Month: July 2022

  • Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware Apps

    Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware Apps

    Toll Fraud Android Malware Apps

    Microsoft has detailed the evolving capabilities of toll fraud malware apps on Android, pointing out its “complex multi-step attack flow” and an improved mechanism to evade security analysis.

    Toll fraud belongs to a category of billing fraud wherein malicious mobile applications come with hidden subscription fees, roping in unsuspecting users to premium content without their knowledge or consent.

    It’s also different from other fleeceware threats in that the malicious functions are only carried out when a compromised device is connected to one of its target network operators.

    “It also, by default, uses cellular connection for its activities and forces devices to connect to the mobile network even if a Wi-Fi connection is available,” Dimitrios Valsamaras and Sang Shin Jung of the Microsoft 365 Defender Research Team said in an exhaustive analysis.

    “Once the connection to a target network is confirmed, it stealthily initiates a fraudulent subscription and confirms it without the user’s consent, in some cases even intercepting the one-time password (OTP) to do so.”

    Such apps are also known to suppress SMS notifications related to the subscription to prevent the victims from becoming aware of the fraudulent transaction and unsubscribing from the service.

    At its core, toll fraud takes advantage of the payment method which enables consumers to subscribe to paid services from websites that support the Wireless Application Protocol (WAP). This subscription fee gets charged directly to the users’ mobile phone bills, thus obviating the need for setting up a credit or debit card or entering a username and password.

    “If the user connects to the internet through mobile data, the mobile network operator can identify him/her by IP address,” Kaspersky noted in a 2017 report about WAP billing trojan clickers. “Mobile network operators charge users only if they are successfully identified.”

    Optionally, some providers can also require OTPs as a second layer of confirmation of the subscription prior to activating the service.

    “In the case of toll fraud, the malware performs the subscription on behalf of the user in a way that the overall process isn’t perceivable,” the researchers said. “The malware will communicate with a [command-and-control] server to retrieve a list of offered services.”

    It achieves this by first turning off Wi-Fi and turning on mobile data, followed by making use of JavaScript to stealthily subscribe to the service, and intercepting and sending the OTP code (if applicable) to complete the process.

    The JavaScript code, for its part, is designed to click on HTML elements that contain keywords such as “confirm,” “click,” and “continue” to programmatically initiate the subscription.

    Upon a successful fraudulent subscription, the malware either conceals the subscription notification messages or abuses its SMS permissions to delete incoming SMS messages containing information about the subscribed service from the mobile network operator.

    Toll fraud malware is also known to cloak its malicious behavior by means of dynamic code loading, a feature in Android that allows apps to pull additional modules from a remote server during runtime, making it ripe for abuse by malicious actors.

    From a security standpoint, this also means that a malware author can fashion an app such that the rogue functionality is only loaded when certain prerequisites are met, effectively defeating static code analysis checks.

    “If an app allows dynamic code loading and the dynamically loaded code is extracting text messages, it will be classified as a backdoor malware,” Google lays out in developer documentation about potentially harmful applications (PHAs).

    With an install rate of 0.022%, toll fraud apps accounted for 34.8% of all PHAs installed from the Android app marketplace in the first quarter 2022, ranking below spyware. Most of the installations originated from India, Russia, Mexico, Indonesia, and Turkey.

    To mitigate the threat of toll fraud malware, it’s recommended that users install applications only from the Google Play Store or other trusted sources, avoid granting excessive permissions to apps, and consider upgrading to a new device should it stop receiving software updates

  • Google Improves Its Password Manager to Boost Security Across All Platforms

    Google Improves Its Password Manager to Boost Security Across All Platforms

    Google on Thursday announced a slew of improvements to its password manager service aimed at creating a more consistent look and feel across different platforms.

    Central to the changes is a “simplified and unified management experience that’s the same in Chrome and Android settings,” Ali Sarraf, Google Chrome product manager, said in a blog post.

    The updates are also expected to automatically group multiple passwords for the same sites as well as introduce an option to manually add passwords. Although Google appears to be not ready yet to make Password Manager as a standalone app, users on Android can now add a shortcut to it on the homescreen.

    CyberSecurity

    In a related change on iOS, should users opt for Chrome as the default autofill provider, Password Manager comes with the ability to generate unique, strong passwords.

    The built-in Password Checkup feature on Android is receiving an upgrade of its own too. Beyond checking for hacked credentials, it can further highlight weak and reused passwords à la Apple iOS. Google is also expanding the compromised password warnings to Chrome users across all operating systems.

    Last but not least, Google is bringing a new “Touch-to-Login” to Chrome on Android that allows users to sign in to websites with a single tap after entering the credentials with autofill. It’s worth noting that Apple implemented a similar feature in Safari with iOS 12.2.

  • Johnny Depp Seen in Paris as He Prepares to Film New Movie Weeks After Amber Heard Trial

    Johnny Depp Seen in Paris as He Prepares to Film New Movie Weeks After Amber Heard Trial

    Johnny Depp seen in Paris to shoot new movie with French actress director Maiwenn. After 6 weeks of a complicated trial against Amber Heard, Johnny Depp arrived in Paris. He also took the opportunity to do the fitting of costumes and wigs for the shooting of his next film of Maiwenn Le Besco which will start in early August and in which he will play Louis XV. During that time he has not seen Vanessa at all despite the fact that she was in Paris as well. Johnny stayed at Hayat hotel and came back late at night after costumes fitting. 18 Jun 2022
    Johnny Depp seen in Paris to shoot new movie with French actress director Maiwenn. After 6 weeks of a complicated trial against Amber Heard, Johnny Depp arrived in Paris. He also took the opportunity to do the fitting of costumes and wigs for the shooting of his next film of Maiwenn Le Besco which will start in early August and in which he will play Louis XV. During that time he has not seen Vanessa at all despite the fact that she was in Paris as well. Johnny stayed at Hayat hotel and came back late at night after costumes fitting. 18 Jun 2022

    Love Paris/MEGA Johnny Depp

    Johnny Depp is back to making movies.

    Weeks after his win in the defamation case he brought against ex-wife Amber Heard, the actor was photographed in Paris last weekend, where he’s set to shoot his new movie with French filmmaker Maïwenn.

    Depp, 59, was snapped in a tan jacket with fringe detailing and black jeans, carrying a black briefcase and accessorizing in a pair of sunglasses and wide-brimmed brown hat. He wore his multicolored hair in multiple braids.

    The actor is set to take on the role of French King Louis XV in the movie, which Variety previously reported would begin filming this summer around Paris, primarily at the Palace of Versailles, and last three months.

    According to the outlet, Maïwenn, 46, will also star alongside Depp as Countess Jeanne du Barry, Louis XV’s final mistress.

  • Johnny Depp might seize Amber Heard’s property if she doesn’t pay him

    Johnny Depp might seize Amber Heard’s property if she doesn’t pay him

    Johnny Depp might seize Amber Heard’s property if she fails to pay him $8 million in damages after losing the blockbuster defamation trial.

    The New York Post reported that the Aquaman actor had gone bankrupt after which Heard would sell her assets to pay for the compensation to Depp.

    If the actor is unable to pay Depp the damages, the Pirates of the Caribbean star could seize her California house, a legal expert Jeremiah Denton said.

    “[Depp] can institute collection proceedings so he can garnish [Heard’s] pay, if she has a salary or wage-type income,” the outlet quoted Denton.

    “He can attach her assets which basically means seize them. He can get to her assets, sell them and take cash,” Denton added,

    Meanwhile, Heard, may be forced to use an expensive gift – a Tesla Model X, from her ex Elon Musk to pay Depp.

  • Johnny Depp’s assault case could be blown up by THIS key witness

    Johnny Depp’s assault case could be blown up by THIS key witness

    Johnny Depp’s assault case could be blown up by THIS key witness
    Johnny Depp’s assault case could be blown up by THIS key witness 

    Johnny Depp’s forthcoming trial could roll out in the favour of the actor as a key witness is reportedly preparing to give a bombshell testimony in court.

    The Pirates of the Caribbean actor, who recently won a blockbuster defamation case against Amber Heard, has an assault case waiting for him after a location manager Gregg “Rocky” Brooks accused Depp of punching him in the ribcage on the set of the City of Lies in 2018.

    According to Radar Online, a former Green Beret and retired 35-year-old veteran of the Los Angeles Police Department Officer John Bigrigg has come forward with his claims.

    The outlet shared a recording of Bigrigg who worked with the L.A. Film Unit at the time of the alleged assault.

    “I walked over to where the disturbance was, and it was already over. Neither of the combatants showed no sign of wear, complained of injuries, or said that they wanted to press charges,” he could be heard saying on the tape.

    Officer Bigrigg’s recollection of the incident contradicts Brook’s claims in the court documents.

    He claimed that the alleged altercation started when he informed Depp that they were shooting the film after the time of their permit. 

  • Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers

    Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers

    Cryptomining Malware Hacking Linux

    A cloud threat actor group tracked as 8220 has updated its malware toolset to breach Linux servers with the goal of installing crypto miners as part of a long-running campaign.

    “The updates include the deployment of new versions of a crypto miner and an IRC bot,” Microsoft Security Intelligence said in a series of tweets on Thursday. “The group has actively updated its techniques and payloads over the last year.”

    8220, active since early 2017, is a Chinese-speaking, Monero-mining threat actor so named for its preference to communicate with command-and-control (C2) servers over port 8220. It’s also the developer of a tool called whatMiner, which has been co-opted by the Rocke cybercrime group in their attacks.

    In July 2019, the Alibaba Cloud Security Team uncovered an extra shift in the adversary’s tactics, noting its use of rootkits to hide the mining program. Two years later, the gang resurfaced with Tsunami IRC botnet variants and a custom “PwnRig” miner.

    Now according to Microsoft, the most recent campaign striking i686 and x86_64 Linux systems has been observed weaponizing remote code execution exploits for the freshly disclosed Atlassian Confluence Server (CVE-2022-26134) and Oracle WebLogic (CVE-2019-2725) for initial access.

    This step is succeeded by the retrieval of a malware loader from a remote server that’s designed to drop the PwnRig miner and an IRC bot, but not before taking steps to evade detection by erasing log files and disabling cloud monitoring and security software.

    Besides achieving persistence by means of a cron job, the “loader uses the IP port scanner tool ‘masscan’ to find other SSH servers in the network, and then uses the GoLang-based SSH brute force tool ‘spirit’ to propagate,” Microsoft said.

    CyberSecurity

    The findings come as Akamai revealed that the Atlassian Confluence flaw is witnessing a steady 20,000 exploitation attempts per day that are launched from about 6,000 IPs, down from a peak of 100,000 in the immediate aftermath of the bug disclosure on June 2, 2022. 67% of the attacks are said to have originated from the U.S.

    “In the lead, commerce accounts for 38% of the attack activity, followed by high tech and financial services, respectively,” Akamai’s Chen Doytshman said this week. “These top three verticals make up more than 75% of the activity.”

    The attacks range from vulnerability probes to determine if the target system is susceptible to injection of malware such as web shells and crypto miners, the cloud security company noted.

    “What is particularly concerning is how much of a shift upward this attack type has garnered over the last several weeks,” Doytshman added. “As we have seen with similar vulnerabilities, this CVE-2022-26134 will likely continue to be exploited for at least the next couple of years.”

  • Amazon Quietly Patches ‘High Severity’ Vulnerability in Android Photos App

    Amazon Quietly Patches ‘High Severity’ Vulnerability in Android Photos App

    Amazon

    Amazon, in December 2021, patched a high severity vulnerability affecting its Photos app for Android that could have been exploited to steal a user’s access tokens.

    “The Amazon access token is used to authenticate the user across multiple Amazon APIs, some of which contain personal data such as full name, email, and address,” Checkmarx researchers João Morais and Pedro Umbelino said. “Others, like the Amazon Drive API, allow an attacker full access to the user’s files.”

    The Israeli application security testing company reported the issue to Amazon on November 7, 2021, following which the tech giant rolled out a fix on December 18, 2021.

    The leak is the result of a misconfiguration in one of the app’s components named “com.amazon.gallery.thor.app.activity.ThorViewActivity” that’s defined in the AndroidManifest.xml file and which, when launched, initiates an HTTP request with a header containing the access token.

    Amazon Photo App vulnerability

    In a nutshell, it means that an external app could send an intent — a message to facilitate communication between apps — to launch the vulnerable activity in question and redirect the HTTP request to an attacker-controlled server and extract the access token.

    Calling the bug a case of broken authentication, the cybersecurity company said the issue could have enabled malicious apps installed on the device to grab the access tokens, granting the attacker permissions to make use of the APIs for follow-on activities.

    This could vary from deleting files and folders in Amazon Drive to even exploiting the access to stage a ransomware attack by reading, encrypting, and re-writing a victim’s files while erasing their history.

    Checkmarx further noted that the vulnerability might have had a broader impact given that the APIs exploited as part of its proof-of-concept (PoC) constitute only a small subset of the entire Amazon ecosystem.

  • New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the Wild

    New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the Wild

    Microsoft IIS Servers

    A newly discovered malware has been put to use in the wild at least since March 2021 to backdoor Microsoft Exchange servers belonging to a wide range of entities worldwide, with infections lingering in 20 organizations as of June 2022.

    Dubbed SessionManager, the malicious tool masquerades as a module for Internet Information Services (IIS), a web server software for Windows systems, after exploiting one of the ProxyLogon flaws within Exchange servers.

    Targets included 24 distinct NGOs, government, military, and industrial organizations spanning Africa, South America, Asia, Europe, Russia and the Middle East. A total of 34 servers have been compromised by a SessionManager variant to date.

    This is far from the first time the technique has been observed in real-world attacks. The use of a rogue IIS module as a means to distribute stealthy implants mirrors the tactics of a credential stealer called Owowa that came to light in December 2021.

    “Dropping an IIS module as a backdoor enables threat actors to maintain persistent, update-resistant and relatively stealthy access to the IT infrastructure of a targeted organization; be it to collect emails, update further malicious access, or clandestinely manage compromised servers that can be leveraged as malicious infrastructure,” Kaspersky researcher Pierre Delcher said.

    The Russian cybersecurity firm attributed the intrusions with medium-to-high confidence to an adversary tracked as Gelsemium, citing overlaps in the malware samples linked to the two groups and victims targeted.

    ProxyLogon, since its disclosure in March 2021, has attracted the repeated attention of several threat actors, and the latest attack chain is no exception, with the Gelsemium crew exploiting the flaws to drop SessionManager, a backdoor coded in C++ and is engineered to process HTTP requests sent to the server.

    “Such malicious modules usually expect seemingly legitimate but specifically crafted HTTP requests from their operators, trigger actions based on the operators’ hidden instructions if any, then transparently pass the request to the server for it to be processed just like any other request,” Delcher explained.

    Said to be a “lightweight persistent initial access backdoor,” SessionManager comes with capabilities to read, write, and delete arbitrary files; execute binaries from the server; and establish communications with other endpoints in the network.

    The malware further acts as a covert channel to conduct reconnaissance, gather in-memory passwords, and deliver additional tools such as Mimikatz as well as a memory dump utility from Avast.

    The findings come as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged government agencies and private sector entities using the Exchange platform to switch from the legacy Basic Authentication method to Modern Authentication alternatives prior to its deprecation on October 1, 2022.

  • Solving the indirect vulnerability enigma – fixing indirect vulnerabilities without breaking your dependency tree

    Solving the indirect vulnerability enigma – fixing indirect vulnerabilities without breaking your dependency tree

    vulnerabilities

    Fixing indirect vulnerabilities is one of those complex, tedious and, quite frankly, boring tasks that no one really wants to touch. No one except for Debricked, it seems. Sure, there are lots of ways to do it manually, but can it be done automatically with minimal risk of breaking changes? The Debricked team decided to find out.

    A forest full of fragile trees

    So, where do you even start?

    Firstly, there needs to be a way to fix the vulnerability, which, for indirect dependencies, is no walk in the park. Secondly, it needs to be done in a safe way, or, without anything breaking.

    You see, indirect dependencies are introduced deep down the dependency tree and it’s very tricky to get to the exact version you want. As Debricked’s Head of R&D once put it, “You are turning the knobs by playing around with your direct dependencies and praying to Torvalds that the correct indirect packages are resolved. When Torvalds is in your favour, you have to sacrifice some cloud storage to uncle Bob to make sure the updates don’t break your application.”

    In other words, there really should be an easier, less stressful, way to do it.

    In this article, we’ll walk you through how solving transitive vulnerabilities can be done manually and, towards the end, show you the Debricked solution, which allows you to do it automatically. If you’re really just interested in the solution, I suggest you start scrolling.

    Precision surgery on your dependency tree

    During the research phase of the graph-database project, or, how Debricked today fixes your open source vulnerabilities at the speed of light, the team stumbled upon some articles explaining how to fix indirect vulnerabilities in NPM.

    As stated in the article, the `minimist` package is affected by vulnerabilities, namely CVE-2021-44906 and CVE-2020-7598.

    These are both “Prototype Pollution” vulnerabilities, meaning that arguments are not properly sanitized. Luckily, the maintainers of `minimist` fixed these vulnerabilities in version 1.2.6.

    Unfortunately, `mocha` version 7.1.0 resolves `minimist` 0.0.8, which is within the vulnerable range of these vulnerabilities. As suggested by the author of this article, these vulnerabilities can be fixed in a few different ways.

    But! What about breaking changes?

    The first suggestion is to simply trigger an update of all “indirect dependencies”, meaning that we won’t actually change the version of `mocha`. To perform this update, simply run `npm update`, delete your `npm.lock` file, and run `npm install`. This regenerates the dependency tree with the latest possible version (according to constraints) of your indirect dependencies. With this method, the risk of breaking changes is very low as you actually don’t update any of your root dependencies, just your indirect ones.

    Breaking changes occur when the package functionality or interface is not forward compatible, meaning that an update to the package could cause your application to break. Common breaking changes are class/function-removal, change of arguments to a function, or licence-change (watch out for that one!).

    But life is not always this easy, and this simple update of the tree will not solve the vulnerability. The problem is that `mkdirp` has actually locked their version of `minimist` to 0.0.8. This means that the contributors of `mkdirp` have come to the conclusion that they are not compatible with newer versions of `minimist`, and forcing the update of `minimist` may introduce breaking changes between `mkdirp` and `minimist`.

    Think… graphs!

    So, the million-dollar question is: what version of `mocha` should be used, that in turn trickles down to a safe version of `minimist` without breaking the dependency tree? This is actually a graph problem, which has been described in this article.

    What graph algorithm would solve this problem? How NPM resolves dependencies can be a bit complicated, as they are allowed to “split” the dependency tree. This means that they can have multiple versions of one dependency to make sure that we always have a tree that is compatible. To solve the vulnerability, we need to make sure that all instances of `minimist` are safe by updating all roots that can trickle down to `minimist`.

    The algorithm used to solve this problem is called “All Max Paths Safe”. By walking down the dependency graph and keeping the max versions, all while pruning all other versions of that package in each intersection, we can create an approximate representation of our dependency tree. If the approximation is safe, that means that our real tree will be safe as well!

    By performing this algorithm for all potential versions of `mocha`, we find the smallest upgrade to fix this vulnerability. To get the speed we wanted for this algorithm, the team had to build a custom Neo4j procedure, which can handle searching over 100 root versions with a search depth of 30+ in ~150 milliseconds. Speedy, huh?

    In this case, we don’t have to search very far… as 7.1.1 of `mocha` is safe! This is only a patch update, which indicates that the risk of breaking changes is very low. For less complex cases (like this example), ‘npm audit’ can help you with their fantastic ‘npm audit fix’ command.

    Don’t be ad-hoc, enter the pub-sub-human way of working!

    Now, if you got this far (congratulations, very impressive) and thought, “this sounds really complex and like an awful lot of work,” don’t worry – you’re not the only one. Luckily, all this happens completely automatically in the Debricked tool when clicking this little button:

    As of right now, this is available for Javascript. Soon, the support will be extended to Java, Golang, C#, Python and PHP.

    If you’re not yet a Debricked user, what are you waiting for? It’s free for single devs, smaller teams and open source projects (and if you’re a larger organization, fear not. There’s a generous free trial). Sign up for free here.

  • Wait, The House Amber Heard Rented During The Johnny Depp Trial Cost How Much A Month?

    Wait, The House Amber Heard Rented During The Johnny Depp Trial Cost How Much A Month?

    The 13,000 square foot mansion sits on an acre of property.

    It takes a lot for me to doubletake at real estate prices. I used to live in Los Angeles and am aware the housing market has been running wild lately. I also know that celebrities have different needs and expectations than many of the rest of us, but even so, I was a bit rattled by the supposed cost of the home Amber Heard was renting during the Johnny Depp trial. A new report is claiming the property fetched $22,500 a month.

    The news comes courtesy of TMZ, who claims they got a hold of the contract. It reportedly didn’t include her name, but the outlet says they spoke with Heard’s alleged neighbors during the trial who said they spotted the actress coming and going alongside her daughter, sister and security detail. That contract was reportedly for $22,500 a month.

    So, what does $22,500 a month buy you? Well, the home in question, which is a bit under 30 minutes from the Fairfax County Courthouse, is reportedly a 13,000 square foot mansion. It sits on an acre of land and comes with its own tennis court. The inside reportedly contains a home theater room, as well as a fitness room and spa. There’s no word on how many bathrooms, which is always my favorite stat in giant homes, but as a comparison, Jennifer Lopez and Ben Affleck were recently looking at a 20,000 square foot place that had 17

    This monthly price tag is extremely high for most of us, but it wouldn’t ordinarily create headlines among celebrities. Kylie, Kendall And Kris Jenner once allegedly rented a home for $450,000 a month as a shocking comparison, but a focus on Amber Heard’s finances is a lot more pressing in light of her recent loss in court to Johnny Depp. She’s going to appeal the verdict, but as of now, she owes her former spouse over $8M, which her own attorney says she can’t afford to pay.

    Johnny Depp and Amber Heard were married from 2015 to 2017 in what was, by all accounts, a volatile relationship. They’ve been in and out of court since their split. Their most recent, highly publicized trial was over an op-ed she wrote in which she claimed to be a victim of domestic violence. Depp sued for defamation, and the recent televised coverage saw a parade of witnesses come forward, testifying to the inner workings of their personal lives.

    Both Depp and Heard also took the stand separately and accused the other of numerous very serious allegations. Drug use and spousal abuse were regular themes throughout the trial, but there was also often a lighter circus-like atmosphere, as the general public watched and argued over topics like who pooped in the bed, what one expert was doing with his mouth and how loudly a witness farted.

    The jury ultimately decided mostly in his favor and awarded him $15M in damages, which was automatically reduced to $10.3M because of Virginia laws. The jury mostly ruled against her in her countersuit but ruled in her favor on one defamation count related to statements made by Depp’s former attorney. She was awarded $2,000,000, which is where the $8.3M ultimately comes from.

    It’s likely there will be more court proceedings between these two in the future, but exactly what the next steps are right now is unclear. Whenever there is forward progress, expect to see a lot of media coverage, and assumedly, at least one outlet once again trying to figure out how much her rental home costs.