Author: Clear Infosec

  • Primer on Microsoft Sentinel

    Primer on Microsoft Sentinel

    Microsoft Sentinel

    Microsoft Sentinel is a SIEM (Security Information and Event Management) and SOAR (Security Orchestration and Automated Response) system in the Microsoft cloud platform.

    Before delving further into Sentinel, let’s see some brief descriptions of SIEM and SOAR.

    Security Information and Event Management (SEIM)

    • SEIM collects data and query logs across the system.
    • It will provide some data correlation and anomaly detection.
    • With the help of SIEM, we can create alerts and incidents based on our findings.

    Security Orchestration and Automated Response (SOAR)

    • It will respond automatically to incidents.
    • SOAR can create automated workflows from the alert triggered.
    • With the help of SOAR, tasks can be orchestrated across the system.

    Sentinel is a powerful Microsoft defender tool that collects, analyzes, and normalizes data across on-premises and cloud workloads whether or not they are native to Microsoft. It can be connected to users’ devices such as laptops or phones, applications, infrastructures, and even IoT devices.

    As mentioned, Sentinel collects and normalizes data from different signals and investigates potential threats using Artificial Intelligence (AI) and Machine Learning (ML) in the environment.

    Sentinel provides intelligent security analytics and threat intelligence across the organization environment. It utilizes the Azure logic apps and Log Analytics present in the Azure to establish automated workflows that come into play once an alert is triggered.  It also has built-in ML that can be used to detect and investigate threats or suspicious behaviors in the enterprise ecosystem.

    Microsoft Sentinel can be deployed in the Azure Tenant organization and accessed easily through the Azure Portal. It will ensure all the preexisting organizational policies. Sentinel provides a single solution for alert detection, threat visibility, proactive hunting, and threat response.

    Sentinel can also incorporate data from another cloud platform like AWS or any other third-party software installed on the premises already.

    How to connect data to Microsoft Sentinel

    Most network and security systems support Syslog or CEF (common event format), both of these are means for the system to send data to SIEM. And many of the resources available in Azure can directly connect to the log workspace, which is how Azure sentinel collects the data.

    The feature Azure monitor will directly stream all these data into the sentinel. And Log analytics is another way to collect telemetry from servers or workstations. Microsoft Sentinel also imports threat indicators utilizing data connectors.

    In the portal, you can search and select Microsoft Sentinel. On the configuration page, you can select data connectors. This will show the number of connectors available to connect to the sentinel. The below figures will show that there are 124 connectors available for me to connect.

    Then choose from which connector you need and select connect. For the connectors of Microsoft native, the steps will be very simple; for other third parties, some additional details may be required.

    Here we are coming to the end of this blog, which gives a brief introduction and ways to connect data to Sentinel. The upcoming blogs will give more information about incident creation, threat hunting, and others. To learn the latest trends and happenings in cybersecurity, you can look into clearinfosec.

  • Phishing

    Phishing

    Phishing is a social engineering attack mostly used by cybercriminals to attack clients for their confidential information. In general, the common details that are commonly asked by cybercriminals are

    • Date of birth of the clients or users
    • Social security numbers
    • Phone numbers
    • Credit card information
    • Home address
    • Password details

    The attacks may be concentrated on a specific user or the organization itself. Depending on that, the attacker will enquire about different information from the victim.

    In phishing attacks, the criminals will disguise themselves as a trusted or genuine entity to cheat the victims open an email. By not observing carefully and trusting the attacker, the beneficiary was then tricked into providing confidential details or opening a suspicious weblink. This will help the attacker to create a starting point for his further attack. The weblink may install malware or attack servers, or collect data from the database and upload it to the attacker system.

    These kinds of data thefts will be used to steal money or unapproved purchase of resources and more. With the organization’s confidential information, the attackers may understand the security protocols and prepare to bypass or break the security for more dangerous attacks. Or gain access to more privileged information, which may destroy the foundation of the organization itself.

    If an organization undergoes such an attack, the financial losses will be very severe. The loss of assets, reputation may reduce the company’s market share and may go bankrupt.

    Depending on the scale of the phishing attack, it may target an individual for money or a severe security incident on a business organization. So it is recommended to take phishing mails as serious attacks and report them to the cybersecurity team.

    Phishing attack starts when the user receives phishing mail but only when the user responds to that subjective mail does the true attacks start. Some of the general actions required in phishing emails are opening an attachment, Providing the details in a form, clicking on the links, sending money to a charity organization (not the real one), and more.

    Some of the examples of email phishing are given below.

    1) Financial attacks

    Usually, these emails look like they come from someone the user knows, like a supervisor or chief or team leader like that and ask the user to urgently send some funds, transfer money or provide bank details for their salary account.

    If you receive mail like that, always be cautious and confirm with the corresponding person with the contact details available from sources other than the one specified in that mail.

     

    2) Job scams

    The mail may contain some details like you are selected for a specified position in a reputed company, but you have to send a demand draft of certain money for the application process. As soon as the DD is obtained, we will send you the appointment order.

    They may also send a form and ask for your complete details for a job application.

    It is always recommended to confirm the job you applied for, the company name, and the company logo before responding to emails like these.

     

    3) Social network profile details

    The attacker may send a mail like a genuine person from any social network site and ask for your details.

    The mail may inform you there may be some discrepancies in your login or a login attempt in another system. And ask you to confirm by giving your profile details.

     

    4) Fake invoice

    The criminal may send a fake invoice showing you have paid a certain amount for buying their services. For example, you have paid 100$ to avail iTunes service. At the end of the mail, they will specify if we didn’t buy that service; click the link and provide details for the refund.

    This kind of mail is sent to ignite greed or make the user think they will get extra money for free. Then the user will give their details to get a refund without knowing they provided confidential details to the hacker who is taking all the money from your bank account with their details.

    There may also be mail like Remainder: Invoice or Important: Invoice and asks you to download the attachment. Be cautious of this kind of mail and report to the cybersecurity in your organization.

     

    5) Charity organization

    The hacker will pretend like they are having an orphanage or other charity organization and request money. They may provide a believable story like a kid who needs lots of money for an operation, making the user feel pity and donate the money.

    If you receive any such emails, kindly confirm the organization’s authentication or the story provided, then donate the money.

     

    6) Account suspension

    We may receive mail describing that our account has been suspended due to some illicit activities or log in from different places like that. And ask as to provide our details in a link they would have sent along with the mail. This kind of mail may come from the bank or social media accounts.

    Believing this mail and without checking if we proceed with sending our details, the hacker may very easily claim our account ownership.

     

    7) Survey

    The email will have surveys to collect information from the user. These surveys can appear as display ads on websites and in the news feed, and more. The most important thing to note is that no legitimate organization will survey by asking about your credentials.

     

    8) CEO fraud/ Higher official scam

    You may receive a simple mail from someone like a higher authority in your organization. For example, someone under your organization’s higher official name will ask you to mail your mobile number to discuss urgent needs like that.

     

    9) Romance scam

    The hacker may have got the email from any dating web and started sending mail. After a while, the hacker may ask for money from the user or ask serious questions about the user. These questions are asked to understand the security questions the user may have given for password retrieval and more. If not careful, the romance scams broke not only the bank vault but also the heart.

     

    10) Lottery

    The mail we receive may contain details such as our mail id may be won a lottery among many thousands of mail id. They will ask for our details to send the prize amount and our details for the same.

    It may come as attachments or links or in many forms. The ultimate goal of the scam is to get the details of the user.

    Some simple ways to identify phishing mail:

    Email header analysis

    Having some knowledge about the email header may help to avoid phishing attacks. Can check this blog for more about email header analysis.

    Checking logo

    The genuine company logos have distinct marks, which cannot be completely duplicated or won’t be duplicated. If the user receives any mail from an organization, it is recommended to check the organization’s logo is correct.

    Checking spellings

    The mail received from the legitimate company will have proper grammar and no typo errors. In most of the scam mail, there might be many spelling mistakes.

    Checking the hyperlinks

    If the mail contains a hyperlink, it is better to hover the mouse pointer above it to see the link’s address. If the specified address in the mail and the link’s address are not the same, there might be a problem with the account.

    Virtual machine

    If the mail is received from an unknown sender or you have some doubts about the sender, it is better to use a virtual machine to download attachments. And use the tools available to examine whether the attachment contains any suspicious file. For more details, check this blog https://clearinfosec.com/pdf-malware-ioc-extraction-2/

    Awareness

    • It is better to understand that no legitimate company will ask for your confidential details.
    • Even if the mail id may seem genuine, it may be phishing mail.
    • Be aware of mail that contains important, awareness, warning like that and ask for confidential information.
    • If the mail seems suspicious, it is better to complain to the cybersecurity team immediately.

    It is recommended that the cybersecurity team in the organization create awareness about phishing mail by conducting webinars or meetings or blogs etc.

     

  • Policy Management Lifecycle – what, why, and how

    Policy Management Lifecycle – what, why, and how

    Reports say that addressing uncertainties is the condition that most organizations aren’t prepared for. But with a Governance, Risk, and Compliance program, it is easier to predict and address uncertainties and act with integrity. The GRC program is created to predict the risks, get prepared for them and protect yourselves from litigation. Over time, organizations will be able to achieve their objectives efficiently.

    An Efficient and effective GRC program should be built from a comprehensive policy management system. Making a set of policies and just announcing their existence isn’t a Policy management system. The rapidly changing regulatory standards of today can be met only with properly aligned policies that keep everything in line. It should be able to adjust and adapt to the needs of the organization.

    Regardless of whether a company is just a start-up or a well-established enterprise, the need of understanding and maintain an effective policy lifecycle management is important. In this context, let us look into what a policy really is and its lifecycle.

    What are Policies

    Policies establish limits for how people, systems, and business connections should behave. The Code of Conduct, which outlines principles and values that apply to the entire organization, serves as the foundation for all other policies. Policies include behaviour expectations so that people are aware of what is expected of them and not. Policies should define the corporate culture and boundaries of individual and business behaviour and personal conduct.

    Why are policies important       

    It is through the policies we define, communicate, and articulate the boundaries, practices, and expectations of an organization. An organization cannot have a strong and established culture without the presence of a good policy in place. With policies managed correctly, exceptions to the policies can be governed efficiently and violations can be recognized and responded to it right on time.

    Without the presence of strong policies, organizations quickly become something they never intended. But with good policies governing the culture and objectives, the corporate culture never goes on unintended paths.

    According to The GRC Pundit, “Policies, done right, articulate and build the desired corporate culture and drive standards for individual and business conduct”.

    Phases of policy management lifecycle

    An effective policy management system follows a lifecycle for the policies. This helps in separating the ineffective policies, out of date, and not aligned with the business needs. The lifecycle is defined under the below phases:

    Creation:

    Policies are created for a variety of reasons, to meet compliance, fulfill business partner obligations, ensure best practices, instill corporate values, etc. so the first step involved in creating a policy would be Defining the need. Once the need is defined, organizations can Decide on the ownership of the policies to be created.  The people with roles assigned as owners should take the responsibility of implementing the policies and monitoring them. Then comes the Policy Writing stage. The policy should be defined more clearly, easy to understand, and ideally consistent in the format, and language. Once written, the policy should undergo an Approval stage. This should be done by the persons with the respective roles assigned before going into circulation.

    Communication:

    According to GRC pundit, this phase should contain 3 sub-phases including Publication, Training, and attestation. Organizations should publish the policies with at least a single authoritative source. Without the right authoritative source, the policy would become difficult to manage in the long run, and the chances of more policies becoming out-of-date. A policy management software in place can efficiently avoid this problem. It allows the right persons with the right roles can login and manage all the existing policies. Training is crucial because companies need to be able to prove that employees are aware of policies and what is expected of them. Once the individuals have read the policy and taken the associated training, the next is to track the attestation of the policy, and that they will adhere to it.

    Management:

    This phase includes the monitoring of policies in the ongoing processes. Every instance of non-compliance and policy violation should be recorded, and it should be considered when the policy review comes up. Although policies must be followed, there are several situations where the organization tolerates non-compliance. These exceptions are also supposed to be documented and managed.

    Maintenance:

    This is the final phase. The policies should be reviewed at regular intervals. If it is still found effective at the time of review, the policy is approved again for the individuals to follow and if found inefficient, that policy should be marked retired or moved to the archive so that it is still available for reference in the future.

    How a policy management application can be effective, efficient, and agile

    an ineffective approach to defining policy management can leave a business open to risks and vulnerable to liability. How do you know whether what you are doing is right or wrong? The solution is Clear Infosec’s ClearGRC.

    It is a complete IT GRC tool with tools and modules that helps you to Govern your organization, manage assets, Risks, and compliance, assess yourself for a wide range of compliances and third-party risks, and much more. It enables you to control your organization’s Policies and Procedures lifecycle and thus ensures effective governance and full compliance. That means, yes, less risk.

    Reach out to know more about ClearGRC and schedule a demo.

  • AstraLocker 2.0 – Smash and Grab attacks

    AstraLocker 2.0 – Smash and Grab attacks

    In 2021, Security researchers from ReversingLabs tracked a relatively unknown malware which was later named AstraLocker. The latest version of AstraLocker, meanwhile, was first observed in March 2022. Rather than the “Low and Slow” methodology that is common among sophisticated ransomware groups, this virus is so unique that it acts immediately after it a user opens the malicious file.

    Version 2.0 was directly distributed from Microsoft office files used as bait in phishing attacks. The underlying code for AstraLocker 2.0 is likely to be obtained from a leak of Babuk Ransomware in 2021. Shared code and marketing markings are the ties between the two campaigns, and a Monero wallet address offered for ransom payment is connected to the Chaos Ransomware gang.

    The affected files will have a “.AstraLocker” extension with its file name. for example, a word document with the title “sample.docx” will become “sample.docx.AstraLocker”. In every folder containing the encoded files, a Recover_Your_Files.html text file will be found. It is a ransom money memo. You can learn there how to get in touch with the racketeers as well as other information. Instructions on how to buy the decryption tool from the hackers are possibly included in the ransom note.

    The below image shows how encrypted “.AstraLocker” files look.


    Source: How to fix guide

    For the AstraLocker virus to get into your system, there are 3 detected popular ways. They are spam emails, Trojan Injection, and Peer networks.

    Emails from unknown senders may sometime escape your spam box and no matter how legitimate it seems, opening any documents from unverified senders are never recommended. Other than emails, bad actors might use Trojan horses to infiltrate your machine by disguising it as something legal. As for the peer networks like torrent trackers, you never know what you are downloading unless you finish the download. So, when using such services, always use trustworthy resources. Additionally, as soon as the downloading is complete, it makes sense to run an antivirus scan on the folder holding the downloaded goods.

    Steps to Remove AstraLocker virus

    It is always better to stay proactive than to be reactive.

    One of the best choices is to have OS restore points or keep the copies of important/sensitive files in the cloud or external storage. Even that might not work as expected as you might still lose the last file you were working on at the time of the attack. It is always recommended to keep an antivirus program in your system and to run the test regularly and mandatorily whenever you perform an OS rollback.

    Also, thoroughly go through readme-files in the encrypted files because there are cases reported with attackers accidentally sharing the decrypting key in them. But this is only a rare chance that you should never expect to happen.

    Important to note: Along with encrypting your files, the AstraLocker virus will probably install the Azorult Spyware on your computer to steal your login information for other accounts. That application can obtain your login information via the auto-fill information in your browser.

    Myth buster:  AstraLocker 2.0 ransomware has no endless power, and neither does any similar malware.

    Announcement: A free decryptor released for AstraLocker and Yashma ransomware

  • Roaming Mantis targets Android and iOS

    Roaming Mantis targets Android and iOS

    Roaming Mantis malware that targets Android and iOS devices is detected in France after hitting Germany, Taiwan, South Korea, Japan, the US, and the UK. This malware did compromise tens of thousands of devices and is believed to be a financially motivated threat actor, which was first reported in February 2022 targeting European users.

    MoqHao (aka Wroba, XLoader for Android) is an Android Remote Access Trojan (RAT) with information-stealing and backdoor capabilities that spread via SMS. It is attributed to Roaming Mantis, which is thought to be a Chinese threat organization with financial motivations.

    How the Malware works

    The threat actor uses SMS to lure users into making them download the malware onto their devices. This smishing campaign was first observed by Sekoia.io analysis through malicious SMS received.

    The SMS says that “Your package has been sent. Please check it and receive” and contains a link. If any user clicks on that link, the users are redirected to a phishing page designed according to the device they have and the location they are at. Now, the Roaming Mantis is detected in France and the messages received are in French.

    iPhone users receive an SMS with a link to a phishing site that can steal Apple credentials. But for Android users, the SMS pushes them to install a mobile app – an Android Package Kit (APK). But for any user outside France, the URL redirects to a 404 error.

    The infrastructure of the threat

    Analysts of this threat report that the infrastructure of Roaming Mantis has not changed much when compared to the last analysis done in April.

    As the threat is targeting both iOS and Android devices, there are two different infection chains detected.

    1. Android Payload

    The servers have the ports like TCP/443, TCP/5985, TCP/10081, and TCP/47001 open. These servers are set to target only one country and traffic from any other country is set to display a 404 error.

    1. Apple Phishing

    The servers have TCP/80, TCP/5432, TCP/5985, and TCP/47001 open. The landing page is designed in a way that replicates the Apple ID login page. Same as the Android infrastructure, this is also geofencing and any traffic from other countries results in a 404 error.

    Domains

    The domains used inside the Smishing SMS are found to be registered in either “GoDaddy” or dynamic DNS servers like “duckdns.org”. The intrusion set uses more than a hundred subdomains, and each IP address is resolved by dozens of FQDNs.

    Do not fall victim to Mantis

    To prevent Roaming Mantis and other Android malware from infecting your device, you should never allow the installation of apps from untrusted sources, and you should never download APKs from strange sites.

    Furthermore, SMS texts that contain URLs should always be treated with caution and suspicion, even if they come from someone you know. If you have even a slight doubt about the sender of the SMS, instead of opening the URL in it, try visiting the vendor that it disguises as directly.

    Finally, given that analysts actively monitor these activities, an Android internet security solution from a reliable vendor could assist flag these URLs upon accessing them.

  • Recent Ransomware attacks 2022

    Recent Ransomware attacks 2022

    Ransomware attacks have become very high in recent days. The ongoing attacks cause losses to lots of organizations. Knowledge of Ransomware and its anatomy is very important to mitigate these attacks. Some simple Protection and Response plans available can be useful in understanding the basics of the mitigation process. Let’s see some of the attacks by Ransomware groups on famous industries.

    In January 2022, the ransomware attack on Bernalillo country in New Mexico can be considered the starting point of this year’s cyber-attack on a large scale. This attack causes many educational institutes and government institutes. The officials, however, said that they didn’t pay any ransom.

    The famous sports manufacturer Puma had a data breach on their employee information. Almost 6000 employees’ personal information has been stolen. But the officials announced the customer’s data were not damaged.

    Similarly, in Portuguese Media, Impresa was attacked by the Lapsus$ gang. This happened during the New year holidays blocking the organization’s websites and online services.

    A multinational defense contractor, Hensoldt, which provides sensor solutions for the defense and security software for many US dense organizations, was under a Ransomware attack. Authorities didn’t reveal the details of the attack, but the ransomware group Lorenz which claimed responsibility for the attack, said they received the ransom. Whether the ransom was paid or not can be a debate.

    The LockBit ransomware gang attacked Bridgestone organization, one of the largest manufacturers of tires, in Feb 2022. The organization tried its best to mitigate the attack, but still, the company was forced to halt its productions for nearly a week. The LockBit gang later threatened the company to pay the ransom before 15th march, or they would leak the stolen information. There was no official information on whether the organization paid ransom or not. Still, it is reported that the company was able to perform a comprehensive security check and reconnect to its network. 

    Near the end of February, one of the largest microchip makers in the USA, Nvidia, was attacked by the Lapsus$ gang, the same one that attacked Impresa. It was confirmed that the group had stolen the data of employees and proprietary company data. Because of this breach, the company went offline for two days. It was rumored that Nvidia tried to hack the attackers to retrieve the data. But Nvidia authorities announced that they are in the process of analyzing the data loss and have not commented on the hacking part.

    In March 2022, Okta, the identity and access management company, confirmed that there was an unsuccessful attempt on their data. Lapsus$ group announced in their Telegram group that they had breached the company’s security and accessed their data. It was later confirmed that Sitel, an Okta sub-processor that provides Okta with contract workers for our Customer Support organization, was breached, and nearly 300 customers were compromised.

    The same organization publicly announced that they had claimed an account in Microsoft and gained limited access. Microsoft announced they received an alert and started the mitigating process, and when the attacker announced in public, the company intervened and stopped the attacker. The company also assured “no customer code or data was involved in the observed activities.”


    Known ransomware attacks in April 2022 by country

    From the pie chart provided by Malwarebytes, it is clear that ransomware attacks are very high worldwide. These charts were only for April, which shows the alarming number of attacks.

    The new gang, Black Besta, came out of nowhere and conducted nearly eleven successful breaches of organizations. Experts in the field believed it might be some old gang re-established themselves in the new name. Some of the organizations attacked are American Dental Association and Deutsche Windtechnik.

    Austin Peay State University also confirmed it had been a victim of a Ransomware attack. The university asked the professors and students to immediately disconnect their systems from the university network. These actions were taken by posting the alert in their official tweet.

    It can be very clear that many attacks were happening worldwide in all industries. Even the top giants also become victims of these attacks. It shows that good knowledge and a well-equipped cybersecurity team are highly important. Moreover, due RaaS model, carrying out ransomware attacks becomes simplified. To know more about the latest trends in cybersecurity services and ransomware, you can check the clearinfosec site.

  • ToddyCat APT unveiled

    ToddyCat APT unveiled

    Multiple threats detected from December 2020 against high-profile entities in Europe and Asia are finally traced to be responsible by a new Advanced Persistent Threat (APT) actor. Not much information about this is not yet gathered but its noticeable signs are the use of 2 previously unknown tools named “Samurai Backdoor” and “Ninja Trojan”.

    Since its start in December 2020, this threat managed to compromise selected Exchange Servers in Taiwan and Vietnam with the use of an unknown exploit leading to the creation of the well-known China Chopper Web Shell, which in turn used to initiate a multi-stage infection chain. Numerous components including custom loaders were found to be used in the final execution stage of passive backdoor samurai. Only 3 organizations were targeted at first by the group behind ToddyCat APT. But the count raised with the group exploiting the ProxyLogon vulnerability to compromise multiple servers across Europe and Asia.

    It is suspected that the group started exploiting Exchange Servers in December 2020, but the information to confirm this is insufficient. The Samurai passive backdoor, a sophisticated backdoor that typically operates on ports 80 and 443, was used to hack Microsoft Exchange Servers, which were the only targets of the first wave of attacks.

    During the period of the second wave, researchers found a sudden surge in the attacks. It is at this time the backdoor exploited the ProxyLogon vulnerability.

     

    The attack surface in the third wave is noted the third wave increases the attack surface to include desktop systems, whereas the first two waves solely affected Microsoft Exchange Servers.

    Credits: Kaspersky

    Security researchers say that there is only a little information is available about this threat actor.

    As mentioned earlier in this blog, the APT leverages 2 passive backdoors in the Exchange server environment with malware called Samurai and Ninja and takes complete control of the victim’s hardware and network. The Samurai malware uses multiple modules that allow the attackers to take control of the remote systems and freely move inside the targeted network. In some cases, Samurai backdoor lays a path to launch another malicious program called Ninja.

    The affected governmental and military groups demonstrate that this group is focused on highly prominent targets and is likely employed to accomplish important objectives, most likely connected to geopolitical interests.

  • Ransomware As A Service

    Ransomware As A Service

    Ransomware as a service is a business model where the customers or the malicious party use the ransomware developed by the experienced hacker. They may pay a certain amount, or a certain percentage of the total ransom received using this tool or code. This may be an example of software as a service.

    And the best part of RaaS is the person who uses this service does not need to know anything about coding. In the past, any attacker needs to have a good amount of knowledge in coding to initiate the attacks. But with the model of Raas, the user is not required to know even the basics of coding and still can execute the attack.

    This increasing trend of Raas gives a huge disadvantage to cybersecurity experts. The number of ransom attacks has been on the increasing graph ever since the Raas model was started. Companies or organizations of all sizes are trying their best to increase their cybersecurity to reduce the victimization of Raas.

    Ransomware attacks are found to be always on the rise. According to the report jointly given by The Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the NSA, ransomware attacks in 2022 will only be on the rising side.

    The most dangerous thing about Raas is it’s very easy to find. It becomes like ordinary goods sold on a market. Some Raas kits even have 24/7 support; other offers, there are forums on this kind of service to provide user services. They follow the same kind of treatment as SaaS. This kind of Raas service is not much costly too. If they buy a kit for 40 to 50$, they can earn up to thousands of dollars if the attack is successful. The person who uses RaaS needs a few attacks to succeed in becoming a rich person.

    The way RaaS work

    • First, the skilled ransomware developer will create a new kind of ransomware that is unlikely to be discovered by the organization’s firewall or cybersecurity team. This itself will give a high chance of a successful attack.
    • The developed code is then advertised in the designated forum or in other ways. The code will be developed to be modified easily to meet the multi end-user infrastructures. The developers mostly use cloud concepts, so it will be easy for users to use. We can call the customer’s affiliates.
    • Next, the affiliates will spread the malware. It may be a targeted attack or send the malware on the internet and wait for the user to get phished. It should be noted that phishing attack may look simple but causes more damage.
    • If the attack were successful, the money would be distributed among the affiliates and developers, as discussed earlier. There are many methods for this distribution, which will be explained briefly on the following page. It should be noted that most of the ransom was asked in cryptocurrency nowadays. This is to make use of the advantage of blockchain technology.

    The model of RaaS

    Almost all the RaaS methods will come under this kind of model. This model is based on profit distribution profits between the developer and affiliates.

    • Monthly Subscription

    In this method, the users pay a monthly fee, like subscribing to a newspaper and earning some percentage of the successful ransom. The developer may use the money from the subscription to develop a code or consider it a pure profit if there are many subscribers.

    • Affiliate

    In this model, a certain number of profits will be given to the RaaS developer. Instead, a developer will provide efficient service and support till the attack is successful.

    • One-time access

    The customer will pay the amount upfront and buy the code in this model. What he does with that and the profits earned solely belong to the customer.

    • Profit sharing

    This model is similar to the affiliate model. The profits are divided between the developer and customer based on their predetermined conditions.

     By understanding how RaaS works and familiarizing yourself with their models, the cybersecurity team to develop their defense. As a cybersecurity expert, you need to be aware of attacks’ different methods and principles to develop a successful defense. It is best to understand more about ransomware, its anatomy, and prevention methods, even if you are not in cybersecurity. Knowing this knowledge may help you avoid becoming a victim of ransomware attacks.

  • Ransomware Blockchain

    Ransomware Blockchain

    This blog will see whether it is possible to use the blockchain concept to track ransomware attackers or prevent such attacks. I have explained Ransomware in my previous blogs, and you can look into it for more details.

    Everyone will be aware of cryptocurrency at this age. The arrival of cryptocurrency as a boon or curse is still a debate. Cryptocurrency uses blockchain technology for the transaction. With rising cryptocurrency trends and the advantage of blockchain technology, cybercriminals started to ask for cryptocurrencies as a ransom.

    Source: Chainalysis

    According to the data collected by chainalysis, more than 600 million USD are transacted as ransomware. They also mentioned that with continuous updates and the range of 2021 may increase further and might be higher than the year 2022.

    Blockchain is a decentralized and digital log of encrypted transactions in the form of blocks. Each transaction is verified by the majority of the participants of the system. The emergence of blockchain also caused a rapid increase in a ransomware attacks. It is mainly because the attackers can demand the ransom in cryptocurrency, and because of its technology, the anonymity of the attackers can be maintained.

    It becomes a game between security experts and attackers to use blockchain for good or harm.

    Blockchain logs are decentralized, so there won’t be a single copy of the confidential data. Also, according to blockchain technology, once the data is entered, it’s impossible to change it. Because of this, both the sender and receiver of the data can be sure that no data has been altered.

    Since the data is decentralized, the critical information ends up in many places. There may be different organizations may store data in the same decentralized storage. This also makes the attacker’s work difficult. If an attacker needs to take the data, they need to compromise multiple protocols in different places.

    Blockchain also uses the sequential hashing (SeqHash) technique; this helps secure the integrity of the data or blocks every 10 minutes. Each company will use its encryption for data too.

    But obviously, if there are any errors in decentralized architecture, the attackers can use them as entry points. If there is one thing that can be sure about security is there is not 100% safe. Cybercriminals will find a way to extract a loophole if security experts find a way to protect. It’s an endless cycle, and whoever is up to date and on top of their game will achieve victory for that moment.

  • Follina – ZeroDay hole in MS Office

    Follina – ZeroDay hole in MS Office

    Microsoft has confirmed a Remote Code Execution (RCE) vulnerability in Microsoft Support Diagnostic Tool (MSDT) which is expected to be exploited since April, at least.  It was on May 27th, 2022, reports came about malicious word documents that leverages remote templates in order to execute PowerShell via the ms-msdt Office URL scheme. This vulnerability is assigned with CVE-2022-30190.

    An attacker who successfully exploits this flaw can execute arbitrary code by calling application’s privileges. In the context allowed by the user’s permissions, the attacker can then install applications, read, alter, or remove data, and create new accounts.

    It all started with a security researcher finding a document on VirusTotal that was used to execute PowerShell code. The security researchers have been analysing the malicious file and discovered that it was actually exploiting a zero-day vulnerability in MSDT. With this file, the researchers found that it will take only opening the file to trigger the exploit.

    Analysis:

    Follina is an RCE vulnerability found in MSDT that impacts several versions of Microsoft Office, including the patched versions of Office 2019 and 2021. Though an attacker leveraging flaw is likely to be Remote, Microsoft list the attack vector as “local” because of the way it is exploited.

    An attacker would create a malicious document, usually in Microsoft Word, and email it to their victim. An attacker can leverage this vulnerability to run commands with the permissions of the application that opened the infected document. Microsoft says that the attacker will be able to install programs, view, change, or delete data, or create new accounts.” The PowerShell was found to be used in the attacks observed in April. A broad range of attacks are expected with this vulnerability in the near future.  

    Proof of Concept:

    A detailed technical breakdown of this vulnerability is provided by Huntress Labs and you can also find other PoC in GitHub.

    Remediations:

    An effective patch is not yet released at the time of writing, you can find mitigation steps to limit attack surface. Microsoft has released mitigation guidance for this vulnerability and this vulnerability was revealed by a member of the Shadow Chaser Group, according to Microsoft’s alert.

    The mitigation guidance says that in Microsoft Defender, activate “Block all office apps from creating child processes” in Block Mode in order to prevent this vulnerability from being exploited. It is still not unclear what the impact would be for this mitigating effort.