WebKit

By CYFIRMA Research

First Published on 6 August 2021

  1. EXECUTIVE SUMMARY

Russian threat actors are suspected to have leveraged and believed to have exploited a zero-day vulnerability CVE-2021-1879 in the wild leveraging LinkedIn messaging and sending spear-phishing emails with malicious links.

Based on our research and analysis, we suspect state-sponsored Russian threat actor – Cozy Bear to be carrying out these activities targeting multiple industries and geographies. These activities are suspected to be part of the data exfiltration campaign – crop up.

The primary motive of this campaign appears to be:

  • Exfiltration of sensitive information, intellectual property, personal, customer, and financial information.

CYFIRMA recommends using reported IOC details for measures against this campaign and threat hunting within your environment.

CYFIRMA Risk Rating for this Research is Critical.

NOTE: The vulnerability has been reported as situational awareness intelligence. CYFIRMA would like to highlight the potential risk and indicators observed which may be leveraged by nation-state threat actors in exploiting the vulnerability to gain a foothold and exfiltrate sensitive information from the target organizations.

  1. VULNERABILIY AT A GLANCE

Universal cross-site scripting Vulnerability in Apple watchOS, iOS and iPadOS –
WebKit (Safari)

CVE-2021-1879

CVSS Score: 6.1

Exploit Details: This zero-day vulnerability is being exploited in the wild and is suspected to be leveraged by Russian threat actors. The exploit details can be found in the link.

Description:
The products are vulnerable to universal cross-site scripting, caused by improper validation of user-supplied input by the WebKit component. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact
Successful exploitation of the vulnerability could allow an attacker to carry out cross-site scripting attacks may allow a remote attacker to steal potentially sensitive information, change the appearance of the web page, perform phishing and drive-by-download attacks.

Insights
The vulnerability exists due to insufficient sanitization of user-supplied data within the WebKit engine. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in the user’s browser in the context of the arbitrary website.

The CWE is CWE-79, and the vulnerability has an impact on confidentiality and integrity.

Affected Version
Please refer to the following links for the affected versions:

Mitigation
Please refer to the following links for the mitigations:

Security Indicators

  • Is there already an exploit tool to attack this vulnerability? Yes
  • Has this vulnerability already been used in an attack? Yes
  • Are hackers discussing about this vulnerability in the Deep/Dark Web? Yes
  • What is the attack complexity level? Low

 

To download the full report, write to [email protected]

PrintNightmare

By CYFIRMA Research

First Published on 6 August 2021

  1. EXECUTIVE SUMMARY

Russian threat actors are suspected to have leveraged malware/ransomware and are believed to have exploited a zero-day vulnerability CVE-2021-34527.

Based on our research and analysis, we suspect state-sponsored Russian threat actor – TA505 or its affiliates to be carrying out these activities targeting multiple industries and geographies. These activities are suspected to be part of the Global Ransomware Campaign – night blood.

CYFIRMA suspects potential collaboration between Chinese hackers and Russian cybercriminals based on the indicators observed and given that Chinese hackers have targeted Japanese organizations with the same malware exploit kits in the past.

The primary motive of this campaign appears to be:

  • Exfiltration of sensitive information, intellectual property, personal, customer, and financial information.
  • Financial Gains.

CYFIRMA recommends using reported IOC details for measures against this campaign and threat hunting within your environment.

CYFIRMA Risk Rating for this Research is Critical.

NOTE: The vulnerability has been reported as situational awareness intelligence. CYFIRMA would like to highlight the potential risk and indicators observed which may be leveraged by nation-state threat actors in exploiting the vulnerability to gain a foothold and exfiltrate sensitive information from the target organizations.

  1. VULNERABILIY AT A GLANCE

Remote Code Execution Vulnerability in Microsoft Windows Print Spooler – (PrintNightmare)

CVE-2021-34527

CVSS Score: 8.8

Exploit Details: This zero-day vulnerability is being exploited in the wild and has been leveraged by REvil Ransomware Group. The exploit details can be referred to in the Link. (Source: Surface Web)

Description:
Microsoft Windows could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a flaw in the Print Spooler service.

Impact
Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code on the system with privileged access and could result in the complete compromise of the vulnerable system.

Insights
The vulnerability exists due to improper input validation within the RpcAddPrinterDriverEx() function. A remote user can send a specially crafted request to the Windows Print Spooler and execute arbitrary code with SYSTEM privileges.

The CWE is CWE-269, and the vulnerability has an impact on confidentiality, integrity, and availability.

Affected Version
Please refer to the following links for the affected versions: Source

Mitigation
Please refer to the following links for the mitigations: Source

Security Indicators

  • Is there already an exploit tool to attack this vulnerability? Yes
  • Has this vulnerability already been used in an attack? Yes
  • Are hackers discussing about this vulnerability in the Deep/Dark Web? Yes
  • What is the attack complexity level? Low

 

To download the full report, write to [email protected]

Anonymous Group OpMyanmar

By CYFIRMA Research

First Published on 27 Apr 2021

Following the coup in Myanmar by the country’s military forces which has detained the elected leader Aung San Suu Kyi and members of her National League for Democracy (NLD) party alleging fraud in the general election, massive protests have been taking place in the country against the coup. To suppress the protestors, the military blocked communication services, including internet and telecom services to quell the uprising. The media also has been prohibited to report on the protest and independent media companies licenses have been revoked which makes their reporting illegal.

In retaliation, several videos and images have surfaced online, predominantly on Twitter under the hashtag #WhatsHappeningInMyanmar, which has garnered huge support in the form of online protests, empathizing with the people and their cause.

The initial hacking campaign, carried out by a group called Myanmar Hackers, claimed to have successfully hacked government websites and a state-run news agency. The famous hacktivist collective, Anonymous, joined and pledged their unanimous support to continue the disruptive activities on the government websites and have launched a cyberwarfare operation, titled OpMyanmar. The hashtag has been trending with the group claiming to have brought down several government websites, ranging from the National Bank to the Presidency.

The Anonymous group has been actively using the hashtag and several Twitter handles, which have since emerged using handles akin to Anonymous, are actively posting target lists of future attacks as well as tweeting about unverified claims of DDoS attacks on organizations. Many Japanese organizations have been listed due to their alleged funding of the shell companies having ties to the Myanmar military- and helping them build a large-scale complex on the site of a military museum in one of the provinces. The Anonymous group is allegedly demanding an immediate suspension of the project and has threatened to carry out similar disruptive or humiliation attacks on the listed Japanese organizations.

Threat Profile of Anonymous

The Anonymous Hacktivist group is a decentralized online collective with no specific affiliation. They advocate freedom of speech, individual privacy, and are staunch opponents of censorship and surveillance. The international group is assumed to comprise anyone who wants to become a member with its supporters being referred to as ‘anons’.

Rebellion has been their regular theme, and they have garnered a lot of support from the online audience. A primary characteristic of the group is the use of voice garbling or text-to-speech software that lets anons mask their voice in video messages, which is usually posted as a warning before an attack.

Their motto – “We are Anonymous. We are legion. We do not forgive, we do not forget. Expect us”, has become a famous caption to their Twitter handles and symbolizes socio-political resistance.

A striking characteristic of the Anonymous Group is the Guy Fawkes mask, portrayed in the novel and film ‘V for Vendetta’. It does not use any verified social media handles, with multiple groups using Twitter accounts and tagging each other for common causes and disseminating the group’s motives and campaigns.

The group first became popular in the early 2000s via the imageboard website ‘4chan’, known for its privacy and anonymity and became famous in 2008 when it targeted the Church of Scientology website in a DDoS attack to protest against the taking down of a Tom Cruise video on Youtube, which had him talking highly of Scientology, a controversial religious group.

OpMyanmar and the Japan Connection

What started as a campaign to show solidarity to the victims of the protest, has turned into a full-blown smear campaign comprising claims of successful hacks of Myanmar government websites, primarily via DDoS attacks and defacement. Various support groups, operating as Anonymous, Twitter, as identified by tracking the hashtag #OpMyanmar, have listed potential targets as well as proof of what appears to be reports of websites downtime. Few of the Twitter Handles of Anons actively posting and executing attacks related to OpMyanmar are:

  • @Y0urAnonOPS
  • @YourAnonS0u1
  • @YourAnonAttacks
  • @YourAnonOnline
  • @LorianSynaro

The group has been using the hashtag #TangoDown to name and shame the websites as well as post screenshots to drive home their goal. Also, another prominent hashtag included #MilkTeaAlliance which again is an online solidarity movement primarily comprising of netizens from Hong Kong, Taiwan, Thailand, and Myanmar (Burma).

The purported attacks appear to have been carried out at the end of last month, wherein a series of tweets were observed in which various Myanmar organizations were allegedly targeted and the details posted, i.e., websites, name of the org., screenshots of website connection downtime.

The group, post its domestic targeting, spread its wings and began posting unverified tweets accusing Japan of supporting and funding the Myanmar military forces, as well as posting target lists which included links to various paste sites, again of which most of them are down or have been deleted, raising questions regarding the validity of these potential targets.

A few of the paste sites that were posted and found inactive or list being deleted are:

https://justpaste.it/92174

https://justpaste.it/opmyanmar_Japan_file

The major motivation behind targeting the Japanese government and a few of the country’s private organizations appears to be a development project named ‘Y Complex’, a USD 320 million complex that includes an Okura Prestige hotel, shops and offices, allegedly being built on a historic site owned by the Myanmar military in Yangon city centre.

According to the tweets, the Japanese investors, are Fujita Corporation, Tokyo Tatemono and the Japan Overseas Infrastructure Investment Corporation for Transport & Urban Development (JOIN), which allegedly control 80 per cent of Y Complex. JOIN is a Japanese Government entity. Further incriminating details of the project and the money trail has been detailed in the following link, which indicates the group’s intent to target and execute attacks on the Japanese organizations:

https://www.justiceformyanmar.org/stories/land-lease-payments-tie-japanese-gov-and-investors- to-myanmars-military

Research from one particular tweet, which posted a list of 105 organizations, called the Dirty list, hinted towards potential future targets spread across geographies supporting the Myanmar Military in its business ventures and violating human and environmental rights:

https://twitter.com/AEGISAllianceTM/status/1384963809853550598

From this list, 3 Japanese organizations were listed as follows:

fukken.co.jp – Fukken is a Japanese Civil Engineering Consultancy Company. Its subsidiary in Burma, Fukken Myanmar, carries out work for military-owned companies.
jcb.co.jp – Japan Credit Bureau (JCB), JCB is a Japanese card payment company. In Burma it is in a business relationship with the military-controlled Myawaddy Bank, providing card payment systems.
corp.asahi.co.jp – Osaka Asahi Group is a Japanese shipping and transport company. It owns Osaka Asahi Shipping, which in turn owns the Sinar Bali container ship. The Sinar Bali uses the military-owned Hteedan International Port in Yangon.

The primary motivation behind these smear campaigns by the anonymous groups, whose victim list also includes global oil & gas companies, is to suspend the major revenue of the Myanmar military, which is profits from Real estate and Oil & Gas, which supports the illegitimate junta’s rule.

Following are the list of recent activities of the Anonymous Group:

1. The threat actor group is suspected of initiating attacks against government websites of Malaysia as part of its suspected operation – wake-up call with possible DDoS attacks. The alleged attacks were to be carried out in protest of the data leaks taking place across organizations in Malaysia and demanding the government taking more action to prevent such attacks.
Link: https://www.thestar.com.my/tech/tech-news/2021/01/26/security-expert-says-anonymous- malaysias-threat-must-be-taken-seriously-doesnt-expect-all-out-attack
Date: 25-Jan-2021

2. The threat actor group is suspected to be behind the takedown of the Law Enforcement agency website in Uganda through possible DDoS Attacks. The cyberattack carried out by group is believed to be in response to the loss of lives of protestors who were protesting against the arrest of high-profile political individual.
Link: https://redpepper.co.ug/2020/11/cyber-attacks-anonymous-hack-uganda-police-website-in-wake- of-bobi-wine-city-riots/
Date: 19-Nov-2020

3. The threat actor group is believed persuaded fans of Korean pop music to hijack the pro-police Twitter hashtag supporting Black Lives Matter and are alleged of taking down the Law Enforcement agency app by flooding it with K-pop fan videos. The threat actor is suspected to be behind the attack as the incident took place few days after they posted a video about targeting Law Enforcement agencies.
Link: https://www.darkreading.com/theedge/whats-anonymous-up-to-now/b/d-id/1338112 Date: 02-Jun-2020

4. The threat actor group is suspected of taking down the Law Enforcement agency website in the US by breaching its database and potentially leaking 798 emails and credentials. The threat actor is believed to be behind the attack as the incident took place a few days after posted a video was posted about targeting Law Enforcement agencies.
Link: https://www.darkreading.com/theedge/whats-anonymous-up-to-now/b/d-id/1338112

 

To download the full report, write to [email protected]

Anonymous Group OpFukushima

By CYFIRMA Research

First Published on 17 May 2021

Post Japanese government’s announcement to approve the plan of releasing radioactive contaminated water from the Fukushima Daiichi Nuclear Power Plant into the Pacific Ocean by 2023, there have been multiple threats on Twitter since April 13, 2021, from a suspected Anonymous member to protest against this political decision.

The Famous hacktivist collective, Anonymous, has gathered forces and pledged their unanimous support to execute disruptive activities on primarily the TEPCO website and have launched a cyberwarfare operation, titled OpFukushima, in this direction. This hashtag has been trending with the group claiming to have breached TEPCO’s website and posting unverified data on a paste site.

The Anonymous group has been actively using the hashtag and several Twitter handles, which have since emerged and using handles akin to Anonymous, have been posting target lists of future attacks as well as unverified claims of network-based attacks on Japanese organizations. Herein, Japanese organizations have been listed with no connection to the nuclear incident nor TEPCO. Anonymous is allegedly demanding an immediate suspension of the project, and has threatened to carry out similar disruptive or humiliation attacks on the listed Japanese organizations.

In this report, the CYFIRMA threat research team has summarized what was have detected so far regarding OpFukushima activities in an attempt to provide a clear view of actual threats against Japanese organizations.

Threat Profile of Anonymous Group

Active since 2003, the Anonymous Hacktivist group is a decentralized online collective with no specific affiliation. They advocate freedom of speech, individual privacy, and are staunch opponents of censorship and surveillance. The international group is assumed to comprise anyone who wants to become a member with its supporters being referred to as ‘anons’.

Rebellion has been their regular theme, and they have garnered a lot of support from the online audience. A primary characteristic of the group is the use of voice garbling or text-to-speech software that lets anons mask their voice in video messages, which is usually posted as a warning prior to an attack.

Their motto, “We are Anonymous. We are legion. We do not forgive, we do not forget. Expect us”, has become a famous caption to their Twitter handles and symbolizes socio-political resistance.

A striking characteristic of Anonymous is the Guy Fawkes mask, portrayed in the novel and film ‘V for Vendetta’. Anonymous does not use any verified social media handles, with multiple groups using Twitter accounts and tagging each other for common causes and disseminating the group’s motives and campaigns.

The group first became popular in the early 2000s via the imageboard website 4chan message boards, known for its privacy and anonymity and became famous in 2008 when it targeted the Church of Scientology website in a DDoS attack to protest against the taking down of a Tom Cruise video on YouTube, which had him talking highly of Scientology, a controversial religious group.

OpFukushima

As part of the campaign, Anonymous has been posting several links related to the environmental disaster including pacific ocean pollution, loss of marine biodiversity and radioactive damage. Various support groups, operating as Anonymous, primarily on the social media platform, Twitter, as identified by tracking the hashtag #OpFukushima, have listed potential targets as well as proof of what appears to be reports of TEPCO credentials. Few of the Twitter Handles of Anons actively posting and executing attacks related to OpFukushima are:

  • @Y0urAnonOPS
  • @YourAnonS0u1
  • @YourAnonAttacks
  • @YourAnonOnline
  • @LorianSynaro

The group has been using the hashtag #TangoDown to name and shame the websites as well as post screenshots to drive home their goal.

The purported attacks appear to have been carried out at the end of last month, wherein a series of tweets were observed in which the allegedly primary culprit, TEPCO was targeted and the details posted, i.e., websites, name of the org, IP address and credentials.

The group, in a post last month, listed Japanese organizations, along with TEPCO, to cause confusion while diverting attention from the main target and raising questions regarding the validity of the other potential targets.

This can be corroborated with Anonymous numerous tweets accusing TEPCO being the primary agency behind the 2012 disaster as well as being given the authority now, to release the radioactive contaminated water in Pacific ocean.

TTPs:

DDoS Attack: Anonymous group is known to largely employ Distributed Denial of Service (DDoS) attacks, in which they flood a website’s server with requests that causes it to crash, making the website inaccessible.

Website Defacement: Another major attack method of Anonymous is defacement – wherein the target website’s pages are replaced with the hacktivists’ messages and graphics.

The group also uses more significant techniques such as doxing, in which private or sensitive information is stolen, destroying data using computer viruses, and “phishing” for extracting personal data.

Target Organizations:

As part of the OpFukushima, the Anonymous group had posted names of Japanese organizations on paste links, which on research, were never found to be connected to the nuclear disaster nor TEPCO. The group, in order to take away the attention from the main target, has listed other significant organizations, allegedly as diversion causing tactics, and reportedly has no intention to follow up on its target list entirely, as seen in the past.

Research on public forums revealed the list of Japanese organizations, likely to have been accessed from the paste links, posted on April 25, 2021.

Source:

https://csirt.ninja/?p=1780

Original Source:

https://justpaste.it/523vp

The above list mentioned has been gathered from the source mentioned above which tracks all Anonymous operations and since that particular post, no significant update or attack methodologies including a plan or specific target have been posted. This is because, for whatsoever reasons, there has been no follow-up activity. This suggests that the Anonymous group is not reliable and the targets that they post are for garnering attention. The URLs and IPs which the group posts are, most of the time, picked up from open sources, and no sensitive information is gathered or posted by the group which indicates that the collective is not reliable nor possesses the resources to follow up on the threats issued.

The group has also posted a file dump, of documents that, on verification were found to be nowhere confidential and seemed to have been picked up from open sources.

https://anonfiles.com/h76av6u0u0/Fukushima_rar

Actual Impact:

Based on their past attacks and on verifying the link mentioned above, The Anonymous group posts target lists to issue threats as part of their Hacktivist nature. So far, barring a few instances, the threats have not been followed with a substantial attack and the claims of the sites being down also are merely screenshots of live traffic and can be easily doctored. In the OpFukushima operation, as witnessed, the group has claimed to have breached TEPCO and no substantial proof except screenshots of credentials were posted. The Japanese entities mentioned in the list are, about a month old and the group has moved on to other burning issues, for instance, OpIsrael, OpColumbia, etc. which indicates that the collective does not have the wherewithal to follow up on its operations, and its scattered presence as well as unfulfilled past threats, proves that the group is not serious and is merely a social causes activist out to cause awareness.

Insights

With the Fukushima news garnering limited attention from International media, the Anonymous group is trying to spread the news and make its presence felt via exposing TEPCO and pressurize Japan government to withdraw the order to release contaminated radioactive water into the Pacific ocean. To achieve this end goal, anonymity is the perfect tool under which the group operates to unabashedly execute its operations.

In this chaotic arrangement where the group does not focus on a single campaign at a time as evidenced on Twitter, and the lack of specific directives or hierarchical structure makes one question the authenticity of the various claims. The TTPs of the group suggest that it operates in small, spread-out groups with Hacktivism being the main prerogative. Lack of sophistication in its tactics, though untraceable, proves that the group is not backed by any Nation-state to carry out espionage-type attacks. Being decentralized makes the overall agenda diluted hence causing low impact attacks which are often reversible by the large organizations focused on cybersecurity practices.

As of April 21, 2021, no statements or target lists have been published by Anonymous and no signs of a major attack have been identified. Possible related operations include “OpGreenRights,” which has been protesting environmental issues, and “OpNuke,” which has previously included Japanese nuclear-related organizations on the target list.

To download the full report, write to [email protected]

US Oil and Gas Pipeline Attack

By CYFIRMA Research

Large-scale cyberattacks targeting critical infrastructure and operations is back rearing its ugly head, forcing the major oil and gas pipeline operator, Colonial Pipeline Co., of the United States, to shut down its operations covering almost the entire east coast. The 5,500-mile (approximately 8,850 km) pipeline carrying gasoline, diesel, natural gas, and jet fuels transports 2.5 million barrels per day from the gulf coast to the eastern and southern part of the US. In contrast, the next biggest operator, Products Pipeline Corporation (PPL), owned by Kinder Morgan Inc. can deliver only 720,000 barrels per day.

The now confirmed ransomware attack, which brought the corporation down on its knees, represents one of the most devastating and widespread disruption of American energy infrastructure known in recent history. The ongoing investigation, as of 10th May, by cybersecurity firms and statements by executives from top security agencies including CISA, DHS and the Department of Energy has, so far not established if the cybercriminals have critical control of the systems that run the pipeline infrastructure. As per the latest update on 14th May, Colonial might have conceded access to only a few businesses and IT systems not connected to the pipeline infrastructure. But, as a precautionary measure, the firm went ahead and shut down systems connected to critical pipeline operations as well, crippling the entire supply network. The US government deployed the services of federal organizations dealing with cyber incidents along with leading cybersecurity firms with expertise in handling investigations of this magnitude. Late on 10 May 2021, the Federal Bureau of Investigation (FBI) attributed this attack to an Eastern European gang, specifically Russia, called ‘Darkside’. As of 14th May, possibly in an operation by the US federal agencies, eight websites of Darkside were pulled down, followed by Darkside gang releasing a statement that they are shutting down their operations claiming that they lost access to a public part of their infrastructure.

It is too early to speculate a nation state-sponsored operation behind this crippling cyberattack, but at the same time it cannot be entirely ruled out due to Darkside gang’s western nations victimology, sophisticated tactics aimed at double extortion for maximum impact, and attack infrastructure with a capability to identify Russian language machines but not infect them. The research team believes that FIN11, a Russian Threat Actor, either independently or in a possible collaboration with DarkSide may have carried out the ransomware attack on Colonial Pipeline Co.

This report covers the following:

1. Executive Summary
2. FIN11 Threat Profile
3. Colonial Pipeline Co. attack and DarkSide Attribution
4. FIN11 Attribution to Ransomware Attack
5. Other Significant Updates of Colonial Attacks
6. Why the Energy Industry?
7. Recommendations
8. Indicators of Compromise (IOC’s)
9. Fact file of DarkSide Ransomware Gang

To download the full report, pls write to [email protected]

SilentFade Malware Exploitation of Weakness in Facebook

Out-of-Band Report

8 Mar 2021

Content
1. Executive Summary
2. Impact
3. Hypotheses
4. Process Flow of SilentFade Malware
5. Malware Toolset and Infection Chain
6. SilentFade: On Platform Persistence
7. SilentFade Group Prosecution by Facebook
8. SilentFade Attribution
9. Facebook Remediation
10. SilentFade: Signs of a Larger Malware Ecosystem
11. Insights
12. Recommendations Executive Summary

 

SilentFade (“Silently running Facebook Ads with Exploits”) gang, the hacker group infamous for cyberfraud, and known for their sophisticated and rare modus operandi to target Facebook users, has grown leaps and bounds to become a global threat defrauding victims to the tune of millions. The malware can run ads on Facebook, without the user’s knowledge, by exploiting a bug on the platform. The social network giant revealed that the malware has a Chinese origin and allowed hackers to siphon $4 million from user’s Facebook linked payment accounts.

Researchers recently noticed Frank rootkit and after having analyzed it, found that it has many similarities to the campaign TTP’s run by the SilentFade gang. A rootkit is a malicious software that allows an unauthorized user to have privileged access to restricted areas of the operating system and designed to remain stealthy and persistent.

The latest investigation, which has brought to light the SilentFade group’s activities in Southeast Asia, apart from multiple geographies, shows that the group, despite being legally prosecuted via its front/shell company, continues to target the mammoth Facebook userbase through their lucrative advertising platform.
The highest number of incidents for the past two months were detected in India, Brazil, Indonesia, Italy, Germany, Algeria, Malaysia, Russia, France, and Egypt.
Following are the country-wise incident numbers:

India – 603
Brazil – 255
Indonesia – 221
Malaysia – 137
Philippines – 96
Vietnam – 71
Thailand – 27
Singapore – 24

Method Used by Attackers:

Window Trojans
Credential theft
Vulnerabilities and Exploits
Malware Implant

Motivation:

The primary motive of the attackers appears to be:
Financial Gains
Exfiltrating Sensitive Information

Impact:

Arrives on victim devices via Adware bundles and pirated software installers.
Run Malicious Ads using Compromised Accounts and linked victim payment methods.
Possibly downloaded by other malware.

Hypothesis

According to Facebook, the SilentFade gang began operating in 2016, when it first developed a malware strain named SuperCPA, wherein CPA refers to Cost Per Action, primarily focused on Chinese users. This malware was said to be an unknown entity but believed to be used for click-fraud, through an install base in China.
The social media giant revealed that the group abandoned the SuperCPA malware in 2017 when they developed the first iteration of the SilentFade malware. This early version infected browsers to steal credentials for Facebook and Twitter accounts, with a focus on verified and high-follower profiles.

Development on SilentFade gathered steam in 2018 when its most advanced version and the one used in the 2018 and 2019 attacks came to the spotlight.
Facebook discovered SilentFade’s operations in February 2019, following reports from users of suspicious activities and illegal transactions originating from their accounts.

During the subsequent investigation, Facebook said it found the group’s current and previous malware strains, as well as campaigns dating back to 2016, and even tracked down the gang’s operations to a Chinese company and two developers, which the company sued in December 2019. Facebook stated that it found ads by the two SilentFade developers posted on underground hacking forums where they were willing to buy web traffic from hacked sites or other sources, and have this traffic redirected towards the pages hosting the SilentFade-infected software bundles.

How SilentFade Malware Works

 

The malware consists of many components with the main downloader component being included Potentially Unwanted Programs (PUPs) bundles as Facebook platform itself was not used to propagate the malware. The downloader application (seemingly legitimate) either download a standalone malware component or a Windows service installed as “AdService” or “HNService”.

Once installed, SilentFade allows attackers to steal only Facebook-specific stored credentials and cookies from major browsers, including Internet Explorer, Chromium, and Firefox.

After stealing Facebook-related credentials, SilentFade obtains the metadata of a Facebook account which is the payment information and total amount previously spent on Facebook ads using the Facebook Graph API.

The stolen data is then sent to the C2 servers as an encrypted JSON blob through custom HTTP headers.

The C2 server stores the data and logs the IP address of the incoming request for the purpose of geolocation.

SilentFade would then be able to use the compromised user’s payment method (credit card, bank account, or PayPal account) to promote malicious ads on Facebook.

The Malware Toolset and Infection Chain:

SilentFade utilized a combination of a Windows trojan, browser injections, clever scripting, and a bug in the Facebook platform, showing a sophisticated modus operandi rarely seen with malware gangs targeting Facebook’s platform.

As the name suggests, SilentFade’s credential-stealing DLL component only retrieved Facebook-specific stored credentials and cookies located on the compromised browser, thus illustrating the dedicated target persistence.

 

Write to [email protected] for the full report

 

Incidents, attributions, and exploitation techniques for path traversal flaw in Fortinet FortiOS SSL VPN devices

First published on 16 Dec 2020

A hacker has published a list of one-line exploits that can exfiltrate VPN credentials from nearly 50,000 Fortinet VPN devices. The list of vulnerable targets contains domains that belong to financial institutions and government organizations across many countries including Japan, the US, China, France, India, South Korea, United Kingdom, Australia, Hong Kong, Malaysia, Germany, and Argentina. Attackers have been leveraging a vulnerability tracked as CVE-2018-13379 affecting a wide range of unpatched Fortinet FortiOS SSL VPN devices.

This report contains observations of recent attacks, threat actor attribution, and a detailed analysis of exploitation techniques.

CYFIRMA Risk Rating for this advisory is: HIGH

The following presents the details of recent attacks that have been observed utilizing this vulnerability.

Iranian Hackers Exploiting VPN Flaws to Backdoor Organizations Worldwide

Threat Actor(s): APT33, APT34, and APT39

CVE-ID(s): CVE-2019-11510, CVE-2019-1579, CVE-2018-13379, CVE-2019-19781

Target(s): IT, Telecommunication, Oil and Gas, Aviation, Government, and Security Sectors (worldwide including Israel)

Objective: Steal sensitive information, Implant backdoors,

Technique: In February 2020, researchers have observed Iranian state-sponsored hackers targeting several organizations across Israel and around the world for the last 3 years. This campaign has been dubbed as Fox Kitten wherein attackers have been primarily leveraging unpatched VPN vulnerabilities including Pulse Secure Connect (CVE-2019-11510), Palo Alto Networks’ Global Protect (CVE-2019-1579), Fortinet FortiOS (CVE-2018-13379), and Citrix (CVE-2019-19781) to penetrate and exfiltrate information from the infected systems. After gaining an initial foothold, the infected systems were observed communicating with C2 servers to download a series of custom VBScript files that can be leveraged to install backdoors. It was seen that the backdoor code was downloaded in chunks to evade detection by antivirus solutions installed on the victim’s system.

Moreover, after gaining lateral movement capabilities, threat actors executed the backdoor to scan the infected system for relevant information and exfiltrate the files back to the attacker by establishing a remote desktop connection. This connection was established via a self-developed tool called POWSSHNET or opening a socket-based connection to a hardcoded IP address. Later in Sep 2020, the Iranian state-sponsored hacking group behind this campaign was noticed selling access to compromised corporate networks on an underground hacking forum.

Hackers Looking to Steal COVID-19 Vaccine Research

CVE-ID(s): CVE-2019-19781, CVE-2019-11510, CVE-2018-13379, CVE-2019-9670

Threat Actor: APT29, Cozy Bear

Target(s): Academic and Pharmaceutical Research Institutions (worldwide including the U.S.)

Objective: Stealing information and intellectual property related to the development and testing of COVID-19 vaccines

Technique: Throughout 2020, APT29 has been seen targeting multiple entities that are working to develop the COVID-19 vaccine across the globe. To carry out this attack campaign, the threat actor has been abusing vulnerabilities including Citrix code-injection bug(CVE-2019-19781); a publicized Pulse Secure VPN flaw (CVE-2019-11510); and issues in FortiGate (CVE-2018-13379) and Zimbra (CVE-2019-9670). Attackers have been abusing these security flaws with an intent to gain initial access to targets, along with spear-phishing to gain authentication credentials to internet-accessible login pages for target entities.

After being established in a network, the threat actor uses malware dubbed as WellMess and WellMail, to carry out further operations on the infected system and steal data. WellMess was initially spotted in July 2018 and it supports HTTP, TLS, and DNS for communications. WellMail is a lightweight malware that is designed to run commands or scripts while communicating with a hardcoded command-and-control (C2) server. Additionally, the threat actor was also observed leveraging another malware known as ‘SoreFang’. It is a first-stage downloader that uses HTTP to steal victim information and download second-stage malware.

Double Extortion Ransomware Attacks and the Role of Vulnerable Internet-Facing Systems

CVE-ID(s): CVE-2019-11510CVE-2018-13379CVE-2019-1579CVE-2019-19781CVE-2020-2021CVE-2020-5902

Objective: Deploy ransomware, perform cyber-espionage campaigns

Technique: During the second half of 2020, the new wave of ransomware attacks relying on an approach defined as “double extortion” was observed. In particular, attackers were noticed actively exploiting multiple VPN vulnerabilities such as CVE-2019-11510CVE-2018-13379CVE-2019-1579CVE-2019-19781CVE-2020-2021CVE-2020-5902 to inject ransomware as well as to carry out cyber-espionage campaigns by state-sponsored actors. Additionally, it was noticed that threat actors have modified their modus operandi and were seen selecting their victims to abuse vulnerable internet-facing systems to break into the target’s network. This mechanism would allow the attackers to establish a footprint, inject the malicious payload, and ensure that the infection distributes rapidly across the entire organization.

Election Systems Under Attack via Microsoft Zerologon Exploits

CVE-ID(s): CVE-2020-1472, CVE-2018-13379

Target(s): U.S. presidential elections

Objective: To gain initial access and compromise government networks

Technique: In Oct 2020, attackers were observed using a Fortinet vulnerability ( CVE-2018-13379) to gain initial access to the targeted entities. Alongside, Microsoft’s severe privilege-escalation flaw (CVE-2020-1472) dubbed “Zerologon” was also used to escalate privileges and gain access to Windows AD servers. Moreover, attackers were also observed leveraging the opensource tools including Mimikatz and the CrackMapExec to acquire valid account credentials from AD servers.

For details on threat actor attribution and exploitation techniques, email [email protected]

 

Hackers Abuse Microsoft Teams’ Vulnerabilities

Microsoft Teams could be targeted by suspected threat actors as they have been observed manipulating and leveraging Microsoft services to gain access to organizations’ networks and to exfiltrate sensitive information stored in it.

In the past, Microsoft Teams has been targeted by ransomware operators as it is considered one of the treasure troves of data for organizations that rely on Microsoft services.

The campaign is potentially targeting various organizations that are similar to yours, where organizations are currently dependent on using apps like Microsoft Teams for video conferencing due to COVID-19 restrictions. Attackers are looking for new and sophisticated techniques each time to target organizations and achieve their malicious objectives.

Method Used by Attackers:

  1. Ransomware Attacks
  2. Abusing Legitimate Services
  3. Vulnerabilities and Exploits
  4. Malware Implants

Motivation:

The primary motive of the attackers appears to be:

  1. Exfiltrating Sensitive Information
  2. Financial Gains
  3. Corporate Espionage

Impact:

  1. Attackers could access private chats, files & folders, internal networks, and confidential information.
  2. The XSS flaw further helps to steal SSO authorization tokens for Microsoft Teams or its other services such as Skype, Outlook, and O365.
  3. This issue is ‘wormable’ as the researchers mentioned. It is possible to repost the exploit payload to any other organizations, channels, or users without any interaction.
  4. Possible phishing attacks by redirecting to the attacker’s site.

CYFIRMA Risk Rating: HIGH

Analysis of captured hackers’ footprints and correlation with external threat vectors indicate that this is a potential threat, and your organization is advised to take precautionary measures as highlighted in this report.

SUSPECTED THREAT ACTOR

Microsoft Teams have been abused by attackers for some time. CYFIRMA researchers observed ransomware operators such as DoppelPaymer, and Wasted Locker, targeting Microsoft Teams to exfiltrate sensitive information in the past.

CYFIRMA also suspects Chinese State-sponsored Threat Actor – MISSION2025 potentially leveraging its toolsets such as Cobalt Strike, and njRAT to target Microsoft with the intent to exfiltrate sensitive information. The threat actor has been observed leveraging legitimate services such as Microsoft O365 to target organizations and download its payload.

Chinese Threat Actor – MISSION2025 could potentially be carrying out such attacks against organizations as part of the Chinese government’s VISION2025/Made in China 2025 Campaign.

VISION2025/Made in China 2025 Campaign is intended to establish China as a leader of innovation and manufacturing. The campaign has been active for the past 2 years in carrying out corporate espionage such as stealing IP, Copyright, and Trade Secrets for local Chinese companies. Over the last 9 months, the campaign has been very active against multiple industries and organizations. In fact, 13 distinct sub-campaigns were observed against various industries.

CYFIRMA suspects that there could be a potential collaboration between Chinese Threat Actor – MISSION2025 and Ransomware Operators under the new Ransomware-as-a-Service (RaaS) business model which could be beneficial for both parties.

INSIGHTS

Threat actors are looking for various sophisticated ways to steal information from their targets. The successful exploitation of the flaws in Microsoft Teams could potentially give access to private keys and personal data outside Microsoft Teams. This can possibly leak internal network information and allowing adversaries to set it up for potential phishing attacks and delivering payloads for possible backdoor entry or additional payloads which include ransomware.

Ransomware operators have been improving their techniques with an intent to intimidate and force victims to pay the ransom. While at the onset, ransomware was primarily developed to encrypt data, later it was later enhanced to a three-way approachInfiltrate into the network, Exfiltrate and Encrypt Data, Demand Ransom and Name & Shame.

For details on technical analysis, YARA rules and more, write to [email protected]

 

N. Korean Hacking Group, Kimsuky, Escalates Attacks

Kimsuky (aka Velvet Chollima, Black Banshee, and Thallium) is a known N. Korean state-sponsored threat actor. The group has been active since 2012 and targeting businesses and individuals with new phishing themes.

It has a history of launching attacks around the world including Japan, the United States, Russia, and European nations.

Kimsuky operatives specialize in stealing intelligence secrets from the U.S. and its closest allies in Asia, such as Japan and South Korea. In recent campaigns, Kimsuky’s primary target is been observed to be pharmaceuticals firms.

Threat Actor Profile 

Kimsuky is a North Korean-based threat group that has been active since at least 2012. This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes. Also responsible for launching a spear-phishing campaign targeting UN officials, including those affiliated with the UN Security Council. The group was attributed as the actor behind the Korea Hydro & Nuclear Power Co. compromise (2014).

Target Industry:

Education and Academic Organizations, Energy, Think Tanks, Ministry of Unification, Pharmaceutical and Research Institutes, Military, Media.

Target Countries:

Japan, Europe, USA, South Korea, Russia

Motivation:

Information theft and Espionage

Attack Methods:

Kimsuky employs common social engineering tactics, spear phishing, and watering hole attacks to exfiltrate desired information from victims.

TTPs of Kimsuky APT

Spear phishing with a malicious attachment embedded in the email—is the most observed Kimsuky tactic to obtain Initial Access to victim networks. It has used emails containing Word, Excel, and/or HWP (Hangul Word Processor) documents in their spear-phishing campaigns.

PowerShell or the Windows Command Shell for Execution– Kimsuky has executed a variety of PowerShell scripts to run executables from the internet without touching the physical hard disk on a computer by using the target’s memory. Kimsuky also uses Visual Basic Script (VBS)-based malware BabyShark.

For gaining Persistence, Kimsuky has been known to use malicious browser extensions, modifying system processes, manipulating the autostart execution.

A list of methods used by Kimsuky for Privilege Escalation is placing scripts in the Startup folder, creating, and running new services, changing default file associations. Kimsuky has used Win7Elevate to inject malicious code into explorer.exe (Process Injection).

Disabling the system firewall and deleting the exfiltrated data on disk after transmission to its C2 server are the two methods used by Kimsuky for Indicator Removal on Host i.e. Defense Evasion.

Kimsuky has used a PowerShell-based keylogger and legitimate tools and network sniffers to harvest credentials from web browsers.

Kimsuky has also used a Mac OS Python implant that gathers data from Mac OS systems and sends it to a C2 server.

Use of Remote Access Software: Kimsuky has used a modified TeamViewer client (version 5.0.9104) as a command and control channel.

To download this report, email [email protected]

 

 

Understanding Open Proxies and Cyberattacks

CYFIRMA research first alerted clients on the increase in open proxy usage as the attack method by known nation-sponsored actor groups in Apr 2020. Since then, these threat actors have accelerated their campaigns targeting a wide mix of industries in Japan as well as other markets.

CYFIRMA’s flagship product, DeCYFIR, has been picking up signals indicating these threat actors are scanning, brute forcing and exploiting vulnerability using proxies to hide their original attack sources. Threat actors continue to expand their infrastructure, steal data from internet-facing systems, and build initial footholds into their target organizations with the objective of launching further cyber-espionage. Threat actors use open proxy to achieve their goals more effectively and anonymously.

This out-of-band report deep dives into open proxy usage by state-sponsored actors, attacks scenarios to prepare for, and other recommendations. Here’re the key takeaways.

Background

  • Open proxies are freely available on the surface web for hackers to launch attacks against exposed servers. Once the exposed servers such as ElasticSearch or MongoDB are identified by the attackers (via Shodan or Censys), attackers can kickstart campaigns to exfiltrate data, cause DDOS, or embark on cryptomining, etc.
  • COVID-19 pandemic has resulted in many organizations migrating workforce to a remote model in a hurry. Many organizations are still struggling to enforce cybersecurity policies and patching process in a timely manner, making internet-facing servers and devices more vulnerable than ever. Unsecured home networks, poor VPN usage, and lack of cybersecurity awareness training have compounded the problem.

Proxychains, Proxy Providers

With Proxychains, hackers can chain numerous proxies and use the TOR browser to execute their actions so that investigators cannot trace the actual IP address. Any type of proxy can be used here, such as socks5, socks4, Http, https. These proxies are compatible with many reconnaissance tools and can utilized as part of an attack campaign.

To understand how hackers access open proxy servers, CYFIRMA conducted additional research on proxy providers. MikroTik network devices are one of the most widely exploited by state actors.

There are three types of open proxies, and hackers would choose according to their attacking vector requirements. These are data centre proxy, residential proxy and rotating proxy.

CYFIRMA researchers also uncovered many proxy providers in the dark web whose tools can be used to exploit routers and devices to gain access to confidential systems and launch their payloads.

Recent Open Proxy Usage by Nation-Sponsored Threat Actors

CYFIRMA uncovered Chinese, N. Korean and Russian state-sponsored hackers using open proxy servers in their many campaigns. This OOB report describes the profiles of their campaigns, and two samples are illustrated here:

Last Observation: Jun 2020
Campaign (Last Observed): $BLT20
Associated threat actors: Stone Panda (APT10) (Chinese)

Targeted geographies: US, UK, France, Italy, Japan
Targeted industries: Hospitality, Transport
Description: The campaign is suspected to be carried out by Mandarin-speaking hacker groups, believed to active since November 2019. In recent times, hacker groups were observed to be carrying out cyberattacks against a global hotel conglomerate to exfiltrate Personally Identifiable Information (PII).

Last Observation: Jun 2020
Campaign (Last Observed): Mud Nationals (Mud Nationals)
Associated threat actors: Lazarus Group (APT38, Hidden Cobra) (N. Korean)
Targeted geographies: Japan, Others
Targeted industries: Multiple Large Iconic Companies
Description: The campaign is suspected to be carried out by the Lazarus group of North Korea, aligned to the interests of government goals, and for financial gains. The primary intent of this campaign is to carry out corporate espionage to steal intellectual property details of major five technology organizations in Japan and trade them with local Chinese companies, under the guidance of Chinese hackers. The campaign has been active since July 2018 and has seen increased activity recently. Hackers has been targeting the product samples, its chemical composition, design, and architecture. CTI observed hackers’  interest in new cloud technologies, IoT, blockchain, automation systems, and robotics.

This OOB report also includes strategic, management, and tactical recommendations to help companies protect their network and data from cyberattacks using open proxies.

Email [email protected] for access to the full report.

 

Out of Band Notification: Next Emotet Campaign

As of December 25, CYFIRMA Threat Intelligence team had gathered indicators suggesting that a new wave of the notorious Emotet malware may strike Japan during the year end and the early days of 2020.

CTI has deduced that this campaign is motivated by financial gains and is looking to target Japanese companies, government entities and individual alike. The malware is looking to steal sensitive data, including financial details, login credentials, and address books, and is capable of moving laterally while opening channels to communicate back with its command and control server.

CYFIRMA Risk Rating for this Out of Band Notification was: HIGH

CTI advised the organizations to take precautionary measures as discussed in the following report, including the feeding of the reported IOCs to their own security controls for monitoring and blocking.

If you would like to read the report, please take a moment to complete the following form.

Out of band notification, UPDATE – PHP ACE VULNERABILITY

As on November 3, CYFIRMA Threat Intelligence had observed heightened interest in Korean and Russian speaking hacker groups about the PHP-FPM Vulnerability with NGINX tracked as CVE-201911043, an Arbitrary Code Execution Vulnerability.

This instance pointed to hackers seemingly working on reconnaissance tools to identify systems at a global scale which are using vulnerable PHP and NGINX combination.

The following details were associated with this campaign:

  • Target Nations: USA, UK, Australia, Japan, and India
  • Industry sector: Financial, Insurance, Manufacturing, Online platforms, payment systems, B2C retails platforms, etc.
  • Motivation: Data exfiltration, reputational damage

CYFIRMA Risk Rating for this Out of Band Notification was: CRITICAL

Analysis of captured hackers’ footprints and correlation with external threat vectors, indicate that this is a potential threat, and organizations were advised to take precautionary measures as discussed in the following report.

If you would like to read the report, please take a moment to complete the following form.

Out of band notification, UPDATE – NGINX WEBSERVER EXPLOIT

Between 29 May 2019 – 2 June 2019, CYFIRMA Threat Intelligence have observed Korean and Mandarin speaking hackers showing intense interest in NGINX Webserver in hackers community.
Under the active campaign: “LongNeck”, a global reconnaissance exercise was carried out by hackers to discover systems susceptible to vulnerabilities in NGNIX webserver/reverse proxy system. Hackers have successfully built the exploit: “Face-NGINX” to target the susceptible systems.
The primary motive of the exploit is to exfiltrate sensitive data along with carrying out operational disruption and reputational damage.
On 13th November 2018, CTI has observed hacker conversations in Dark web suggesting global reconnaissance namely “NGUME” and “LongNeck” to identify vulnerable NGINX web servers. We also suspect that malware authors are building a Denial of Service exploit, named Face-NGINX.

CYFIRMA Risk Rating for this Out of Band Notification is: LOW

Analysis of captured hackers’ footprints and correlation with external threat vectors indicate that this is a potential threat, and your organization is advised to take precautionary measures as highlighted in this report.

If you would like to read the report, please take a moment to complete the following form.

CYFIRMA’s Cyber Threat and Risk Prediction Report for 2019

AUTHOR

CYFIRMA

 

TOKYO/SINGAPORE, Nov 28, 2018: CYFIRMA releases its Cyber Threat and Risk Predictions for 2019.

Kumar Ritesh, CYFIRMA Chairman and CEO says “While 2018 was a year of financially motivated threat actors having a free run against individuals, organizations, institution and countries, we have noticed an increasing trend of state sponsors interested in arming threat actors to pursue defined geopolitical objectives. Cryptocurrency exchanges, healthcare companies, the energy sector, and traditional financial institutions were at the brunt of cyberattacks this year. What has been very interesting to witness is the shift in the hackers’ intention to use emerging technologies, increasing the difficulty to defend an expanding attack surface.”


Mr. Kumar Ritesh highlights the growing space for Cyber Threat Intelligence in 2019, and beyond!

CYFIRMA’s cyber analytics platform demonstrated its predictive capabilities by releasing 16 Early-Warning Threat Reports detailing imminent cyber threats to various technologies, across organizations, industries and countries, out of which 11 to date are active threats in the wild.

As we enter 2019, cyberattacks and breaches will continue to increase in intensity and frequency. Based on CYFIRMA’s research, the following trends and shifts will take precedence:

Hackers will unleash rejuvenated attacks by leveraging emerging technologies: In 2019, threat actors will show a greater affinity for emerging technologies by exploiting them handsomely. Multi-pronged cyberattacks will be operationalized with increased usage of AI/ML. This will lead to breaches in humanoid systems alongside blockchain ecosystems and other autonomous systems.

Tokyo 2020 Olympics will be a prime target for threat activities: Countries that are antagonistic to Japan will target the upcoming Tokyo Summer Olympic Games to cause reputational damage. The fact that these games will massively leverage on new-age technologies and digitalization will serve as a beacon for malicious actors.

State-sponsored/ corporate-sponsored espionage will take centerstage: The next leg of the global trade wars will be fought online- involving state sponsored actors and intelligence agencies initiating corporate cyberattacks. In 2018, the North Korean, Chinese and Russian state-sponsored attacks on nations and organizations have made global headlines. In 2019, additional countries will join the fray in a bid to highlight their own political power and technological might to meet their proxy objectives.

Hackers will place the highest value for personal behavioral data: Threat actors will exponentially leverage social engineering techniques to attack and mine behavioral data from individuals, societies, organizations and nations. Malicious actors will identify potential targets, recruit them inconspicuously, and exploit their access levels to penetrate government or corporate target systems in a seamless and highly camouflaged operation.

Cloud security will be repeatedly attacked for vulnerabilities: In 2018, AWS and Azure cloud assets were a favorite target for hackers’ intent on disrupting the public cloud security layer to unearth an assortment of individual and corporate data. In 2019, this trend will continue as hacker communities reiterate their inclination to this favorite prize. Unfortunately, most organizations are still not trending towards employing a comprehensive security policy for their cloud-based data assets and footprints, inadvertently playing into the hands of these threat actors.

Internet of Things (IoT) must contend with the hackers’ curiosity: In 2018, as many as 10 new variants of the infamous Mirai botnet were discovered, each employing the old attack vectors. Almost every IoT product manufacturer has exhibited device vulnerabilities, yet this industry is booming away. In 2019, renewed variants of legacy threats will be unearthed, and coupled with the lack of standardization amongst the manufacturers of IoT devices, cyberattacks on IoT sensors is going to ramp up at a never seen before scale. Further possibilities include, IoT weaponization, centralized collection units, and transaction ecosystems to support it all.

Identity Theft will be an extremely common phenomenon: Globally, both individual and business data will continue to suffer enormous breaches courtesy of privileged attack vectors. Identity theft, as always, will continue to be the mainstay campaign for threat actors who will now intently look towards the east for their exploits. In 2019, expect Asia, and especially Japan, to be severely tested by this problem, almost on a daily basis.

Multihomed malware attacks on the rise: In 2019, multihomed and multi-magnitude variants of crypto malwares, variety of banking trojans, ransomwares, etc. will expand into some of the biggest challenges to be faced by the cybersecurity professionals. 2018’s examples of SamSam and GandCrab, behavior mapping malware that showed uncanny adapting and evolution skills on the target system whilst mimicking legitimate software, offers some insights into what’s coming up in 2019, and beyond!

Hackers will be drawn to the vulnerabilities posed by Supply Chain Systems: The latest trend is supply chain attacks with embedded malware. In 2019, increasing number of attacks impacting corporate strategies and supply chain systems are anticipated requiring additional layers in cybersecurity strategy and policy considerations. This could be the first of many upcoming corporate attack strategies by way of supply chain systems.

DDoS attacks will not lose its potency or applicability: Distributed Denial of Service (DDoS) has always been a favorite with threat actors and the affection is only going to grow in 2019. Attributes such as the low campaign cost and associated rewards will continue to inspire hackers to plot and deploy DDoS attacks. Japan is and will continue to be one of the top 10 countries to be targeted by DDoS outbreaks.


The work is cut out: Modern industrial and business domains have a lot of catching up to do when it comes to cybersecurity, as highlighted by CYFIRMA’s Cyber Threat and Risk Predictions for 2019.

GDPR based theft will gain the organizations’ undivided attention: In 2019, with organizations needing to adhere with GDPR, they are exposed to any non-compliance related eventualities. One of the facets being fines dished out for not complying, thus opening up avenues for hackers to exploit remediation and regulatory procedures. Data being playing field worth billions of dollars, even a small attack could cost organizations as hackers see opportunities to earn millions.

AI and ML will power the next salvo of cyberattacks: As high as 70% of the companies will encounter botnet attacks with a flavor of AI/Machine Learning in the immediate future, with the cost of restitution running into an estimated USD 0.4 M per company. CYFIRMA’s research highlights the changing composition of these attacks- multi variant, altering behavior and multi-intent being the common signatures.

State-sponsored cyberattacks on critical infrastructure will be the norm: Operational technologies like PCI, HMI, Control and Workflow Systems will be high on the cybercriminals’ bucket lists. CYFIRMA’s research has indicated that threat actors are developing new attack methods featuring complex malwares to accomplish tasks such as passive asset discovery and control instruction hijacking.

The most common attack vector will continue to be Social Engineering and Phishing/Smishing: In 2019, organizations will finally figure out that employees are the weakest link in their cybersecurity posture. This will likely lead to the reassessment and redefinition of core internal security strategies, as the fact that the most prevalent attack vector isn’t the network, but the user becoming part of the conventional threat landscape.

Cryptocurrency exchanges and trading platforms will need fortification: As institutional capital progressively flows into the cryptocurrency market, thefts will correspondingly increase. The growing necessity for cryptocurrency mining will lead to renewed attacks on mining resources and unsuspecting victims. Already, the Japanese cryptocurrency exchanges and trading platforms have enticed great interest from hackers based out of China, North Korea, Russia and Ukraine. More are likely to follow suit, soon!

Kumar Ritesh reiterates that “the cybersecurity landscape of Japan and South East Asia is changing dramatically, due to the aggressive involvement of state-sponsored hackers and an expanding attack surface. Nations will also continue to acquire and build their cyber warfare capability to strengthen their national interests. Digital proliferation will continue to outpace the speed with which defense mechanisms are being invented and applied to protect emerging technologies. Organizations need to balance the need for new technologies to enable business efficiency, expansion, and flexibility while defending against the increasing complexity and variety of new attacks created by emerging technologies.”

There’s more from where this came from. Follow us on TwitterLinkedIn and Facebook and be in the know.

UPDATE – TOKYO OLYMPICS 2020 THEMED SPEAR PHISHING/SMISHING CAMPAIGN

Over the last 24 hours, CYFIRMA Threat Intelligence has gathered information which indicates that financially motivated Chinese speaking cybercriminals are developing infrastructure for staging phishing campaigns to sell fake Tokyo 2020 Olympics merchandise. These phishing emails abuse Tokyo 2020 Olympics brand and target English and Spanish speaking population.

Earlier Observations:

On 20th August 2018, CYFIRMA Threat Intelligence team issued an early warning of Tokyo Olympic themed phishing/smishing campaign. Mandarin and Russian speaking attackers were found colluding for a major data exfiltration campaign installing interceptor malware executable via phishing link/attachment.

On 4th September 2018, CYFIRMA gathered substantial evidences around the launch of the first of the five phishing campaigns.

On 19th September 2018, CYFIRMA gathered intel around hackers having launched the second phishing campaign.

The CYFIRMA Risk Rating for this Out of Band Notification is: HIGH

CTI have gathered additional Indicators of Compromise pertaining to possible future attack and continues to monitor and assess the situation. You are advised to take precautionary measures.

WARNING – HACKERS PREPARING TO LAUNCH ATTACKS AGAINST SUSCEPTIBLE APACHE STRUTS 2 SYSTEMS

In the last 24 hours, CTI has gathered additional details about the vulnerability CVE-2016-1000031. Once again, we suspect threat actor group BOLIC14 to be exploiting the vulnerability in the wild.

On 19th September 2018, CTI have gathered evidences suggesting that threat actor group BOLIC14 is performing large scale passive reconnaissance and targeting thousands of vulnerable systems using Struts2 RCE exploit – named PsionApache2 under the Bleeding Thunder campaign.

On 5th September 2018, CTI have noticed high scale passive port scanning originating repeatedly from a few identified Russian IP addresses and hackers claims of developing PsionApache2, an exploit for Apache Struts 2 vulnerability.

On 26th August 2018, CYFIRMA Threat Intelligence Team (“CTI”) intercepted multiple discussion threads in dark web channels about an exploit of remote code execution vulnerability (CVE-2018-11776) in Apache Struts 2 systems. The malicious actors were found discussing about launching reconnaissance campaign to find vulnerable websites and target them with the exploits created.

CYFIRMA Risk Rating for this Out of Band Notification is: CRITICAL

Analysis of captured hackers’ footprints and correlation with external threat vectors indicate that this is a potential threat, and your organization is advised to take precautionary measures as highlighted in this report.

Please download the report from the from below:

UPDATE – LETSDANCE RANSOMWARE CAMPAIGN

Over the last 24 hours, we have gathered additional indicators around LetsDance Ransomware.

Antuit Cyber Intelligence Research Team (“ACIRT”) has determined possibility of a Ransomware campaign dubbed as LetsDance targeted towards Japanese organizations.

The attack vector is suspected to be fake website/phishing email which downloads an initial malicious payload. This is a multistage ransomware campaign which aids the attacker to gain sensitive information from the target system and customize the final encryption payload.

Attackers are financially motivated. We suspect that a North Korean threat actor group dubbed as TENJACKAL is behind this ransomware campaign.

The Antuit Risk Rating for this Out of Band Notification is: HIGH

Analysis of captured threat actor footprints and correlation with external threat vectors indicates that this is a possible threat, and your organization is advised to take precautionary measures as highlighted in this report.

Please download the report from the from below:

WARNING OF A GDPR NON-COMPLIANT THEMED DATA STEALING MALWARE

Antuit Cyber Intelligence Research Team (“ACIRT”) has determined a possibility of GDPR Non-Compliant themed phishing campaign which distributes a Data Stealing malware.

The phishing email has a zipped attachment which contains a malicious Word document. It further downloads an executable which enables attackers to exfiltrate data from the targeted systems. Our analysis suggests that an unnamed Russian threat group is associated with this phishing campaign.

Since the last OOB report on 25th June 2018, ACIRT has gathered additional IOCs related to this campaign.

The Antuit Risk Rating for this Out of Band Notification is: HIGH

Analysis of captured threat actor footprints and correlation with external threat vectors indicates that this is a possible threat, and your organization is advised to take precautionary measures as highlighted in this report.

Please download the report from the from below:

UPDATE OF A NEW DOUBLE-FACE CRYPTOMINER CAMPAIGN

On 25th April, Antuit Cyber Intelligence Research Team (“ACIRT”) intercepted communications between threat actors in a few specific hacker forums, indicating a collusion to distribute a Double-Face Cryptominer malware targeting Financial, Energy, Retail and FMCG enterprises.

Earlier on 9th May, we had observed additional Indicators of Attack suggesting that the malware is in the wild. Involvement of threat actor group BOLIC is confirmed.

In last 24 hours, ACIRT has gathered additional Indicators of Compromise (IoC) which are closely associated with the threat actors and the above-mentioned campaign

Analysis of captured threat actor footprints and correlation with external threat vectors indicate that this is a possible threat, and your organization is advised to take precautionary measures as highlighted in this report.

Please download the report from the from below:

UPDATE OF A NEW PERMANENT LOCKDOWN RANSOMWARE CAMPAIGN

Over the last 24 hours, Antuit Cyber Intelligence Research Team (“ACIRT”) have observed an increase in chatter between threat actors in various deep, dark web and hacker forums indicating that they might be planning to launch a new Permanent Lockdown Ransomware campaign targeting Financial Institutions, Retail, Critical Infrastructure and Manufacturing enterprises. There are new evidences indicating of this campaign already making inroads in Australia, New Zealand and Japan.

We have observed multiple discussions were conducted in Korean and Mandarin. Correlation and analysis of these threat actor footprints with our Cyber Threat Intelligence Analytics Platform (CAP) indicate that this is a possible threat, and your organization is advised to take precautionary measures as highlighted in this report.

Please download the report from the from below:

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.