Author: Clear Infosec

  • Adopting Zero Trust Model

    Adopting Zero Trust Model

    From Zero to Hero

    Employees are not limited to the office building like in the old days. The remote working had effects on literally everything. Organizations today need a comprehensive security strategy to manage the complexities of securing the data.
    From perimeter-based security to Zero trust architecture, we have come a long way. Let us look into how everything used to be and how everything is today.

     

    Before Zero Trust

    There was a time when the organizations only had to secure just the perimeter and everything inside that was counted as a trusted device or person. With time, technologies evolved and we have measures to secure each device/person within the perimeter.

    In Perimeter based security:      1. External access is untrusted
                                                               2. Internal access is trusted

    With remote working, organizations no longer have the perimeter, and made the attack surface increase. Excessive trust is always the main challenge to overcome and that is what the Zero-Trust model addresses.

    What is Zero Trust Model?

    Zero Trust is an advanced tactic intended to secure data and information by continuously verifying every digital interaction and avoiding implicitly trusting any access requests. The Zero-Trust model is built on a foundation that says, “NEVER TRUST, ALWAYS VERIFY”. No device or person is trusted by default, regardless of the location – whether within or outside the security perimeter.

    The basic principles of the Zero Trust model are:

    1. Verify Explicitly: Always Authenticate and Authorize.
    2. Use least privileged access: Limit user access with limited permissions for a limited time.
    3. Assume breach: Verify all sessions and attempts made for accessing data

    This model assumes every incoming request into the network as a breach and looks at that request as it is from an unauthenticated source. So the response to the request is provided only if that request is proved to be from a trustworthy source. Under the zero trust model, all traffic should be:

    • Authenticated – Every user/device is authenticated and is proved to be legitimate to gain trust
    • Encrypted – To protect Confidentiality, the data is encrypted while transmitting between source and destination.

    Need for Zero Trust Model

    Organizations are allowing employees to access business assets from remote devices and locations. So, organizations can no longer trust everything within the security parameter is secure. Regardless of where the request originates from, companies should secure connections to the business resources.

    With users and devices moving outside the enterprise perimeter, the business processes driven by digital transformation are increasing the risk exposure. The need to think of some strategy other than “Trust but verify” was inevitable.

    To protect data, and securely provide access to devices and users from wherever they are, organizations needed a new strategy. The zero trust model can be called a powerful strategy to stand protected in the competitive market.

    Building zero trust in your organization

    Zero trust controls should be implemented into all fundamental elements which are:

    • Identities: It can be people, devices, or services. When an identity tries to access a resource, that attempt should be verified with strong authentication and ensure that the least privileged access is provided.
    • Devices: Once an identity is granted access, it can access the data from anywhere via different devices. This increases the attack surface area and needs to be properly secured. The device should be compliant for secure access and its health should be continuously monitored.
    • Applications: Applications and APIs stand as the point of contact through which an identity access the data. The applications should have appropriate in-app permissions, control for user actions, and should be monitored for abnormal behavior.
    • Data: Data is the primary thing that needs the most secure options. Data should be classified, labeled, and encrypted. Whether it is in motion or at rest, it should be protected.
    • Infrastructure: The infrastructure of organizations every from one another. It can be On-Premises, Cloud, hybrid, etc. the infrastructure as a whole should be secured, monitored for any suspicious behavior, and apply patches/updates whenever it is available.
    • Networks: The data transfer is carried out over the networks. Proper controls should be placed in order to enhance better visibility of the data flowing in the network. The network connection should be monitored and end-to-end protected.

    Organizations should ensure that their data is kept safely to be recognized in the competitive business market. We highly recommend increasing the visibility of your networks and speeding up your detection procedures. Talk to our information security expert to start your journey towards a fortified infrastructure.

  • Browser in The Browser – A new near invisible attack

    Browser in The Browser – A new near invisible attack

    While reading on the different types of phishing attacks, recently I came across an interesting article by mr.d0x. His article explores the type of attack called Browser in the Browser (BITB). It is a novel phishing attack that exploits the user by simulating a browser window within a browser to spoof a legitimate domain. In simple terms, the pop-up window is used for spoofing.

    For all those who want to access the net and be safe, the first thing they will note is to look for whether the website URL shows HTTPS. This will indicate that the site is secured with TLS/SSL encryption.

    Of course, as technology develops, cybercrimes also develop with time. The URL method of checking is not reliable for quite some time because of many homographs attacks, DNS hijacking, and more. Now we can add one more attack to this list.

    BITB

    This BITB attack exploits the advantage of the third-party single sign on options (SSO) embedded on websites that issue pop-up windows for authentication. For example, Sign into Facebook, Apple, Google, or Microsoft. And it should be taken into consideration that these kinds of SSO pop-up methods are used widely for authentication.

    Fabricating POP up is easy

    According to the researcher, mr.d0x, creating a malicious pop-up window is very simple using basic HTML and CCS code. This BITB attack is very hard to find as it looks exactly similar to the original version. The following image shows the side by side by comparing original and fake windows provided in the mr.d0x blog.

    As we can see, the imitation of the windows is uncanny. Many security industrialists will also fail to see the difference between the two.

    POP-UP windows from click

    Fortunately, for this kind of attack to initiate, the attacker needs to make the user first visit the malicious site and click on the links to provide the pop-up windows.

    The attackers may use JavaScript to make the fabricated window appear when pressing the button click or link. The attackers may use animations or other designs to make it more appealing to the users.

    Hover over the links

    Hovering over the links is another simple method to confirm the link’s legitimate address. But if JavaScript is included in the attack, this method will ultimately fool the users. So BITB attacks render another simple means of avoiding phishing attacks useless.

    Avoid Fake POP window

    By using BITB, stealing the passwords will be very easy. Now let’s see some ways to avoid falling into this malicious attack lose our valuable credentials.

    • The best way to avoid this is to use password managers, as unnatural links may not fool the best password managers.
    • We can resize the desktop browser. If the JavaScript is not good enough, it will be easy to identify the fake.
    • You can also drag the pop window past the browser edge and hope that the pop-up window responds correctly. Otherwise, you can conclude that you are subjected to a phishing attack.

    The BITB attack mainly targets SSO, so using Multi-Factor Authentication (MFA) is highly recommended.

  • How Attack Vectors Can Harm Your Company

    How Attack Vectors Can Harm Your Company

    Effects Of Cyber Attacks :

    In recent years, we’ve likely to hear more about cybersecurity problems affecting all sorts and scales of businesses. This year, remote employment played a big role in the breach and the average cost was USD 1.07 million in which compromised credentials were the most prevalent first attack vector – accounting for 20% of breaches with an average cost of USD 4.37 million.

    Global cybercrime expenses which are expected to reach USD 10.5 trillion annually by 2025 up from USD 3 trillion in 2015 include – Theft of intellectual property, theft of personal and financial data, fraud, post-attack disruption to the regular run of business, forensic investigation, restoration and deletion of hacked data and systems, and reputational damages are all costs associated with cybercrime.

    A cyberattack can shut down a city’s, state’s, or even our entire country’s economy. In this blog, we’ll look at what is attack vectors and how cybercriminals utilize these attack vectors to exploit IT security flaws and execute their methods. We’ll also go over some basic security precautions for your firm to protect from these types of attacks.

    Attack Vector

    An attack vector is a technique used by cybercriminals to gain unauthorized network access to launch a cyber-attack and get access to sensitive data, personally identifiable information (PII), and other valuable information by exploiting system flaws.

    Cybercriminals can be former employees, politically motivated organized groups, hacktivists, professional hacking groups, or state-sponsored groups who always seem to find a way to overcome a strong cybersecurity perimeter by using increasingly complex attack vectors. Malware, viruses, email attachments, web pages, pop-ups, instant chats, text messages, and social engineering are all common attack vectors they use. Firewalls and antivirus software can help to block attack vectors to some extent. However, no security system is completely impenetrable to attack.

    Hackers are continually upgrading attack vectors and seek to exploit unpatched vulnerabilities published on CVE and the dark web to get unauthorized access to computers and servers, thus a protection approach might quickly become obsolete. Because cybercriminals are becoming more adept, antivirus software is no longer sufficient as a primary security measure.

    Attack Vector And Attack Surface:

    Attack Vector : An attack vector is a tool that cybercriminals use to gain unauthorized access to a network or computer system.

    Attack Surface : Attack surface is any broken links on a company’s network where an attack vector can be used to launch an attack. Surface grows as the number of endpoints, servers, switches, software applications, or other IT assets increases in the network.

    Common Types Of Attack Vectors And Mitigations :

    Weak and Compromised Credentials:  Users revealing their user IDs and passwords knowingly or accidentally remains the most frequent sort of credential access. This is typically triggered by phishing victims – exposing their login information to an attacker by entering it on a spoofed website. Attackers can also use stolen or lost credentials to gain access to user accounts and organization systems without being detected, and then elevate their access level within a network. Cybercriminals utilize brute-force attacks to target weak or easily guessed user IDs and passwords.

    Employees must use strong passwords and multi-factor authentication to limit the chances of an attacker stealing their credentials and also should be taught how to create a secure password or invest in a password manager.

    Malicious employees:  Some security breaches occur within the firm when unhappy or disgruntled employees with access to sensitive information and networks disclose confidential information to hackers.

    Organizations should keep an eye on network access for odd behavior, such as users accessing files or systems they wouldn’t usually access, as this could indicate insider risk.

    Poor Encryption: Encryption prevents cybercriminals from stealing sensitive information by ensuring that the data within a transmission cannot be read by an unauthorized person and sensitive data is transmitted in plaintext when encryption is missing, inadequate, or weak.

    To avoid this, users should utilize strong encryption methods such as Advanced Encryption Standard (AES) or Rivest-Shamir-Adleman (RSA) and ensure that sensitive data is protected at all times, including when at rest, in processing, and transit.

    Misconfiguration: Company software and hardware security can be misconfigured, leaving them open to hackers. As businesses rely more and more on internet-of-things (IoT) devices to do their duties, a hardware breach might also open the door for cybercriminals.

    To avoid misconfiguration, automate configuration management whenever possible.

    PhishingPhishing is a social engineering method in which hackers pretend to be a real colleague or known person to target employees via email, phone, or text message to disclose sensitive data, credentials, or personally identifiable information (PII).

    To reduce the risk of phishing, teach your employees about the importance of cybersecurity and how to avoid email spoofing and typosquatting.

    Malware: Malware stands for malicious software that allows cybercriminals to gain access to computers and networks and steal data or do significant damage. Once the authorized users lose access, cybercriminals threaten to leak data or disable access until a ransom is paid. Viruses, trojan horses, worms, spyware, adware, rootkits, and ransomware are some of the malware attackers use.

    Understanding the process of an attack, such as phishing techniques that ask users to disclose sensitive information is crucial to avoiding infection. Technology such as sandboxing, firewalls, antivirus, and anti-malware software that detect and stop possible assaults are required to protect against malware.

    Distributed denial-of-service (DDoS): In DDoS attacks, hackers use botnets to flood a server with internet traffic, preventing users from accessing services and perhaps crashing the organization’s website.

    The deployment of firewalls to filter and prevent unwanted traffic can help minimize a DDoS attack. Regular risk assessments, traffic differentiation to spread traffic and avoid a targeted attack, and rate-limiting to limit the number of requests a server may accept are some more protection methods.

    Trust Relationships: Users and systems have a particular level of trust in each other, which is referred to as a trust relationship. Because trust connections link two domains, a user only needs to log in once to access resources. If credentials that are cached on a trusted client are hacked, then It’s easy for an attacker to breach.

    Managing trust connections and passwords can assist you in limiting or eliminating the impact of the damage.

    How Clear Infosec Can Help :

    Clear Infosec helps organizations secure their networks and control internal and external attack vectors. We also enable them to encrypt data securely to keep it out of the hands of malicious hackers, even if they try.

    Please contact us to learn more about our services and the cutting-edge security technologies we can provide for your organization.

  • Phishing and DDoS attacks on Ukraine

    Phishing and DDoS attacks on Ukraine

    “In the last 12 months, Threat Analysis Group (TAG) has issued hundreds of government-backed attack warnings to Ukrainian users alerting them that they have been the target of government-backed hacking, largely emanating from Russia.” wrote Shane Huntley, Google’s TAG lead. TAG has seen activity like espionage to phishing attempts from several threat actors, including FancyBear and Ghostwriter which they monitor regularly and are well-known to law enforcement.

    FancyBear:

    FancyBear also known as APT28 or Sofacy is a nation-state adversary group that has been active since at least 2008 and poses a persistent danger to a wide range of organizations around the world. They use a sophisticated and cross-platform implant to attack aerospace, defense, energy, government, media, and dissidents. Now they are carrying out many large-scale credential phishing attempts targeting media company UkrNet users in Ukraine. A huge number of compromised accounts (non-Gmail/Google) were used to send phishing emails. Users of i.ua, meta.ua, rambler.ru, ukr.net, wp.pl, and yandex.ru webmail have also been targeted.

    DDoS Attacks:

    According to Google TAG, a recent slew of distributed denial-of-service (DDoS) attacks have targeted Ukrainian government sites like the Ministry of Foreign Affairs and the Ministry of Internal Affairs, as well as critical information-finding services like Liveuamap. According to the report, Google TAG used Google Safe Browsing to block several credential phishing domains that researchers discovered throughout the campaigns. Among the domains were: i[.]ua-passport[.]top, login[.]creditals-email[.]space, post[.]mil-gov[.]space, and verify[.]rambler-profile[.]site.

    Mustang Panda:

    a Chinese phishing operation has also joined the fray, focusing on European companies with lures related to the Ukrainian invasion in a new phishing effort. Mustang Panda has been active against EU entities before, most recently targeting Rome’s Vatican and Catholic Church-related organizations with a spearphishing campaign in September 2020. While Huntley noted that targeted Europe represents a shift for the threat actor – which typically targets entities in Southeast Asia – Mustang Panda has been active against EU entities before. TAG discovered malicious attachments with file names like ‘Situation at the EU Borders with Ukraine.zip’ contains a basic downloader that downloads numerous extra files before loading the final payload. TAG notified the appropriate authorities of its findings in order to minimize the potential for harm.

    Ukraine’s governmental Computer Emergency Response Team (CERT-UA) took this issue to social media right after the invasion by Russian armed troops to warn Ukrainians about an increase in phishing attempts targeting devices in the country. UA’s cyber security firm ESET has urged the warning outside Ukraine to be aware of phishing attempts linked to the conflict when the State Service of Special Communication and Information Protection (SSSCIP) of Ukraine was giving CERT warnings. 

    SSSCIP has issued a new warning to Ukrainian businesses asking them to segregate non-critical workstations and servers, upgrade systems and software to the most recent versions, and back up data to external storage.

    ProjectShield:

    All qualified organizations are encouraged to sign up for ProjectShield-with-google so that systems can stop assisting these assaults and keep websites up and running. Over 150 websites in Ukraine including numerous journalistic organizations use the service as it stops Google to bring harmful traffic generated by a DDoS assault. The number of people eligible for Project Shield has been increased for free DDoS protection, so that Ukrainian government websites, embassies around the world, and other governments in close proximity to the conflict can stay online, protect themselves, and continue to provide critical services and information.

    Reference:
    Montalbano, A. E., & Montalbano, E. (n.d.). Russian apts furiously Phish Ukraine – google. Threatpost English Global threatpostcom. Retrieved March 10, 2022, from https://threatpost.com/russian-apts-phishing-ukraine-google/178819/

  • Best practices for Data Loss Prevention

    Best practices for Data Loss Prevention

    We know that data is what drives the technology today. Data is a distinctive type of information that is collected and translated for a specific purpose. If the data is not formatted in the right way, it does not provide any value to both humans and computers. Data is considered sensitive when it gives classified information and requires the users to have the right permissions to access it. In other words, any data that should be prevented from unauthorized access can be considered sensitive.

    In order to efficiently manage data, they are organized into relevant categories according to usage. Data are categorized into groups of similar kinds. The process of organizing categorized data according to its sensitivity level is Classification and it helps to define a protection scheme for each type. When it comes to risk management and compliance, Data classification is of high importance. Data classification is a useful tactic that facilitates proper security responses based on the data being transmitted, retrieved, or updated.

    Over the years, cyber-attacks are getting highly evolved, and reports say that it takes organizations an average of around 190 days to identify a data breach. If an organization is not careful enough to protect its sensitive data, they are at the risk of getting exposed to bad actors or those who are not authorized to view those data. There exist many security procedures to keep your data secured. The strategy organizations adopt to keep the data secured from reaching the wrong hands is often referred to as Data Loss Prevention or DLP.

    In other words, it is a set of practices or a strategy that detects potential data breaches and ensures no sensitive data is shared, misused, or accessed by unauthorized users. It is identical with the term Data Leakage prevention and these terms are often used interchangeably. But the most commonly used term is Data Loss Prevention itself.

    DLP Best practices

    1. Data Classification

    You need to be clearly aware of the data types you handle. Data classification is the process of classifying data you have under its relevant category. Some of the commonly known data types are Personally Identifiable Information (PII), Protected Health Information (PHI), Payment Card Information (PCI), and any other information that you are legally obliged to safeguard.

    2. Identify the Sensitive data you handle

    You should have a clear understanding of the kind of Data your organization is handling. Don’t matter you are running only a small business or even an Enterprise, this understanding is the primary level of maturity to adopt a DLP strategy.

    If you are handling any Intellectual Property or Personally Identifiable Information or any such sensitive data that requires high security, it is highly recommended to adopt a DLP strategy. In order to enhance the value and creativity of your DLP program, you should engage with your Executive and Senior Leadership.

    3. Research Multiple Vendors

    With senior leadership, you can define your expectations for the DLP program in your organization. Consult with industry peers and vendors to learn about the DLP programs they’ve implemented, their workflow, and their level of confidence.

    4. Define Incident Response and Remediation

    If you are representing an Enterprise level organization, you should not buy any random DLP tool. You should take time to research and implement a complete DLP strategy. What many organizations fail to do is to plan incident management. They won’t go through the strategy process well and purchase any of the tools and fail to define a DLP incident management plan.

    Make sure you have an Incident Response Team in place.

    5. Start Slow, plan well and go for it

    Instead of implementing every single policy checkbox while implementing a tool, go through them all and go for small wins. Start with the prior ones and implement more security on the go.

    6. Perform a Proof-of-Concept exercise

    The goal of this step is to duplicate the functionality and test feature sets. Upon selecting a tool, ensure that it meets your compliance needs and study carefully the deficiencies in your Incident Management program.

    7. Identify the DLP stakeholders

    Many researchers say that not every organization having a DLP strategy is utilizing the program efficiently. Make sure you won’t be one such. Form an internal DLP team comprised of Senior Leaders, Managers, Legal Representatives., and skilled InfoSec professionals.

    If you feel hard to go through any of the DLP strategy implementing steps, try partnering with a reputed and experienced Managed Service Provider with skilled InfoSec professionals.

    8. Always be in touch with the Stakeholders

    Ensure you keep the stakeholders updated about the program. Never let a communication gap takes place between the DLP team and the Stakeholders. Monthly or Quarterly meetings can keep your strategy in a loop that will add value to your entire program.

     

    What you gain with a DLP solution

    With a DLP solution, you get better visibility of the data in your organization. With the right DLP solution, you get to:

    1. Monitor data in motion

    2. Monitor data at rest

    3. Monitor how the data is being used

    4. Take actions such as Delete, Log, Archive, and Quarantine

    We understand that not all organizations get much investment to get a paid tool for DLP. If you are one of them, we got some solutions for you too.

    1. MyDLP –

    It is one of the first free software projects for data loss prevention. The project was acquired by Comodo Group in 2014 and started marketing the Enterprise version once they removed the free version from the website.

    The centralized management options and Google-like search engine makes the application very easy to use. A free trial of 30 days is available for MyDLP.

    2. OpenDLP

    It is an open-source Data Loss Prevention tool. It is a web-based application with Data management and tracking features. It is an always-free software. You can find the application source code here.

    Make sure your capital investment is put to good use and it is made after a cost-benefit analysis, risk assessment, and Vendor analysis. Understand your business model in the first place to start defining a DLP strategy. A well-planned DLP strategy and Deployment makes a DLP program successful.

  • Trojans are targeting Microsoft teams

    Trojans are targeting Microsoft teams

    A recent harmful campaign is taking control over end-user computers by placing malicious documents in Microsoft Teams chat. Cybercriminals have targeted Microsoft’s omnipresent document creation and sharing suite – the legacy Office and its cloud-based successor Office 365 – with assaults on individual apps like PowerPoint, as well as business email compromise and other schemes.

    According to Statista, the number of teams users has nearly quadrupled in the last year, from 75 million in April 2020 to 145 million in the second quarter of 2021. As the application serves over 270 million monthly users as of January 2022, it became an appealing component for both cyber criminals and APT actors. Threat actors are attaching malicious files in chat and drop system-hijacking malware to penetrate into the app rapidly.

    Avanan began to recognize how hackers were placing harmful executable files in Teams talks in January 2022. The application may self-administer since the file writes data to the Windows registry, installs DLL files, and makes shortcut links. Thousands of similar attacks occur every month, according to Avanan. In this attack overview, we’ll look at how hackers in Microsoft Teams employ these.exe files.

    Attack

    Hackers are attaching .exe files to the Teams chats in this attack in order to install a Trojan. The trojan is utilized then to install malware.

    • Vector: Microsoft Teams
    • Type: Malicious Trojan File 
    • Techniques: .exe files
    • Target: Any end-user

    Email

    Hackers are breaking into the Teams app in this attack, which can be done via email-based East-West attacks or by faking a user. The threat actor then attaches a “User-Centric”.exe file to a chat. This file is a Trojan that will install DLL files and build self-administering shortcut links.

    Techniques

    Hackers have discovered a new way to easily target millions of users by adding the file to a Teams attack. Accessing Teams is the first step. Hackers can do this in a variety of ways. They can infiltrate a partner organization and listen in on inter-organizational conversations.

    They can gain access to Teams by compromising an email address. They can use stolen Microsoft 365 credentials from a prior phishing attack to gain full access to Teams and the rest of the Microsoft Office suite. 

    Given how well hackers can compromise Microsoft 365 accounts using classic email phishing techniques, they’ve figured out that the same credentials work for Teams. 

    Furthermore, once inside an organization, an attacker is usually aware of the technologies in place to secure it. That implies they’ll be able to predict which spyware will be able to get beyond existing defenses.

    This exploit shows that cybercriminals are starting to recognize and better utilize Teams as a potential attack vector. As the use of Teams grows, Avanan anticipates a large increase in these types of attacks.

    Tips and Best Practices

    Security experts can take the following steps to prevent these attacks:

    • Adopt a security solution that checks all files for malicious content in a sandbox.
    • With a comprehensive, full-suite security solution, protect all lines of company communication, including Teams.
    • End-users should be encouraged to contact IT if they come across an unexpected file.

    Reach out to Clear Infosec today to keep your workforce aware of evolving threat landscape and define an Information Security strategy that fortifies your systems.

    Reference:

    Montalbano, A. E., & Montalbano, E. (n.d.). Microsoft teams targeted with takeover trojans. Threatpost English Global threatpostcom. Retrieved February 21, 2022, from https://threatpost.com/microsoft-teams-targeted-takeover-trojans/178497/

    Fuchs, J. (n.d.). Hackers attach malicious .EXE files to teams conversations. Avanan. Retrieved February 21, 2022, from https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversatio

  • Hackers Infecting PCs With Windows Update Malware

    Trojanized version of IDA Pro:

    The North Korea state-sponsored group- Lazarus used a trojanized pirated version of the popular IDA Pro reverse engineering software (which translates machine language into assembly language) to target security researchers with available backdoors and remote access trojans.

    IDA Pro enables security researchers to analyze the malicious and debugger to detect errors. According to the Slovak cybersecurity firm, “attackers bundled the original IDA Pro 7.5 software developed by [Hex-Rays] with two malicious components.”

    During the installation of the application, an internal module called “win fw.dll” is executed. After that, a second component named “idahelper.dll” from the IDA plugins folder on the system is loaded. The “idahelper.dll” program connects to a remote server at “www[.]devguardmap[.]org” to obtain further payloads after successful execution.

    Windows update service Malware:

    The IP was previously tied to a similar North Korean-backed campaign aiming at security professionals, as revealed by Google’s Threat Analysis Group earlier this year. This North Korean nation-state hacking group APT38, also known as Hidden Cobra, Whois Hacking Team, and Zinc, has been active since at least 2009. The hacker was sending two files: Lockheed Martin JobOpportunities.docx and Salary Lockheed Martin job opportunities confidential.doc, which were clearly aimed towards people looking for work at Lockheed Martin.

    The malicious macros once it is activated the documents drop a WindowsUpdateConf.lnk file in the target endpoint’s startup folder and a DLL file (wuaueng.dll) in the Windows/System32 folder. The .lnk file then launches the Windows Update Client and starts the malicious DLL. Also in order to get through antivirus and other security measures, Lazarus runs its malicious DLL using the Windows Update Client by passing the following arguments: /UpdateDeploymentProvider, Path to malicious DLL, and /RunHandlerComServer.

    Malwarebytes detected the most recent spear-phishing attempt on January 18 based on weaponized documents with job-themed lures emulating Lockheed Martin, an American global security and aerospace business.

    When you open the malicious Microsoft Word document, it activates the macro attached in the document, which then executes a Base64-decoded shellcode that injects malware into the “explorer.exe” process. Then one of the loaded files, “drops lnk.dll,” uses the Windows Update Client (“wuauclt.exe”) to run a command that loads a second module called “wuaueng.dll,” which is used as a defense evasion method to blend bad activity with trusted Windows software.

    This isn’t the first time the Windows Update Client has been used to spread malware; MDSec researcher David Middlehurst found the threat being exploited in October 2020. We’ll have to wait and see what Microsoft does about it, but meanwhile be cautious while downloading the attachment from the email, especially if they require macro activation.

    If you receive an email with attachments that appears to be legitimate but you are unsure, turn to our blog and use the methods to assess the attachments.

    Researchers, at last, reported that ”Lazarus APT is one of the advanced APT groups known to target the military industry. In order to escape security systems, the organization is constantly improving its toolkit.“

    Reference :

    shamili0508. (2022, January 29). North Korean hackers are infecting pcs with malware through  the windows update service. CyberWorkx. Retrieved February 2, 2022, from https://cyberworkx.in/2022/01/29/north-korean-hackers-are-infecting-pcs-with-malware-through-the-windows-update-service/

    North Korean hackers target cybersecurity researchers with Trojanized Ida Pro. The Hacker News. (2021, November 15). Retrieved February 2, 2022, from https://thehackernews.com/2021/11/north-korean-hackers-target.html

  • Ransomware Protection and Response

    Ransomware Protection and Response

    Over the past weeks, we discussed What is ransomware, and the Anatomy of ransomware attacks. Now, let us look into some ways to protect yourself from ransomware and how to respond if you fall victim to any.

    According to IBM, ransomware attacks are very high which contributes up to more than 23% of total cybersecurity attacks. The total amount of ransom amount was more than 120 million dollars in a year. To prevent a ransomware attack, the organization needs to have a specified plan, awareness, and cooperation from everyone in the organization. Below are some of the methods to prevent the organization from ransomware attacks.

    • Backups
    • Plans and policies
    • Port and endpoints
    • Awareness

    Backups

    The simplest and easiest way is to prepare a backup copy of the confidential data. It will be easy to recover the data if the backup is available and not infected. So, it should be noted that backup files should be protected properly offline or some other networks which can’t be accessed if the current system network was hacked. And the backup files should be routinely monitored. Some ransomware strains are specifically created to attack the data stored in the cloud system. Before doing recovery during an attack it is of utmost importance to check if the backup data are infected or not.

    Plans and policies

    Having a proper plan and policies will help a lot in mitigating ransomware attacks. Create incident response plans and policies if the system undergoes infection, so the cybersecurity team can handle it according to the plans without issues. It will prevent panic among the organization. The plans should also have who should be contacted if the attack happens.

    Ports and endpoints

    The systems in the organization should be customized by having security as their top priority. Having a proper secure configuration can help to prevent attacks and stop the security gaps provided in the standard configuration. The hackers mainly used certain ports to spread the malware strains. Knowing the ransomware strains can help in understanding the specified ports. It should be properly considered if the organization needs those ports to be open. If it is required to be set in open it should be limited only to the trusted hosts.

    Awareness

    It is highly recommended to develop a team specialized in cybersecurity. Every employee should be aware of ransomware attacks. A phishing email is the highest method hackers have used for spreading ransomware. The employees should know how to spot suspicious emails and report immediately to the cybersecurity team about the mail. Having a specified team with the latest updates and hardware will help in preventing or mitigating the attack faster.

    The systems should be updated regularly to not give the hackers to use of any kind of loophole to initiate the attack. Having regular patches of the software also help to reduce the vulnerability of the system.

     

    Ransomware Incident response

    If an organization was infected by ransomware, these are the best and most simple response plans that needed to be carried out.

    Identify and Validate

    First and foremost, confirm whether the attack was a ransomware attack or some other bugs, viruses, or malware. It is easy to confirm as the files will be encrypted or systems will lock with ransom notice published.

    Analyze

    If the attack was confirmed, immediately gather a response team to analyze the exact scope of the attack. How the malware is spreading, which network is affected, which network and systems are not affected should be analyzed as soon as possible.

    Containment

    After analyzing, disconnect all the systems that have been confirmed to be infected immediately from the networks. If it’s not possible, disconnect the network to prevent from infection spreading. Have a SOC team monitor the network traffic and block access to the ransomware command center.

    Investigation

    Next is to identify what kind of ransomware strain infects the systems. Having a clear understanding of the specified strain may help to mitigate the attack much faster. Some strains use low-level encryption algorithms which have decryption code publicly available.

    Erase and recovery

    This step includes formatting all the systems that have been infected and restoring the backup data. Backup data should be checked for infection before restoring and all the passwords, security keys should be changed.

    Post-infection actions

    After the infection is over, properly adhere to all the instructions stated in the contracts. Informing law enforcement agencies can help in mitigating the attack impact or capture the hacker as soon as possible. They might have encountered similar attacks and have ways to prevent the attack. If not, they may provide the proper guidance to pay the ransom and recover data without loss.

    Properly analyze and check how the attack was initiated, time taken for the security team to respond, logs created during the attack, type of strains of malware that infected the system and all such information should be noted. It will help to prevent from getting attacked by the same kind of vulnerability in the future. And from the reports, the policies can be improved further to prevent future attacks.

    With Clear Infosec, keep your workforce trained to stay fortified to any kind of social engineering attacks. Also, keep them informed of the evolving threat landscape.

  • TOP 10 CYBER SECURITY BEST PRACTICES TO FOLLOW IN 2022

    TOP 10 CYBER SECURITY BEST PRACTICES TO FOLLOW IN 2022

    Educate your workforce about the importance of security and about the highly evolving threat landscape. Make these below mentioned practices a part of your work culture to prevent your organization from ransomware attacks:

    1.Multi-Factor Authentication

    Multi-Factor Authentication is one of the most effective controls in preventing unauthorized access by bad actors. Authentication uses two or more different factors to achieve authentication. Factors can be (i) something you know (e.g., a password/PIN); (ii) something you have (e.g., a cryptographic identification device, a token); or (iii) something you are (e.g., a biometric).

    2.Password Security

    Strong password policy includes longer passwords (12-15 characters minimum), mix characters, password age shouldn’t be more than 60 days, using password manager.

    3.Security Culture

    Regularly conducting security awareness training fosters a security culture across the organization.

    4.Data Security

    Regular backups of the data and having a strong DLP policy and controls to prevent egression of data.

    5.End Point Security

    Endpoint security, or endpoint protection, is the cybersecurity approach to defending endpoints such as desktops, laptops, and mobile devices from malicious activity. Enabling strong spam filters, antivirus or anti- malware security on endpoints is proven to provide a layer of defense to secure the organization.

    6.Zero Trust and SASE adaption

    The global pandemic further accelerated a trend toward remote work. Traditional, perimeter-based approaches to security will no longer work in a cloud-first environment. Hence, applying zero trust principles to every interaction with that data will enhance the overall security posture. This paradigm shift towards digital transformation calls for a modern architecture to combine cloud access security broker (CASB), Next Generation Secure Web Gateway (NG-SWG), and Zero Trust Network Access (ZTNA) capabilities as foundational for SASE (Secure Access Service Edge).

    7.Security Assessments & Upgrades

    Regular security assessments, like vulnerability assessments, pen tests, and social engineering assessments, will help in identifying the existing vulnerabilities, weak controls and provide compliance and information assurance.

    8.Threat Monitoring

    Real-time monitoring for threats helps in early detection and responding to threats while enhancing the security posture.

    9.Email Protection

    Email protection helps in filtering spam and provides a fortified approach to combat ransomware attacks and many other attacks where users fall prey to phishing attacks.

    10.DOS & DDOS protection

    Utilizing tools to protect against denial of service or distributed denial of service by whitelisting, blacklisting, and having strong firewalls alongside DNS Security will help in combating DOS/DDOS attacks.

  • Android malware BRATA strikes again with new dangerous capabilities

    Android malware BRATA strikes again with new dangerous capabilities

    Android malware BRATA gained new dangerous features in the latest version like GPS tracking, the ability to use various communication channels and factory reset to hide fraudulent wire transfer.

    BRATA – Brazilian Remote Access Tool (RAT) Android was a spyware, which was later known to be a banking trojan. This spyware was found out by Kaspersky as banking and financial institution-targeting Android RAT (The remote access trojan) in 2019. Before this RAT reach US and Spain, it used to target only Brazil.

    Cleafy published a research in December 2021 and highlighted BRATA as malware emerging across Europe. It was discovered that hackers posing as bank customer service representatives were targeting e-banking users and collecting their credentials.

     

    Variants and Capabilities:

    The BRATA trojan has been detected in three different variants so far:

    Source: Cleafy

    1. BRATA.A: This variation has been most popular for the last few months and hackers included 2 more capabilities to it in December. GPS tracking of the user’s device is the first capability that is under development and the second feature is wiping out the infected device.
    2. BRATA.B is quite comparable to the first variant. The partial concealment of the code and using customized banking overlay pages to steal the PIN is what sets this variant unique from the previous one.
    3. BRATA.C :  This variant consists of a trap that attacks by downloading and executing the malicious app.

    The creators of BRATA are constantly changing the malicious code to avoid antivirus software detection. “Although the majority of Android banking trojans try to obfuscate/encrypt the malware core in an external file (eg. .dex or .jar), BRATA uses a minimal app to download in a second step the core BRATA app (.apk),” the Cleafy team added.

    “When the victim clicks on the install button, the downloader app sends a GET request to the command-and-control (C2) server to download the malicious .APK,” they explained. “At this point, the victim has two malicious apps installed on their device.”

    After BRATA installs a malicious app and executes the code, the accessibility permissions had been granted and can take control over the compromised device. Here’s a list of commands discovered by McAfee in all of the payloads :

    • lock screen Theft (PIN/Password/Pattern)
    • Screen Capture: Screenshots are sent to a remote server after the device’s screen is recorded.
    • Execute Action: Abuse accessibility services to interact with the user’s interface.
    • Unlock Device: Use stolen PIN/Password/Pattern to unlock the device
    • Start/Schedule activity lunch: Opens a specific activity provided by the remote server
    • Start/Stop Keylogger: Captures user’s input on editable fields and leaks that to a remote server
    • UI text injection: Injects a string provided by the remote server in an editable field
    • Hide/Unhide Incoming Calls: Sets the ring volume to 0 and creates a full black screen to hide an incoming call
    • Clipboard manipulation: Injects a string provided by the remote server in the clipboard
    • In addition to the commands above, BRATA also performs automated actions by abusing accessibility services to hide itself from the user or automatically grant privileges to itself:
    • Hides the media projection warning message that explicitly warns the user that the app will start capturing everything displayed on the screen.
    • Grants itself any permissions by clicking on the “Allow” button when the permission dialog appears on the screen.
    • Disables Google Play Store and therefore Google Play Protect.
    • Uninstalls itself in case the Settings interface of itself with the buttons “Uninstall” and “Force Stop” appears on the screen.

    Here are some of the apps which are compromised :

    Source: McAfee

     

    Prevention against Android Malware:

    Here are some suggestions to help you avoid being deceived by Android malware.

    • Be aware of the Android application available in the official store before you download. Most victims are induced to install the app with the promises of a secure device but with a fake update. Users shouldn’t need to install a third-party app to keep their devices updated.
    • To detect malware applications the users should install a trustworthy and up-to-date antivirus on their devices.
    • Do not click on any suspicious links from an unknown sender, because it may download malicious applications through it.
    • Check the developer information, requested permissions, the number of installations, and the content of the reviews before installing an app. There is a chance that an application’s positive rating be a result of a majority of fake reviews.

    As a result, Android users must exercise extreme caution when allowing this access to any app. As accessibility services are so powerful, a malicious application may exploit them to completely take over device data, online banking, and funds.

    Get the protection you need and the privacy you want, with Clear Infosec. Check out our services and reach out to know more about how to secure your data.

     

    Reference :

    Fernando Ruiz Apr 12, Ruiz, F., Fernando Ruiz Mobile Malware Researcher Fernando Ruiz is a Security Researcher in McAfee, Researcher, M. M., & Fernando Ruiz is a Security Researcher in McAfee Labs. He specializes in mobile threats and Android malware. Ruiz performs deep analysis and reverse engineering of malicious code. (2021, April 12). Brata keeps sneaking into Google Play, now targeting USA and Spain. McAfee Blog. Retrieved January 25, 2022, from https://www.mcafee.com/blogs/other-blogs/mcafee-labs/brata-keeps-sneaking-into-google-play-now-targeting-usa-and-spain/