Category: Technology

  • The Most Dangerous Threat to Your Staff and Business Survival

    [ad_1]

    Being involved with technology solutions professionals see things that could be a real threat to you, your staff or even your business; while the internet can be seen as a wonderful tool (cloud based communications and solutions for example) and all of the other great achievements that the internet has created there is a far darker side to it all; of that there is no doubt and it can be a real threat.

    And factually you have in your business nowhere to run or nowhere to hide; sooner or later it becomes a high odd’s bet that employee, you or your company will suffer and in severe cases the effects could even close your company overnight.

    Don’t believe this? Read on where examples of actual major threats are shown below. Not worried? You should be!

    It’s so dangerous that Deloitte opened a cyber threat hunting service!

    But on an everyday level to ordinary SME’s just like your business there really is no amount of anti virus this or anti malware that available that is really going to help; the examples below show you exactly why; things these days have moved on exponentially to levels that you may not believe, but some are revealed that are actual examples highlighting just how bad these threats have become. There will be casualties no doubt but you don’t want to be one of them!

    Email has been a driving force that has moved forward communications between every aspect of business that anyone could imagine, from sales, customers, support, management, publicity and many more important areas; but it’s obvious that the underlying technology of email servers are flawed and because it’s now a worldwide transport for communications that’s hard to fix; these communications channels have to be compatible with every other email server in the world and that creates massive inherent vulnerabilities.

    In almost every town, city or country, government bodies are working towards combating fraud and other nasty things from many areas, but email is one of the most widely abused platforms there is because of the ease of abuse by non-experts. And if you’re not an expert it does not take long to learn how to be one!

    One organisation in the UK is Action Fraud operated by the police and while they handle other areas of fraud, email scams are very high on their list.

    But here’s where things start to get nasty. Since the advent of cryptocurrency worldwide fraud has increased exponentially. And in the USA SEC Rejects Bitcoin Exchange Traded Fund because they are very concerned about investor losses in Bitcoin.

    However, this article is specific; Bitcoin is being used fraudulently and in both of the cases shown below Bitcoin is clearly involved in the transportation of monies to the perpetrators of these illegal demands on you, your staff or even your business. It’s no joke and anyone ignoring these really bad potential harms to their organisation will sooner or later come unstuck in maybe a really big way. The results could be catostrophic.

    The first example shown below included personal details of the recipient that have been removed for security reasons. But this email (that passed every check through a company’s infrastructure) is threatening the life of an employee and should never be ignored.

    Note that bitcoin and email addresses are edited for security purposes throughout this article.

    HERE IS EXAMPLE ONE VERBATIM:

    “From: kristin*********

    Sent: ******

    To: *********

    Subject: How to save themself

    Read this warn carefully, since it can be the last in your life.

    People are by nature envious. Given the fact of successful development of your business, people (your contestant ) paid me 30,000 Pound Sterling for your head on a stick.

    It’s not the first time I’ve done this kind of work, but I’m already tired of these envious bastards and your life will be the last one I’ll take or will not do, it’s up to you.

    Under normal circumstances, I would just do the work for which I was paid without going into the details, but I’m going to get away from it and go on a long-awaited vacation.

    You have 2 versions for deciding this problem.

    Adopt my proposal or refuse.

    You pay me 5 thousand GBP for safe your life and you receive all the information about the customer with whom you apply to the police and thus you save your life and the lives of your relatives.

    The second option is you ignore my proposal and turn to the police, but by the same token you will only postpone your judgment day, even if I can not do the work, then somebody else will do it, not within a week and say in a month or half a year, but order for your head will be fulfilled sooner or later.

    Thus, you will be afraid of every rustle, walk around looking and thinking that you are being persecuted.

    If you want such a life, your choice, but if I were you, I would think very well.

    Tickets to England have been taken for July **, and you have exactly 3 days to transfer money to an anonymous account bitcoin 1QJNjRmon3iD3RwdjaGomFLHs25B******.

    I can check the last time receipt of money before the flight to you, on the **th

    In the event of receiving a reward, I will not come to take your life, but will also pass all the information about your customer (Let the bastards get what they deserve) and you can protect yourself, otherwise you know the consequences.

    The well-being of the future life depends on your choice.

    Think about your life, you family.

    on all will of Allah”

    END OF EMAIL MESSAGE ONE

    The above email is unedited except for recipients details and Bitcoin account numbers. It can be clearly seen in this email that there is a threat on the life of the recipient. While some recipients would simply brush this type of email off, others become extremely concerned; it’s easy to see exactly why. Indeed some recipients will go and pay the demanded money and not think twice. Imagine that a key employee received this email and they completely believed its contents? The resultant downfall of the employee could be extreme. This email threatens the recipients life and mentions their family etc.

    Notice that the spelling is incorrect for English on this example (undisclosed but its in the content) and somehow the writer suggests that the email is the ‘will of Allah’. Probably not. But the user identified the recipient was in ‘England’ likely from the email address so the recipient could believe some of the contents.

    The above email passed numerous checks throughout the receiving companies infrastructure. Now it’s easy to see if you are tech savvy, but most email users are not. And if you’re a small SME then things could happen that could literally create very serious effects on your business even though the email targeted an employee. But if you’re not tech savvy and a company owner, would you believe the above? and send money? Many will have and that ‘feeds’ the criminals for millions of pounds or in this case $US.

    Bitcoin in the above example is used because Bitcoin CANNOT be traced to the ultimate recipient of the payment. This is a major flaw in crypto currency and one reason (irrespective of some suggesting it’s an easy way to make money) you really should have nothing to do with it. Criminals use Bitcoin all the time.

    As suggested, you just might not believe the above email if you received it, but there is no doubt that you might well believe the next example because it has information in it that is only known by you!

    HERE IS EXAMPLE TWO VERBATIM:

    From: “Gloriana Feany”

    To: *********************

    Date: *********

    Subject: (HERE WAS THE USERS NAME AND THEIR PASSWORD)

    I know ****** is your password. Lets get right to the purpose. You may not know me and you are most likely thinking why you are getting this email? Nobody has paid me to check you.

    actually, I actually setup a malware on the X videos (porn material) web site and you know what, you visited this site to have fun (you know what I mean). While you were viewing videos, your web browser initiated operating as a RDP that has a key logger which gave me access to your display and webcam. Immediately after that, my software program gathered every one of your contacts from your Messenger, social networks, and emailaccount. And then I created a video. First part displays the video you were watching (you’ve got a fine taste hehe), and 2nd part displays the recording of your web camera, yea it is u.

    There are two different possibilities. Let us take a look at each one of these options in details:

    1st alternative is to skip this message. In this case, I most certainly will send your very own video clip to all your your contacts and visualize concerning the humiliation you will see. Moreover if you happen to be in a committed relationship, how it will affect?

    Next choice should be to give me $3000. We are going to call it a donation. In this scenario, I most certainly will quickly remove your videotape. You will continue your way of life like this never took place and you will never hear back again from me.

    You will make the payment through Bitcoin (if you do not know this, search for “how to buy bitcoin” in Google search engine).

    BTC Address: 18PvdmxemjDkNxHF3p3Fu9wkaAZ********

    [CASE sensitive, copy & paste it]

    In case you are thinking about going to the law enforcement officials, very well, this e-mail can not be traced back to me. I have covered my actions. I am also not trying to charge you a lot, I simply want to be rewarded. I’ve a unique pixel in this e-mail, and at this moment I know that you have read through this email message. You have one day in order to pay. If I don’t get the BitCoins, I will certainly send your video to all of your contacts including family members, colleagues, etc. Having said that, if I receive the payment, I’ll erase the recording right away. If you really want evidence, reply Yup! then I will send out your video to your 7 friends. This is the non-negotiable offer, and thus please do not waste my personal time & yours by responding to this e mail.

    END OF EXAMPLE TWO EMAIL:

    This is an entirely different threat. The recipient picked this email up because of a multitude of reasons that were simply incorrect and not representative of their actions on the internet; however, the stated password was about 80% shown (and it would be reasonable to assume the perpetrator knew the rest of the password). This could be seen by many as a factual document and it’s credibility is created in the recipients mind by the inclusion of the password in to the threat.

    Imagine owning a SME business that might indeed be a larger business, the threat demanded much more money and the recipient had viewed what was suggested in the email? People do. It could be seen as likely or at;east a possibility that the recipient might well pay the money to the perpetrator through Bitcoin. And again Bitcoin rears its ugly head.

    Again in this second email instance shown the email passed all checks and tests in the company where the email was received. So these are real threats to individuals or business.

    But consider this; how did the perpetrator get the recipients password? (it was an old password but nevertheless was mostly valid). The perpetrator suggested key logging on a site known for pornographic video and images. But that is most likely not where the perp got the details from.

    When reading about companies like Facebook, TalkTalk, Dixons Carphone Warehouse, Equifax, Adobe, AOL, Apple, AT&T, British Airways, Mastercard and Visa, Compass Bank, Dominos Pizza, DVLA UK, Dropbox, Kmart, Hewlett Packard, eBay, Experian, Trump Hotels, Gmail, Vodaphone, Walmart, Morgan Stanley, NHS, Ofcom, SnapChat, Adidas, Macys, Sony Pictures (and the list goes on) is it really no wonder that most personal details of importance (even financially) of individuals and businesses are all over the internet. There is a Wikipedia about these breaches of data that is extremely concerning reading as these breaches involve all kinds of information that will no doubt be available to buy on the internet. With the incredible reductions in share prices at Facebook maybe that might be the start of a mass exodus from those sort of ‘social media’ sites; but of course Facebook is merely one of the very long list of companies that have let you down through not protecting your data properly as the list above clearly demonstrates.

    Its easy to see why GDPR has become law and countries will continue to pass GDPR legislation accordingly. Thank all of the companies mentioned above and many more for allowing this ridiculous situation that could be the start of the downfall of the internet as it is known today.

    But is it time to go back and retrospectively fine each and every company involved in the dispersal of personal details? Are those companies any less ‘guilty’ now? It seems for many companies that the only thing they understand is when they are faced with very large fines; and even the fines might be irrelevant to organisations like Facebook and Google because large fines seem to be ‘petty cash’ to some of those companies. But shere price reduction wakes them up.

    If anyone is concerned about a ‘key logger’ from the above email example getting your information Kaspersky latest offering of internet security includes software that stops key loggers from logging your information as you type.

    A third example of fraud covered in this article relates to a company that received an email pro-forma invoice to pay from one of its regular suppliers. One day the finance department received a pro-forma invoice that needed to be paid immediately. The email address and the invoice itself looked entirely unremarkable. The sending company advised the finance department that they had recently changed banks and that the new details were on the invoice attached. Finance paid the £60,000+ ( $US 80,000) invoice.

    The only problem was, that the invoice was completely fraudulent, the email address did read correctly unless you looked close (instead of wonderful.com it was wonderfull.com (just made up example to illustrate the methodology used) and the recipient in the finance department saw and read what they were used to seeing. The real question is, how did the perpetrators get all that information about what an invoice should be like, the real suppliers details, etc., their website and email addresses and more; it’s food for thought and make no mistake it can be so easy to allow one of these scams through your business; the chances are pretty high and the consequences could be dire and even bankrupt your business if taken to the extreme.

    There is no doubt that the underlying email systems are no longer fit for purpose in general and have not been for some time. Notice that in the first example the scammer sent mail from ‘mail.bg’ and the second one (even more concerning) was from ‘outlook.com’. While the sending email addresses can be ‘replaced’ with any email address upon examination those two shown emails seemed to be real; indeed one of the perps even used Google to advise how to use Bitcoin for payment. But there are multiples of very large companies that every day offer a service but allow their email servers and systems to send out such threatening emails to users. Maybe it’s time to pressure these organisations (outlook.com, gmail.com and there are multiples of others) to actually filter their emails properly as well as the sendersbefore these sort of threats go out and create serious harm that these sort of messages could easily do.

    Of course there are millions of other examples of fraud through an outdated abused email system (and other related internet technologies) that could be shown here, but the aim of this article is to educate readers so that they don’t fall foul to these sort of appalling scams.

    One company, Network Systems has seen many of these sort of internet related issues and offers a cybercrime service to SME’s to help to create a safe environment for empolyees and business as they work on the internet today.

    Hopefully this article will at least make the reader think very hard about how they are going to ensure protection of employees and their company and if nothing else that is a wothwhile objective. Using specialist companies will always help more than by just trying to put solutions in place created by someone without experience in this area and could actually save your company.

    [ad_2]

    Source by Anthony Mckenzie

  • Medibank Refuses to Pay Ransom After 9.7 Million Customers Exposed in Ransomware Hack

    Medibank Refuses to Pay Ransom After 9.7 Million Customers Exposed in Ransomware Hack

    Australian health insurer Medibank today confirmed that personal data belonging to around 9.7 million of its current and former customers were accessed following a ransomware incident.

    The attack, according to the company, was detected in its IT network on October 12 in a manner that it said was “consistent with the precursors to a ransomware event,” prompting it to isolate its systems, but not before the attackers exfiltrated the data.

    “This figure represents around 5.1 million Medibank customers, around 2.8 million ahm customers, and around 1.8 million international customers,” Medibank noted.

    Compromised details include names, dates of birth, addresses, phone numbers, and email addresses, as well as Medicare numbers (but not expiry dates) for ahm customers, and passport numbers (but not expiry dates) and visa details for international student customers.

    It further said the incident resulted in the theft of health claims data for about 160,000 Medibank customers, around 300,000 ahm customers, and around 20,000 international customers.

    This category comprises service provider name, the locations where customers received certain medical services, and codes associated with diagnosis and procedures that were administered.

    Medibank, however, said financial information and identity documents like drivers licenses have not been siphoned as part of the security breach and that no unusual activity was observed since October 12, 2022.

    “Given the nature of this crime, unfortunately we now believe that all of the customer data accessed could have been taken by the criminal,” the company said, urging customers to be on the alert for any potential leaks.

    In a standalone investor statement, the company also said it will not make any ransom payment to the threat actor, stating doing so will only encourage the attacker to extort its customers and make Australia a bigger target.

  • Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware Apps

    Microsoft Warns About Evolving Capabilities of Toll Fraud Android Malware Apps

    Toll Fraud Android Malware Apps

    Microsoft has detailed the evolving capabilities of toll fraud malware apps on Android, pointing out its “complex multi-step attack flow” and an improved mechanism to evade security analysis.

    Toll fraud belongs to a category of billing fraud wherein malicious mobile applications come with hidden subscription fees, roping in unsuspecting users to premium content without their knowledge or consent.

    It’s also different from other fleeceware threats in that the malicious functions are only carried out when a compromised device is connected to one of its target network operators.

    “It also, by default, uses cellular connection for its activities and forces devices to connect to the mobile network even if a Wi-Fi connection is available,” Dimitrios Valsamaras and Sang Shin Jung of the Microsoft 365 Defender Research Team said in an exhaustive analysis.

    “Once the connection to a target network is confirmed, it stealthily initiates a fraudulent subscription and confirms it without the user’s consent, in some cases even intercepting the one-time password (OTP) to do so.”

    Such apps are also known to suppress SMS notifications related to the subscription to prevent the victims from becoming aware of the fraudulent transaction and unsubscribing from the service.

    At its core, toll fraud takes advantage of the payment method which enables consumers to subscribe to paid services from websites that support the Wireless Application Protocol (WAP). This subscription fee gets charged directly to the users’ mobile phone bills, thus obviating the need for setting up a credit or debit card or entering a username and password.

    “If the user connects to the internet through mobile data, the mobile network operator can identify him/her by IP address,” Kaspersky noted in a 2017 report about WAP billing trojan clickers. “Mobile network operators charge users only if they are successfully identified.”

    Optionally, some providers can also require OTPs as a second layer of confirmation of the subscription prior to activating the service.

    “In the case of toll fraud, the malware performs the subscription on behalf of the user in a way that the overall process isn’t perceivable,” the researchers said. “The malware will communicate with a [command-and-control] server to retrieve a list of offered services.”

    It achieves this by first turning off Wi-Fi and turning on mobile data, followed by making use of JavaScript to stealthily subscribe to the service, and intercepting and sending the OTP code (if applicable) to complete the process.

    The JavaScript code, for its part, is designed to click on HTML elements that contain keywords such as “confirm,” “click,” and “continue” to programmatically initiate the subscription.

    Upon a successful fraudulent subscription, the malware either conceals the subscription notification messages or abuses its SMS permissions to delete incoming SMS messages containing information about the subscribed service from the mobile network operator.

    Toll fraud malware is also known to cloak its malicious behavior by means of dynamic code loading, a feature in Android that allows apps to pull additional modules from a remote server during runtime, making it ripe for abuse by malicious actors.

    From a security standpoint, this also means that a malware author can fashion an app such that the rogue functionality is only loaded when certain prerequisites are met, effectively defeating static code analysis checks.

    “If an app allows dynamic code loading and the dynamically loaded code is extracting text messages, it will be classified as a backdoor malware,” Google lays out in developer documentation about potentially harmful applications (PHAs).

    With an install rate of 0.022%, toll fraud apps accounted for 34.8% of all PHAs installed from the Android app marketplace in the first quarter 2022, ranking below spyware. Most of the installations originated from India, Russia, Mexico, Indonesia, and Turkey.

    To mitigate the threat of toll fraud malware, it’s recommended that users install applications only from the Google Play Store or other trusted sources, avoid granting excessive permissions to apps, and consider upgrading to a new device should it stop receiving software updates

  • Google Improves Its Password Manager to Boost Security Across All Platforms

    Google Improves Its Password Manager to Boost Security Across All Platforms

    Google on Thursday announced a slew of improvements to its password manager service aimed at creating a more consistent look and feel across different platforms.

    Central to the changes is a “simplified and unified management experience that’s the same in Chrome and Android settings,” Ali Sarraf, Google Chrome product manager, said in a blog post.

    The updates are also expected to automatically group multiple passwords for the same sites as well as introduce an option to manually add passwords. Although Google appears to be not ready yet to make Password Manager as a standalone app, users on Android can now add a shortcut to it on the homescreen.

    CyberSecurity

    In a related change on iOS, should users opt for Chrome as the default autofill provider, Password Manager comes with the ability to generate unique, strong passwords.

    The built-in Password Checkup feature on Android is receiving an upgrade of its own too. Beyond checking for hacked credentials, it can further highlight weak and reused passwords à la Apple iOS. Google is also expanding the compromised password warnings to Chrome users across all operating systems.

    Last but not least, Google is bringing a new “Touch-to-Login” to Chrome on Android that allows users to sign in to websites with a single tap after entering the credentials with autofill. It’s worth noting that Apple implemented a similar feature in Safari with iOS 12.2.

  • Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers

    Microsoft Warns of Cryptomining Malware Campaign Targeting Linux Servers

    Cryptomining Malware Hacking Linux

    A cloud threat actor group tracked as 8220 has updated its malware toolset to breach Linux servers with the goal of installing crypto miners as part of a long-running campaign.

    “The updates include the deployment of new versions of a crypto miner and an IRC bot,” Microsoft Security Intelligence said in a series of tweets on Thursday. “The group has actively updated its techniques and payloads over the last year.”

    8220, active since early 2017, is a Chinese-speaking, Monero-mining threat actor so named for its preference to communicate with command-and-control (C2) servers over port 8220. It’s also the developer of a tool called whatMiner, which has been co-opted by the Rocke cybercrime group in their attacks.

    In July 2019, the Alibaba Cloud Security Team uncovered an extra shift in the adversary’s tactics, noting its use of rootkits to hide the mining program. Two years later, the gang resurfaced with Tsunami IRC botnet variants and a custom “PwnRig” miner.

    Now according to Microsoft, the most recent campaign striking i686 and x86_64 Linux systems has been observed weaponizing remote code execution exploits for the freshly disclosed Atlassian Confluence Server (CVE-2022-26134) and Oracle WebLogic (CVE-2019-2725) for initial access.

    This step is succeeded by the retrieval of a malware loader from a remote server that’s designed to drop the PwnRig miner and an IRC bot, but not before taking steps to evade detection by erasing log files and disabling cloud monitoring and security software.

    Besides achieving persistence by means of a cron job, the “loader uses the IP port scanner tool ‘masscan’ to find other SSH servers in the network, and then uses the GoLang-based SSH brute force tool ‘spirit’ to propagate,” Microsoft said.

    CyberSecurity

    The findings come as Akamai revealed that the Atlassian Confluence flaw is witnessing a steady 20,000 exploitation attempts per day that are launched from about 6,000 IPs, down from a peak of 100,000 in the immediate aftermath of the bug disclosure on June 2, 2022. 67% of the attacks are said to have originated from the U.S.

    “In the lead, commerce accounts for 38% of the attack activity, followed by high tech and financial services, respectively,” Akamai’s Chen Doytshman said this week. “These top three verticals make up more than 75% of the activity.”

    The attacks range from vulnerability probes to determine if the target system is susceptible to injection of malware such as web shells and crypto miners, the cloud security company noted.

    “What is particularly concerning is how much of a shift upward this attack type has garnered over the last several weeks,” Doytshman added. “As we have seen with similar vulnerabilities, this CVE-2022-26134 will likely continue to be exploited for at least the next couple of years.”

  • Amazon Quietly Patches ‘High Severity’ Vulnerability in Android Photos App

    Amazon Quietly Patches ‘High Severity’ Vulnerability in Android Photos App

    Amazon

    Amazon, in December 2021, patched a high severity vulnerability affecting its Photos app for Android that could have been exploited to steal a user’s access tokens.

    “The Amazon access token is used to authenticate the user across multiple Amazon APIs, some of which contain personal data such as full name, email, and address,” Checkmarx researchers João Morais and Pedro Umbelino said. “Others, like the Amazon Drive API, allow an attacker full access to the user’s files.”

    The Israeli application security testing company reported the issue to Amazon on November 7, 2021, following which the tech giant rolled out a fix on December 18, 2021.

    The leak is the result of a misconfiguration in one of the app’s components named “com.amazon.gallery.thor.app.activity.ThorViewActivity” that’s defined in the AndroidManifest.xml file and which, when launched, initiates an HTTP request with a header containing the access token.

    Amazon Photo App vulnerability

    In a nutshell, it means that an external app could send an intent — a message to facilitate communication between apps — to launch the vulnerable activity in question and redirect the HTTP request to an attacker-controlled server and extract the access token.

    Calling the bug a case of broken authentication, the cybersecurity company said the issue could have enabled malicious apps installed on the device to grab the access tokens, granting the attacker permissions to make use of the APIs for follow-on activities.

    This could vary from deleting files and folders in Amazon Drive to even exploiting the access to stage a ransomware attack by reading, encrypting, and re-writing a victim’s files while erasing their history.

    Checkmarx further noted that the vulnerability might have had a broader impact given that the APIs exploited as part of its proof-of-concept (PoC) constitute only a small subset of the entire Amazon ecosystem.

  • New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the Wild

    New ‘SessionManager’ Backdoor Targeting Microsoft IIS Servers in the Wild

    Microsoft IIS Servers

    A newly discovered malware has been put to use in the wild at least since March 2021 to backdoor Microsoft Exchange servers belonging to a wide range of entities worldwide, with infections lingering in 20 organizations as of June 2022.

    Dubbed SessionManager, the malicious tool masquerades as a module for Internet Information Services (IIS), a web server software for Windows systems, after exploiting one of the ProxyLogon flaws within Exchange servers.

    Targets included 24 distinct NGOs, government, military, and industrial organizations spanning Africa, South America, Asia, Europe, Russia and the Middle East. A total of 34 servers have been compromised by a SessionManager variant to date.

    This is far from the first time the technique has been observed in real-world attacks. The use of a rogue IIS module as a means to distribute stealthy implants mirrors the tactics of a credential stealer called Owowa that came to light in December 2021.

    “Dropping an IIS module as a backdoor enables threat actors to maintain persistent, update-resistant and relatively stealthy access to the IT infrastructure of a targeted organization; be it to collect emails, update further malicious access, or clandestinely manage compromised servers that can be leveraged as malicious infrastructure,” Kaspersky researcher Pierre Delcher said.

    The Russian cybersecurity firm attributed the intrusions with medium-to-high confidence to an adversary tracked as Gelsemium, citing overlaps in the malware samples linked to the two groups and victims targeted.

    ProxyLogon, since its disclosure in March 2021, has attracted the repeated attention of several threat actors, and the latest attack chain is no exception, with the Gelsemium crew exploiting the flaws to drop SessionManager, a backdoor coded in C++ and is engineered to process HTTP requests sent to the server.

    “Such malicious modules usually expect seemingly legitimate but specifically crafted HTTP requests from their operators, trigger actions based on the operators’ hidden instructions if any, then transparently pass the request to the server for it to be processed just like any other request,” Delcher explained.

    Said to be a “lightweight persistent initial access backdoor,” SessionManager comes with capabilities to read, write, and delete arbitrary files; execute binaries from the server; and establish communications with other endpoints in the network.

    The malware further acts as a covert channel to conduct reconnaissance, gather in-memory passwords, and deliver additional tools such as Mimikatz as well as a memory dump utility from Avast.

    The findings come as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged government agencies and private sector entities using the Exchange platform to switch from the legacy Basic Authentication method to Modern Authentication alternatives prior to its deprecation on October 1, 2022.

  • Solving the indirect vulnerability enigma – fixing indirect vulnerabilities without breaking your dependency tree

    Solving the indirect vulnerability enigma – fixing indirect vulnerabilities without breaking your dependency tree

    vulnerabilities

    Fixing indirect vulnerabilities is one of those complex, tedious and, quite frankly, boring tasks that no one really wants to touch. No one except for Debricked, it seems. Sure, there are lots of ways to do it manually, but can it be done automatically with minimal risk of breaking changes? The Debricked team decided to find out.

    A forest full of fragile trees

    So, where do you even start?

    Firstly, there needs to be a way to fix the vulnerability, which, for indirect dependencies, is no walk in the park. Secondly, it needs to be done in a safe way, or, without anything breaking.

    You see, indirect dependencies are introduced deep down the dependency tree and it’s very tricky to get to the exact version you want. As Debricked’s Head of R&D once put it, “You are turning the knobs by playing around with your direct dependencies and praying to Torvalds that the correct indirect packages are resolved. When Torvalds is in your favour, you have to sacrifice some cloud storage to uncle Bob to make sure the updates don’t break your application.”

    In other words, there really should be an easier, less stressful, way to do it.

    In this article, we’ll walk you through how solving transitive vulnerabilities can be done manually and, towards the end, show you the Debricked solution, which allows you to do it automatically. If you’re really just interested in the solution, I suggest you start scrolling.

    Precision surgery on your dependency tree

    During the research phase of the graph-database project, or, how Debricked today fixes your open source vulnerabilities at the speed of light, the team stumbled upon some articles explaining how to fix indirect vulnerabilities in NPM.

    As stated in the article, the `minimist` package is affected by vulnerabilities, namely CVE-2021-44906 and CVE-2020-7598.

    These are both “Prototype Pollution” vulnerabilities, meaning that arguments are not properly sanitized. Luckily, the maintainers of `minimist` fixed these vulnerabilities in version 1.2.6.

    Unfortunately, `mocha` version 7.1.0 resolves `minimist` 0.0.8, which is within the vulnerable range of these vulnerabilities. As suggested by the author of this article, these vulnerabilities can be fixed in a few different ways.

    But! What about breaking changes?

    The first suggestion is to simply trigger an update of all “indirect dependencies”, meaning that we won’t actually change the version of `mocha`. To perform this update, simply run `npm update`, delete your `npm.lock` file, and run `npm install`. This regenerates the dependency tree with the latest possible version (according to constraints) of your indirect dependencies. With this method, the risk of breaking changes is very low as you actually don’t update any of your root dependencies, just your indirect ones.

    Breaking changes occur when the package functionality or interface is not forward compatible, meaning that an update to the package could cause your application to break. Common breaking changes are class/function-removal, change of arguments to a function, or licence-change (watch out for that one!).

    But life is not always this easy, and this simple update of the tree will not solve the vulnerability. The problem is that `mkdirp` has actually locked their version of `minimist` to 0.0.8. This means that the contributors of `mkdirp` have come to the conclusion that they are not compatible with newer versions of `minimist`, and forcing the update of `minimist` may introduce breaking changes between `mkdirp` and `minimist`.

    Think… graphs!

    So, the million-dollar question is: what version of `mocha` should be used, that in turn trickles down to a safe version of `minimist` without breaking the dependency tree? This is actually a graph problem, which has been described in this article.

    What graph algorithm would solve this problem? How NPM resolves dependencies can be a bit complicated, as they are allowed to “split” the dependency tree. This means that they can have multiple versions of one dependency to make sure that we always have a tree that is compatible. To solve the vulnerability, we need to make sure that all instances of `minimist` are safe by updating all roots that can trickle down to `minimist`.

    The algorithm used to solve this problem is called “All Max Paths Safe”. By walking down the dependency graph and keeping the max versions, all while pruning all other versions of that package in each intersection, we can create an approximate representation of our dependency tree. If the approximation is safe, that means that our real tree will be safe as well!

    By performing this algorithm for all potential versions of `mocha`, we find the smallest upgrade to fix this vulnerability. To get the speed we wanted for this algorithm, the team had to build a custom Neo4j procedure, which can handle searching over 100 root versions with a search depth of 30+ in ~150 milliseconds. Speedy, huh?

    In this case, we don’t have to search very far… as 7.1.1 of `mocha` is safe! This is only a patch update, which indicates that the risk of breaking changes is very low. For less complex cases (like this example), ‘npm audit’ can help you with their fantastic ‘npm audit fix’ command.

    Don’t be ad-hoc, enter the pub-sub-human way of working!

    Now, if you got this far (congratulations, very impressive) and thought, “this sounds really complex and like an awful lot of work,” don’t worry – you’re not the only one. Luckily, all this happens completely automatically in the Debricked tool when clicking this little button:

    As of right now, this is available for Javascript. Soon, the support will be extended to Java, Golang, C#, Python and PHP.

    If you’re not yet a Debricked user, what are you waiting for? It’s free for single devs, smaller teams and open source projects (and if you’re a larger organization, fear not. There’s a generous free trial). Sign up for free here.

  • North Korean Hackers Suspected to be Behind $100M Horizon Bridge Hack

    North Korean Hackers Suspected to be Behind $100M Horizon Bridge Hack

    North Korean

    The notorious North Korea-backed hacking collective Lazarus Group is suspected to be behind the recent $100 million altcoin theft from Harmony Horizon Bridge, citing similarities to the Ronin bridge attack in March 2022.

    The finding comes as Harmony confirmed that its Horizon Bridge, a platform that allows users to move cryptocurrency across different blockchains, had been breached last week.

    The incident involved the exploiter carrying out multiple transactions on June 23 that extracted tokens stored in the bridge and subsequently made away with about $100 million in cryptocurrency.

    “The stolen crypto assets included Ether (ETH), Tether (USDT), Wrapped Bitcoin (WBTC) and BNB,” blockchain analytics company Elliptic said in a new report. “The thief immediately used Uniswap – a decentralized exchange (DEX) – to convert much of these assets into a total of 85,837 ETH.”

    Days later, on June 27, the culprit is said to have begun moving funds amounting to $39 million through the Tornado Cash mixer service in an attempt to obfuscate the ill-gotten gains and make it difficult to trace the transaction trail back to the original theft.

    Elliptic, which was able to “demix” the transactions, said it was in a position to further track the stolen funds funneled through the service to a number of new Ethereum wallets.

    The company’s attribution to the Lazarus Group stems from the threat actor’s history of carrying out cryptocurrency thefts, including those targeting cross-chain bridges earlier this year, and the manner in which the funds were stolen and subsequently laundered.

    “The theft was perpetrated by compromising the cryptographic keys of a multi-signature wallet – likely through a social engineering attack on Harmony team members,” it said. “Such techniques have frequently been used by the Lazarus Group.”

    North Korean

    “The relatively short periods during which the stolen funds stop being moved out of Tornado cash are consistent with [Asia-Pacific] nighttime hours,” Elliptic added. “Although no single factor proves the involvement of Lazarus, in combination they suggest the group’s involvement.”

    Harmony has since notified all cryptocurrency exchanges and involved law enforcement and blockchain forensic firms to help in the recovery of stolen assets. It’s also offering “one final opportunity” for the cyber thieves to send the funds back with anonymity and “retain $10 million and return the remaining amount” by July 4, 2022, 11 p.m. GMT.

    On top of that, it has promised a $10 million reward for any information that leads to the return of plundered virtual currencies.

    The Horizon Bridge digital heist also arrives against the backdrop of a “crypto winter” that has witnessed a steep decline in cryptocurrency markets, sending prices of Bitcoin down below $20,000 and potentially risking a key source of income for the sanctions-hit North Korea.

    In a related development, Sky Mavis, developers of the popular non-fungible token (NFT) video game Axie Infinity, announced this week the official restart of the Ronin Bridge following three different audits.

    What’s more, the European Parliament and Council reached a landmark agreement on Wednesday to force crypto platforms to provide identifying information on the originators and the beneficiaries in a bid to enforce transparency of crypto-asset transfers.

    “This is what payment service providers currently do for wire transfers,” the Council said in a press statement. “This will ensure traceability of crypto asset transfers in order to be able to better identify possible suspicious transactions and block them.”

  • Ex-Canadian Government Employee Pleads Guilty Over NetWalker Ransomware Attacks

    Ex-Canadian Government Employee Pleads Guilty Over NetWalker Ransomware Attacks

    NetWalker Ransomware Attacks

    A former Canadian government employee this week agreed to plead guilty in the U.S. to charges related to his involvement with the NetWalker ransomware syndicate.

    Sebastien Vachon-Desjardins, who was extradited to the U.S. on March 10, 2022, is accused of conspiracy to commit computer fraud and wire fraud, intentional damage to a protected computer, and transmitting a demand in relation to damaging a protected computer.

    The 34-year-old IT consultant from Gatineau, Quebec, was initially apprehended in January 2021 following a coordinated law enforcement operation to dismantle the dark web infrastructure used by the NetWalker ransomware cybercrime group to publish data siphoned from its victims. The takedown also brought its activities to a standstill.

    A search warrant executed at Vachon-Desjardins’s home in Canada resulted in the seizure of 719 bitcoin, valued at approximately $28.1 million at the time, and $790,000 in Canadian currency.

    In February 2022, the Ontario Court of Justice sentenced him to six years and eight months in prison after he pleaded guilty to five criminal charges prior to his extradition to the U.S.

    Stating that the defendant “excelled at what he did,” the court said that the individual “even improved upon the ransom messages used by NetWalker affiliates and eventually convinced the creator of NetWalker to use ‘mixing services’ to disguise funds paid for ransoms in Bitcoin.” The ruling also called him “good-looking, presentable, and instantly likeable.”

    Attacks mounted by the NetWalker gang are believed to have targeted dozens of victims all over the world, specifically singling out the healthcare sector during the COVID-19 pandemic in an attempt to capitalize on the global crisis opportunistically.

    It’s known to adopt the lucrative tactic of double extortion to steal sensitive personal information prior to encrypting it and hold that data hostage in return for a cryptocurrency payment or risk getting the information published online.

    Vachon-Desjardins, in his capacity as one of the 100 affiliates for the NetWalker gang, is suspected to be linked to at least 91 attacks since April 2020, in addition to working for other RaaS groups like Sodinokibi (REvil), Suncrypt, and Ragnarlocker.

    According to court documents filed in a district court in Florida, the NetWalker crew amassed 5,058 bitcoin in illegal payments (about $40 million at the time of the transaction), with Vachon-Desjardins named as “one of the most prolific NetWalker ransomware affiliates” and responsible for the extortion of about 1,864 bitcoin.

    His role in the criminal scheme allegedly ranged from researching on victims and controlling the servers hosting tools for reconnaissance, privilege escalation, and data theft to operating accounts that posted the stolen data on the data leak site and receiving payouts after a successful attack.

    The defendant, as part of the plea deal, has now agreed to forfeit all the digital assets held in his crypto wallet as well as dozens of equipment that consist of laptops, tablets, phones, gaming consoles, and external hard drives, among others.