinking about restoring it. The key learning from such an incident must be to understand the degree of compromise – the how, when, what, and why equation. It is possible that to install the ransomware, operators would have leveraged backdoor access to the network using remnants from a previous malware intrusion. Ransomware operators are increasingly leaving behind footholds that could be exploited in a future attack. By not examining how their network was originally compromised, potential victims are helping the ransomware operators’ cause.

Recently, UK’s National Cyber Security Centre (NCSC) wrote in a blog post about one such incident where the victimized company paid millions in bitcoins to secure their stolen files and restore the compromised network. Unfortunately, they failed to analyze how the cybercriminals originally infiltrated the network. In less than two weeks after the settlement, the same ransomware gang infected the now restored network with the same ransomware.

Updating all your internet-facing devices with the latest patches is the first step towards containing all kinds of cyberattacks, especially ransomware attacks. Restricting users’ ability (permissions) to install and run unwanted software applications is yet another way in which the attack surface can be reduced.

It will be wise to assess and deploy an advanced endpoint protection solution that provides detection/prevention for ransomware activities that do not rely on signature-based detection methods. We would also recommend organizations be prepared for ransomware attacks by constructing a business continuity plan that includes backup and recovery.

The best outcome would be to prevent the ransomware attack from occurring in the first place. This requires a telemetry system with insights into cybercrime in the making where defenders are equipped with early warnings to thwart an attack.

 

 

SOLARWINDS HACK – Sunburst, Supernova and more

Research on this cyberattack is ongoing. Its full magnitude and impact are still under investigation. This report will be updated by CYFIRMA researchers as new data comes to light.

Report covers the following:

OUTLINE

1. Summary
2. Introduction
3. Key Findings
4. Suspected Threat Actors
5. Insights
6. YARA Rules
7. Recommendations
8. Indicators of Compromise
9. Extract of List of Organizations affected by the campaign (As of 21 December 2020)

SUMMARY

Attack Vector: Vulnerabilities and Exploits, Steganography
Objective: Lateral Movement, Data Exfiltration, Credential Theft
Suspected Hacker Group: Unknown Russian Groups <Reach out to CYFIRMA for details>
Target Country: Global
Target Industry: Government agencies, Universities, Manufacturing, Hospitals, Telco and Technology, Semiconductor, Retail, Financial, and many more
Type of Attack: Supply Chain
Target Technology: SolarWinds – Orion Platform 2019.4 HF 5, 2020.2 with no hotfix, and 2020.2 HF 1
Detected Date: 13 December 2020
Attack Status: On-going
Risk Rate: High

INTRODUCTION

As per researchers, threat actors have gained access to numerous institutions and organizations around the world in a widespread campaign, known as UNC2452. This was executed by trojanizing SolarWinds Orion business software updates that inserted a vulnerability (SUNBURST) within their Orion Platform software builds for versions 2019.4 HF 5, 2020.2 with no hotfix, and 2020.2 HF 1, which, if present and activated, potentially allowed attackers to compromise the server on which the Orion products run.

Subsequent activity after this supply chain compromise has included lateral movement and data theft. The campaign is the work of a highly qualified set of possibly state-sponsored threat actors and the operation was carried out with significant operational efficacy and competency.

The cyberattack, which began to be exploited last spring, targeted numerous entities of the US administration, in addition to public and private organizations from around the world. Potentially attributed to Russia, it would be one of the most unsettling attacks identified in years.

In the subsequent analysis of the trojanized Orion artifacts, the .NET .dll app_web_logoimagehandler.ashx.b6031896.dll was dubbed SUPERNOVA, details of its operations are still being uncovered and progressively getting explored publicly.

After an initial period of inactivity of up to two weeks, the backdoors recover and run commands, called “Jobs,” which include the ability to transfer files, run files, profile the system, reboot the machine, and disable system services. The malware disguises its network traffic as the Orion Improvement Program (OIP) protocol and stores the recognition results within legitimate plug-in configuration files, allowing it to integrate with legitimate SolarWinds activity. The backdoors use multiple obfuscated block lists to identify forensic and antivirus tools running as processes, services, and drivers.

KEY FINDINGS

Post-compromise behavior following this supply chain compromise involved lateral movement and data theft. The campaign is the work of a highly-skilled threat actor and the operation was conducted with significant operational proficiency and persistence.

Traces of SUPERNOVA (Latest)

By analyzing artifacts from the SolarWinds Orion supply chain attack, security researchers uncovered another backdoor, likely coming from a different threat actor. Dubbed SUPERNOVA, the malware is a webshell planted in the code of the Orion network and application monitoring platform and has allowed adversaries to execute arbitrary code on machines running the Trojan horse version of the software.

The webshell is a Trojan variant of a legitimate .NET library ( app_web_logoimagehandler.ashx.b6031896.dll ) present in the SolarWinds Orion software, modified to allow it to bypass automated defense mechanisms.
Orion software uses the DLL to expose an HTTP API, allowing the host to respond to other subsystems when requesting a specific GIF image.

Researchers analysing the DLL concluded that malware could escape even manual analysis, as the code implemented in the legitimate DLL is harmless and of “relatively high quality”. Threat actors have added four new parameters to the legitimate SolarWinds file to receive signals from the command and control infrastructure (C2).

The malicious code contains a unique method, DynamicRun, that compiles the parameters to an in-memory .NET assembly on the fly, leaving no artifacts on the disk of a compromised device. In this way, the attacker can send arbitrary code to the infected device and execute it in the context of the user, who most often has elevated privileges and visibility on the network.

Most webshells run their payloads in the context of the runtime environment or by calling a subshell or process such as CMD, PowerShell, or Bash.

Microsoft believes that SUPERNOVA is likely the work of an adversary different than the one who breached cybersecurity firm FireEye and more than half a dozen US government entities.

SUNBURST Backdoor (Earlier)

SolarWinds.Orion.Core.BusinessLayer.dll is a digitally signed Orion software system component that includes a backdoor that communicates to a third-party servers using HTTP. This SolarWinds Orion plugin is being monitored as a trojanised version.

It retrieves and runs commands, called “Jobs,” after an initial sleeping time of up to two weeks, which includes file capability, executing scripts, profiling programs, rebooting the computer, and deactivating device services. The malware masks its network traffic as a protocol for the Orion Improvement Program (OIP) and stores recognition results from invalid plugin configuration files that allow it to integrate with legit SolarWinds operation. The backdoor is used to classify forensic and anti-virus methods as systems, utilities, and drivers using several fog lists.

Post-Compromise Operations

After gaining initial access, this group uses a variety of tactics to cover up their activities when advancing laterally. These threat actors tend to keep a light malware footprint, choosing to provide the legal certificate and remote access to the victim’s environment.

TEARDROP is a memory-only dropper that operates as a service, spawns a thread, and reads “gracious truth.jpg” from a file that is likely to have a bogus JPG header. Then, verify that HKU\SOFTWARE\Microsoft\CTF exists, decode an embedded payload using a custom XOR rolling algorithm, and manually load an embedded payload into memory using a custom PE-like file format. TEARDROP has no incompatible coding for any previously seen malware.

The threat actor sets hostnames on their command-and-control infrastructure to represent the legal hostname contained in the victim’s setting. This helps the adversary to pass into the atmosphere, avoid suspicion, and avoid detection.

SolarWinds.Orion.Core.BusinessLayer.dll (b91ce2fa41029f6955bff20079468448) is a SolarWinds-signed plugin feature of the Orion software system that includes an obfuscated backdoor that communicates to third party servers through HTTP. After an initial inactive duration of up to two weeks, it retrieves and executes commands called “Jobs,” which provide the ability to pass and execute data, device profile, and disable system services.

Backdoor’s behavior and network protocol combine into legitimate SolarWinds operations, such as masking the Orion Improvement Program (OIP) protocol and storing identification data in plugin configuration files. Backdoor uses a range of blocklists to identify forensically and anti-virus approaches through networks, services, and drivers.

Researchers have claimed that FireEye, Microsoft, and Godaddy worked together to build a “kill switch,” for the Sunburst malware.

SUSPECTED THREAT ACTORS

Unknown Russian Groups. Reach out to CYFIRMA for detailed insights on the attributions and correlations.

INSIGHTS

SolarWinds is a well-known managed services provider that provides a range of tools and services to organizations to manage their IT infrastructure. Adversaries have interfered with the SolarWinds’ Orion platform, a software used to monitor and manage large networks. It is expected that the software update version between 2019.4 and 2020.2.1 has been exploited by the adversaries. The company has now released a fix to version 2020.2.1 HF 2.

Researchers warned that software updates for SolarWinds’ Orion product had been subverted by backdoors dubbed SUPERNOVA and SUNBURST. Malicious software updates, which have been signed with valid digital signatures, could steal files, profile systems, and disable system services.

Threat actors are upgrading their arsenal with new and sophisticated malware tools to target organizations and exfiltrate sensitive information. Threat actors are observed pushing their malware/tools as part of updates of a legitimate application and using steganography to evade detection.

For more research data on Yara Rules, IoCs, and hashes, email [email protected]

 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.