DATA SOVEREIGNTY AND CYBERSECURITY

By Kumar Ritesh, Founder & CEO, CYFIRMA

(First published in SMEFutures)

The pre-pandemic years usher in a heady era of globalization, open systems, and interconnection. Collaboration between governments and businesses resulted in globalization of supply chains which opened new markets and new business models. Data sovereignty or data localization became a new buzzword as early as 2014 when cloud models facilitated the flow of data in and out of national borders. Not knowing exactly where and how data of its citizens and businesses are stored, consumed, and monetized created concerns for governments. Data privacy and protection becomes a point of contention when users’ private and confidential information is perceived to be accessible, ready to be examined and replicated by machines for user behaviour analysis, advertising, surveillance and other malicious objectives.

The arrival of foreign ‘hyperscalers’, cloud companies such as Microsoft Azure, Google Cloud, Amazon Web Services (AWS) and AliCloud, exacerbated the situation as local businesses start subscribing to these services. This created tension among local ICT players who now have to compete against these large foreign cloud services providers. Data sovereignty, is thus, a loaded term and evokes sense of nationalism and xenophobia (protecting local businesses and keep the foreigners out).

In the last six months, Covid-19 upended ‘business as usual’ and international relations are tested as governments look inwards to protect jobs and appease restive citizen groups. Data sovereignty has been a heated discussion topic when European states enacted GDPR. Over in Asia, countries with huge populations like India and Indonesia have been evaluating options to protect citizens’ data, and keeping data ‘on-soil’ has become the vernacular among politicians. And today, even as regulations are enacted to enforce data sovereignty, data privacy and protection can still be a thorny issue. Cyber threats and risks exist no matter where data resides – it is the execution of sound cybersecurity strategies that can effectively protect businesses and citizens’ data.

Instead of a draconian, repressive and authoritarian approach to managing data under the pretext of ‘for the good of the nation’, we would be better off promoting an open system where innovation, trade and economic growth can flourish while ensuring private and confidential data does not fall into the wrong hands. Many nations face many common technical challenges when trying to mitigate risk in the face of conflicting priorities. The following cybersecurity strategies will help businesses untangle the web of confusion, remove the corrosive nature of reclusive mentality and start embracing connected and digital ecosystems confidently.

Approach Cybersecurity from the ‘Outside-in’

To minimize the fear of data breaches and cyberthreats, adopt an intelligence-centric mindset. The adage ‘knowledge is power’ is more relevant than ever. Leaders need to understand threats that are coming from the outside and be well equipped to handle adversaries before actual cyberattacks occur. A thorough understanding of who are the threat actors, what do they want, why are you an attractive target, when are they planning to launch an attack, and how do they intend to do so is absolutely important to be able to mount an effective strategy to fend off attacks. A complete threat landscape view will give cybersecurity teams insights into digital risk, vulnerabilities, cyberattacks, hackers’ interest, early warning, out of band, malware, and phishing campaigns to gauge impending cyber threats and risks.

Adopt a Comprehensive Approach

Data sovereignty may keep data within the borders of a nation, but this does not keep threat actors and hackers out of companies’ crown jewels. Hackers continue to jump over the proverbial wall and gain illicit access into systems and databases. Cybersecurity teams need to deploy a holistic approach to managing data and this requires strategic, management and tactical cyber-intelligence. This multi-layer deployment invokes not just security operational personnel but also risk and governance leaders. Corporate risk policy changes may be needed to ensure cyberthreats do not become cyberattacks.

Regulatory Environment Needs to Change

Governments may have enacted cyber laws but many are proving to be difficult or impossible to enforce. There are a few areas that are within the circle of influence where relatively faster improvement can be made. One would be to make incident reporting mandatory. This will create a body of research data that can provide insights on threats to the nation and inform the government on strategies it can undertake to strengthen the nation’s cyber posture. Another key area would be to impose mandatory risk and vulnerability assessment, at least biannually, on large enterprises. This will help identify threats early and remediations can take place to close any cybersecurity gaps. The third approach would be to commence attack vector assessments at least once a year – these assessments will uncover new attack surfaces as businesses adopt new digital formats and build further supplier-partner-customer connectivity. A cyber reward culture can also be cultivated where the discovery of bugs and vulnerabilities are rewarded. This effort will uplift the cybersecurity community and promote a culture of knowledge sharing and joint solutioning.

People, Technology, Process and Governance

For many small and medium businesses looking to ensure cyber resilience, it is important to build a basic level of cyber hygiene. The most important being ‘people’ where employees and individuals must be educated on cyberthreats and risks. This is particularly vital given the prevalence of phishing attacks and social engineering hacking campaigns. From the technology perspective, businesses should incorporate layered defences with data and endpoint security, gateway-based security, automating scanning, monitoring and malware removal. Antivirus solution, data loss detection and protection, and VPN solutions should also be incorporated. When it comes to processes, businesses should perform threat profiling, creation of threat segmentation, zoning and risk containerization. Keeping core content encrypted would be both prudent and necessary. The basic process of daily data backup would be a good policy to adopt too. When it comes to governance, businesses should incorporate a good cyber threat visibility and intelligence program to complete their cybersecurity strategy.

Innovation, entrepreneurship, open systems, inter-connection – these are tenets that result in new growth possibilities. To view data sovereignty through narrow lens may stifle progress. It would be prudent to deploy forward-thinking and progressive cyber strategies as we march into a highly digital post-pandemic world.

 

MAZE RANSOMWARE GROUP DECLARED SUCCESSFUL EXPLOITS OF MANY ORGANIZATIONS AND RELEASED MASSIVE DATA ON PUBLIC SITE IN ONE DAY

CYFIRMA Research – 10 Jun 2020

CYFIRMA’s researchers have tracked Maze as early as Jun last year, and on 10 Jun, Maze group have released a long list of companies who have fallen victim to their cyberattacks. Affected companies span from the US and South America to the UAE.

Maze ransomware operators are known to launch their attack under the surface and have a history of first stealing the data before locking their target devices. As an extortion cartel, Maze operators capitalize on victim organizations’ fear of reputation damage, potential lawsuit, and other business impact to extract maximum financial benefits. Run-of-mill ransomware demands are usually in the range of hundreds to thousands of dollars (bitcoin equivalent), but with Maze, the amount can run into millions.

The modus operandi of Maze hackers would entail releasing threats of data dump on public forum if ransom is not paid. When such data is made available, other hackers and cybercriminals will have access to the sensitive data, and would continue their separate exploits, including reselling stolen data in dark web marketplaces.

Maze operators have targeted a number of high-profile large enterprises, and government-linked corporations, across wide-ranging industries. Their recent breaches include Cognizant, a global IT services powerhouse with 290,000 employees and annual revenue turnover of almost US$17B in 2019, and ST Engineering, a Singapore government-linked company involved in defence and military projects.

Here is the latest list of companies who have been compromised by Maze operators and shared in Maze website:

Domingos Martins – Brazilian government website containing information related to Domingos Martins municipal. Breached data could include citizens’ information such contact details, taxes, e-government services rendered.

Daily Thermetrics – A US firm providing process engineering industries with precise temperature measurement instrumentation.

John Christner Trucking – A family trucking business based out of Oklahoma.

FERSPED Inc. – A shipping and freight-forwarding company based in Macedonia.

Mead O’Brien, Inc. – The company provides valves & valve automation, steam & hot water products and systems, instrumentation products, skid designs, field services, surveys, assessments, and consulting services, and is based in Kansas City, USA.

United Enertech – A US construction, building and engineering company based in Tennessee

Collabera – A HR recruitment, search and training company located in New Jersey, USA.

Munoz Engineering P.C. – Provides engineering, land surveying and building and construction services, based in New York, USA.

Ahmed Almazrouei Group – Engineering and Design Services, General Trading, Property Management, Facilities Management, Oil & Gas, Educational and Food retail business headquartered in Abu Dhabi, UAE.

Omnix Int’l – A provider of business analytics, BPM, mobility solutions, information management, ERP implementation and IT networking services to public and private sectors, based in Dubai, UAE.

Westmoreland Mechanical Testing and Research, Inc. – A material testing facility for the additive manufacturing, aerospace, automotive, composites, and medical and power generation industries, based in Pennsylvania, USA.

CPFL Energia – A large energy company with businesses in distribution, generation, commercialization of electricity and services serving 9.6 million customers in Brazil.

Here are extracts of the stolen data belonging to the above organizations which are now publicly available.

Domingos Martins
Contracts – ANA PAULA HUVER

Daily Thermetrics

Ahmed Almazrouei Group

Omnix International
Engagement Letter with Deloitte- Dec 19

United Enertech

Collabera
GCI Global Escrow Agreement

Mead Obrien
Mead O’Brien COI 2018

John Christner Trucking
2019 Carrier Settlement History 693450_1

FERSPED Inc.
MySQL .IBD Data base files exposed

Muñoz Engineering P.C.
Agate Construction Company Agreement – 51312

Westmoreland Mechanical Testing & Research, Inc.

Here’re the screens as captured from the Maze Group forum where the hackers announced their successful campaigns of locking down victims’ systems:

CYFIRMA Research Analysis

Maze ransomware operators have a history of first stealing the data before locking their target devices and demanding ransom. They capitalize on the reputational consequences of their target as their strategy is “steal, lock and inform.” Suspected threat actors appear to be Russian-based APT28 (Confidence Level: Moderate) and TA2101/APT29 ((Confidence Level: Moderate).

The IP addresses <Details Masked> mentioned in Cognizant attack vector was seen exploiting two old vulnerabilities CVE-2016-7255 and CVE-2018-8453. Both these Win32k Elevations of Privilege Vulnerabilities targeting Windows server was exploited by suspected Russian state sponsored threat actor APT28 in the past.

The threat actor group APT28 leverages TTPs like obfuscated files or information, PowerShell, exploitation of remote services for lateral movement, credential stealing through spear-phishing links and data-staged techniques. These similar TTPs were seen in the Cognizant hack due to Maze ransomware.

The mentioned IP addresses like <Details Masked> belong to Russian origin which gives us the glimpse that Russian threat actor groups (possibly APT28) are behind the attack.

On similar lines, the threat actor group TA2101 had leveraged Maze Ransomware targeting German, Italian and U.S. organizations with malicious emails carrying samples of Maze ransomware in November 2019. TA2101 has been actively using Maze ransomware for attacks.

Advisory

Maze Ransomware usually deploy phishing emails with MS Office attachments and fake/phishing websites laced with Exploit Kits. Recipients should be cautious when handling emails from unknown sources, downloading attachment, or clicking on suspicious links as Maze operators utilizes social engineering tactics aggressively.

To strengthen security controls, software and applications should contain the most updated patch. Avoid pirated and counterfeit software as they could be laced with malware.

Maze tends to use known vulnerabilities like the Pulse VPN CVE-2019-11510 to break in and this means employees working from home must be mindful when accessing sensitive company information. More actions can be taken to protect your organization from Maze ransomware.

Contact our Researchers today for a consultation.

 

 

 

COVID-19 TRIGGERS CHANGE IN THE CYBER-CRIME WORLD

BY CYFIRMA RESEARCH

Much has been said about the massive disruption to economies caused by the Covid-19 pandemic. Lives and livelihoods have been irrevocably changed and the post-pandemic world may look very different from what we used to know. The dark web, too, reveals a different veneer in terms of hacker targets, methods of attacks, and the rise of state-sponsored threat actors.

While researching for cyberthreats against our global clients in the high-tech manufacturing, financial services, F&B, critical infrastructure industries as well as government bodies, we have uncovered an exponential uptick of cybercrime. The noise in the dark web has become louder and more audacious as hackers capitalize on the pandemic for financial gain, create brand damage, and jostle for geopolitical supremacy.

Corporate networks are interesting but so as high-value individuals

Cyber criminals have always profited from corporate espionage by stealing customer information, financial records, and other valuable assets. Spear phishing email, combined with trawling staff information from social platforms, has proven to be effective conduits for delivering hackers payloads. Over the last three months, with the pandemic in full force, a number of cyber criminals have diverted their targets towards high-value individuals. These are influential personalities with access to intellectual property, trade secrets and other sensitive information. Hackers have taken the path of least resistance by attacking individuals as opposed to investing vast amounts of resources to break into corporate systems.

With millions of employees working remotely and away from the protection of corporate layered defenses, vulnerabilities to cyber attacks have increased dramatically. Work patterns have shifted on a massive scale, and as reported by the European cybersecurity agency, ENISA, and the UK’s National Cyber Security Centre, the number of coronavirus-themed phishing attacks has gained momentum among remote workers. This scenario presents significant business risks when high-value individuals enter cyber criminals’ radars.

Communication applications are a new source of monetization

Hackers have shifted their attention to exploiting communication applications such as VPNs, video-conferencing systems, and VOIP devices. Cyber criminals have created many fictitious VPN clients to trick people into disclosing credentials to gain access to corporate networks. These fake VPN clients include perennial brands such as FreeVPN, ExpressVPN, PrivateVPN, as well as new VPN clients such as PandaVPN, RemoteArCon, and FreeRemoteConnect_CN.

Our analysis revealed a global reconnaissance campaign called Redwall, where suspected Chinese hackers have listed hundreds of publicly accessible VPN devices, proxy servers, firewalls, switches, and global load balancing devices and appliances in dark web forums and communities. These remote working tools and software have become the new source of monetization for hackers who are taking advantage of the pandemic crisis. Hacker groups such as REvil (Sodinokibi) are also observed to be actively crawling the web for vulnerable VPNs.

Do they really need APTs when repurposing current malware and ransomware can do the job

Our intelligence revealed hackers working on new variants of EMOTET malware, Clickbait Ad Revenue Generation, Mining cryptocurrency, as well as utilizing existing variant of malware like Agent Tesla, LokiBot, RemcosRAT, TrickBot, and FormBook as weapons for more cyber exploits.

Phishing attacks have become a primary mechanism for tricking individuals and businesses into clicking fictional Centers for Disease Control (CDC), and the World Health Organization (WHO) themed messages or announcements.

Threat actors also create fake online stores to deceive customers into downloading malware, enabling hackers to exfiltrate personal and financial information.

By re-purposing existing malware or simply using commodity malware, hackers can quickly re-calibrate their weapons and launch new attacks.

Hack for social, religious unrest using fake news

Under the cloak of fear and uncertainty, misinformation campaigns have gained traction in recent months. Hackers have breached WorldofMeters website and grossly inflated the data on COVID-19 deaths in Vatican City. The intention was to stimulate negative social sentiments and create unrest against specific communities.

Speculation, rumours, scams, and outright falsehoods have spread like wildfire. In Singapore, fake videos of foreign workers fighting in the dormitories and committing suicide, allegedly in frustration at having been mistreated during the outbreak of the pandemic, have been widely shared and circulated.

 

State-sponsored groups taking center stage again

We analysed 14,649 COVID-19 related domain names, of which at least 8 per cent were associated with Vicious Panda (Chinese), 11 per cent Lazarus Group (North Korean), and 6 per cent FIN Group (Russian). These are known state-sponsored or affiliated groups.

There are over 124,600 domains registered with COVID-related keywords such as “COVID-19,” “COVID,” “Corona,” “CVD-19,” “C-Virus,” “MASK,”  “C-COVID,” “WUHAN,” “HYDROXYC,” “KIT” and “HYDROXYCHLORO.”

The pandemic has triggered a response from state actors not quite seen before. These well-funded, well-oiled, cyber-war machines have jumped into the fray, maximizing the crisis in their efforts to achieve geopolitical supremacy.

By researching the hacker groups, we have seen their modus operandi and the objectives driving the many campaigns.

  • Korea-speaking hacking communities are working on releasing new malware and phishing campaigns to exfiltrate financial information, PII and CII for financial gains.
  • Mandarin-speaking hacking community focuses on health research, intellectual property, trade secrets, and corporate espionage. They are using COVID-19 themed malware to execute phishing campaigns. The goal is to achieve geopolitical supremacy and damage the reputation of enemy states.
  • Russian-speaking groups are interested in stealing financial information, PII and CII for financial gain and damage to reputation.
  • South-Asian groups are out to deface government health services and research websites, as well as exploiting the vulnerabilities of large corporations.
  • Yet-to-be identified hacktivist groups are out to drive social sentiments in favor of their partisan leanings.

The COVID-19 pandemic has triggered many changes in the cyber-crime world. Criminals are fast adapting their attack methods and weaponizing the coronavirus. The defence paradigm of cybersecurity practitioners needs to shift quickly to impede these attackers. Cyberthreats have gained momentum over the course of three months with the level of creativity and ingenuity not quite seen before. It is time for defenders to understand threats and risks coming from outside the wire.

 

WANT TO DECODE THREATS AND DEPLOY THE BEST CYBER INTELLIGENCE STRATEGY FOR YOUR ORGANIZATION?

SPEAK TO OUR CYBER RESEARCH TEAM TODAY.

 

 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.