listen more to learn more.

Saturday, November 19, 2016

New Trojan Used to Spy on Russian Crane Manufacturers

Researchers at Russian security company Doctor Web discovered a new piece of malware used by malicious actors to target some of the largest construction crane manufacturers in Russia.

The Windows Trojan, dubbed by the security firm BackDoor.Crane.1, has been spotted in attacks aimed at two major companies specializing in cranes and auxiliary equipment. When the malware was discovered, it had been stealing confidential information from infected systems for some time.

BackDoor.Crane has been used to steal financial documents, agreements and internal business correspondence, which has led experts to believe that the attacks are part of a corporate espionage campaign conducted by “unscrupulous rivals.”
Once it infects a device, the malware contacts its command and control (C&C) server and waits for instructions. The attackers can install various modules, each designed to carry out certain activities, such as executing commands in the Command Prompt, downloading files from a specified link, uploading files via FTP or HTTP, and taking screenshots.
Dr. Web said some of the modules also downloaded a couple of Python-based Trojans. One of them, tracked as Python.BackDoor.Crane.1, can execute the same commands as BackDoor.Crane, but it can also get a list of files and folders from a specified path, delete files, terminate processes, copy files, and terminate itself.
The second piece of malware, Python.BackDoor.Crane.2, can open a shell on the infected device.

An “about” window left behind by mistake by the malware developers suggests that the first version of BackDoor.Crane was launched in 2015. However, Doctor Web said the samples analyzed by its researchers were compiled in April 2016. The security firm has published a detailed report on how the malware works and the traces it leaves on an infected system.

Moxa, Vanderbilt Surveillance Products Affected by Serious Flaws

Surveillance products from Moxa and Vanderbilt are affected by several critical and high severity flaws that can be exploited by remote hackers to take control of vulnerable systems.

Moxa SoftCMS vulnerabilities

ICS-CERT has published an advisory describing three serious vulnerabilities affecting Moxa SoftCMS, a central management software designed for large-scale surveillance systems. Gu Ziqiang from Huawei Weiran Labs and Zhou Yu have been credited for finding the security holes.

The most severe of the flaws, with a CVSS score of 9.8, is a SQL injection (CVE-2016-9333) that can be exploited by a remote attacker to access SoftCMS with administrator privileges.

Another flaw, tracked as CVE-2016-8360, is a double free condition that allows an attacker to cause a denial-of-service (DoS) and possibly even execute arbitrary code.
The third vulnerability (CVE-2016-9332) has been described by ICS-CERT as an “improper input validation” issue that can lead to a crash of the application.
ICS-CERT said in its advisory that Moxa patched these security holes with the release of SoftCMS 1.6 on November 10, but the vendor’s release notes show that the latest version only addresses the SQL Injection issue.

A different SQL injection, also discovered by Zhou Yu, was patched by Moxa in its SoftCMS software a couple of months ago with the release of version 1.5. Versions 1.3 and 1.4, released last year, also fixed potentially serious flaws found by security researchers.

Vulnerabilities in Siemens-branded Vanderbilt CCTV cameras

Siemens and ICS-CERT informed users that several Siemens-branded Vanderbilt IP cameras are affected by a vulnerability (CVE-2016-9155) that allows an attacker with network access to obtain administrative credentials using specially crafted requests. Updates have been released by Vanderbilt for each of the affected products.
Vanderbilt Industries completed the acquisition of Siemens’ security products business in June 2015. Since the affected CCTV cameras are Siemens-branded products, the German engineering giant has published a security advisory on its own website.

iPhone Call Logs Quietly Synced to iCloud, Forensics Firm Warns

A log of all phone calls made from iPhone devices running iOS 8 or newer may be automatically synchronized to iCloud and susceptible to third-party access, digital forensics and IT security solutions provider Elcomsoft has warned.

The issue, Elcomsoft’s Oleg Afonin explains, is not only that call records are synced to iCloud (when iCloud is enabled) regardless of whether the user wants that to happen or not, but also that iCloud data is loosely protected. Thus, if user’s calls are synced to the cloud, Apple themselves and third-parties with access to the proper credentials could extract them.

What’s more, all of the information stored in iCloud is available for law enforcement upon request, unlike data stored exclusively on the device, which Apple has said numerous times it cannot access.

In fact, Apple entered a spat with the FBI earlier this year when it refused to help decrypt the iPhone of San Bernardino shooter Syed Rizwan Farook, claiming that the Bureau was actually requesting a backdoor to be included in all iPhone devices. Eventually, the FBI received help from a third-party firm, but the quarrel went viral as large tech companies expressed their support for Apple. Some even announced plans to improve their encryption to provide users with increased privacy.

“On devices running iOS 8 and later versions, your personal data is placed under the protection of your passcode. For all devices running iOS 8 and later versions, Apple will not perform iOS data extractions in response to government search warrants because the files to be extracted are protected by an encryption key that is tied to the user’s passcode, which Apple does not possess,” Apple says.
However, the same is not true about data saved on iCloud, because the same encryption level no longer applies to it. In Afonin’s opinion, the cloud syncing functionality is actually a blessing for forensic researchers and law enforcement agencies, as they can access user information that would otherwise be out of reach, because of the privacy features in iOS.  

“The ability to extract call logs from the cloud instead of having to deal with the tough hardware protection of todays’ iPhones can be a blessing for forensic examiners,” Afonin says.
iPhone Call Log
For users, however, this is a privacy nightmare. Not only is access to their data much easier, for Apple and for anyone with the right credentials, but the synced data – in this instance, call logs – is visible on all devices on which the same Apple ID is used.
If a user has two iPhones but a single Apple ID, the calls will appear on both devices. If two people share the same Apple ID, they will have visibility into each other’s calls. What’s more, if one of them clears the calls list on their device, the other user/device will be impacted as well.

The only way to avoid that, Elcomsoft says, is to disable iCloud Drive functionality on the iPhone. The move will not affect features such as iCloud Photo Library or iCloud backups, but will affect the syncing of data for third-party apps that rely on iCloud Drive for that. Increased privacy, it seems, comes at a cost.

Friday, November 18, 2016

Hackers Access Private Details of Three Mobile Customers

Computer hackers have broken into a database of Three Mobile customers and accessed their personal details in order to steal smartphones, the UK network said on Thursday.
A spokesman for the company said there had been an uptick in attempted phone fraud over the past four weeks, both through burglaries of Three retail stores and intercepting customer phone upgrades.
"In order to commit this type of upgrade handset fraud, the perpetrators used authorised logins to Three's upgrade system.
"This upgrade system does not include any customer payment, card information or bank account information," the spokesman said.
Three Mobile Cyber Attack and Data BreachPersonal details including names and addresses were accessed and are believed to have been used by fraudsters to order the phone upgrades, which were sent to eight customers and intercepted.
A probe is currently underway to determine how many more of the company's nine million customers have had their data breached, while the eight known clients have been contacted by Three.
A source close to the matter was quoted by The Telegraph as saying the private information of two thirds of Three customers could be at risk.
"The investigation is ongoing and we have taken a number of steps to further strengthen our controls," said the company spokesman.
Three people were arrested on Wednesday in connection to the fraud and have since been bailed.
A 48-year-old man from Kent, south-east England, and a 39-year-old man from Manchester, north-west England, were arrested on suspicions of computer misuse offences.
A 35-year-old man also from Manchester was arrested on suspicion of attempting to pervert the course of justice.

Thursday, November 17, 2016

Carbanak Hackers Hit Hospitality Firms With New Tactics

The prolific Carbanak crime group has recently zoned in on the hospitality sector and adopted a new attack methodology, Trustwave security researchers warn.

The security firm analyzed three separate attacks, two targeting hospitality clients and one aimed at a restaurant chain, and found that all three featured the modus operandi of the infamous hacking group. Carbanak, also known as Anunak, managed to steal as much as $1 billion from more than 100 banks across 30 countries, and reemerged this year, targeting banks in the in the Middle East and U.S.

The attackers used social engineering in the new incidents: they would call customer service saying they couldn’t make a reservation and requested to send information via email. The email message contained a malicious Microsoft Word document with an encoded .VBS script to steal system information and screenshots, and download additional malware. The attackers would reportedly stay on the phone until they had confirmation of a successful attack.

The malicious script uses macros to search for running Word instances and replaces their content with attacker-generated text. Next, a compromised system connects to hxxp://95.215.47.105 to download additional malware (AdobeUpdateManagementTool.vbs).
This malicious program creates folders on the compromised systems and adds files to them, adds a persistence mechanism, creates a scheduled task to call the vbs, creates a service to call the vbs, and drops a Shockwave Flash icon and disguises itself as such. The malware was observed contacting a few websites, as well as several command and control (C&C) servers.

Trustwave researchers say that this threat can steal system and network information and can download reconnaissance tools to map out the network. Some of the downloaded utilities include Nmap, FreeRDP, NCat, NPing, and others. It would also grab el32.exe and el64.exe, which are privilege escalation exploits for 32 and 64 bit architectures.

This piece of malware, researchers say, was mainly responsible for the reconnaissance stage of the attack, in addition to downloading malicious apps to set up for the next stage of the attack. It could also execute Powershell scripts on command.
The malware sends beaconing messages via standard HTTP GET requests every 5 minutes, which allows it to hide within standard corporate network traffic. What’s more, the content of the GET request is encoded with Base64 and secondarily encrypted with RC4. The purpose of beaconing is for the attacker to know that the infected system is available for further exploitation.

In the second stage of the attack, the malware identified as bf.exe executes a new iteration of svchost.exe and injects its malicious code into this running process to hide itself. Next, it drops a pseudo-randomly named configuration file into the %ProgramData%\Mozilla folder, with a base64 encoded name based on the infected system's MAC code, and with a .bin extension.

The malware also searches the infected system for Kaspersky antivirus processes and terminates them, after which it registers itself as a randomly-named service with the “C:\Documents and Settings\All Users\Application Data\Mozilla\svchost.exe” path.
After this step has been completed, the malware downloads well-known Carbanak malware, namely kldconfig.exe, kldconfig.plug, and runmem.wi.exe. The decrypted string references “anunak_config,” which researchers say is the encrypted configuration file downloaded from the C&C server.

The malware can enable remote desktop, steal local passwords, search user's email, target IFOBS banking systems, install remote desktop programs such as VNC or AMMYY, and also target credit card data by scraping memory on Point-of-Sale systems. In addition to allowing for the remote command of the infected system, the malware also communicates with two encrypted addresses and exfiltrates data to them via HTTP POST messages, using base64+RC2 encryption.

While following a common series of events (the social engineering lure, establishing remote control of victim system and downloading additional tools, conducting reconnaissance on the network to expand foothold, and exfiltrating payment card information and/or personally identifiable information), the campaign shows an unusual level of persistence, professionalism, and pervasiveness.

“The malware used is very multifaceted and still not caught by most (if any) antivirus engines. The social engineering is highly targeted, conducted via direct phone calls by threat actors with excellent English skills. The network reconnaissance and lateral movement is rapid and highly effective. Finally, the data exfiltration methodology is stealthy and efficient,” Trustwave researchers say.

Disgruntled Gamer 'Likely' Behind October US Hacking: Expert

The hacker who shut down large parts of the US internet last month was probably a disgruntled gamer, said an expert whose company closely monitored the attack Wednesday.

Dale Drew, chief security officer for Level 3 Communications, which mapped out how the October 21 attack took place, told a Congressional panel that the person had rented time on a botnet -- a network of web-connected machines that can be manipulated with malware -- to level the attack.

Using a powerful malware known as Mirai, the attacker harnessed some 150,000 "Internet of Things" (IoT) devices such as cameras, lightbulbs and appliances to overwhelm the systems of Dynamic Network Services Inc, or Dyn, which operates a key hub in the internet, according to Drew.
The so-called distributed denial of service attack jammed up traffic routing the Dyn's servers to major websites like Amazon, Twitter and Netflix for hours before the attack could be overwhelmed.
"We believe that in the case of Dyn, the relatively unsophisticated attacker sought to take offline a gaming site with which it had a personal grudge and rented time on the IoT botnet to accomplish this," he said.
Drew did not identify the gaming site but The Wall Street Journal, citing people familiar with the attack, said it was the PlayStation network.
At the time, there were worries that a foreign government might have been behind the attack.

Drew said the ability of hackers to make use of mundane home electronics to mount such an attack signalled a huge new risk in the global internet circuitry.
He said IoT devices often have easily hackable passwords, including hard-wired passwords that owners cannot change.

"IoT devices also are particularly attractive targets because users often have little way to know when they have been compromised. Unlike a personal computer or phone, which has endpoint protection capabilities and the user is more likely to notice when it performs improperly, compromised IoT devices may go unnoticed for longer periods of time."
He noted that such devices are widespread around the world, including in areas with few cybersecurity protections, and that the October attack made use of "just a fraction" of those available. Mirai, he said, has infected nearly two million devices connected to the internet.

"The current lack of any security standards for IoT devices is certainly part of the problem that ought to be addressed."

Young Belgian Cyber-Patrollers Trained to Fight Online Hate

Belgium is training young people as cyber-pat-rollers in a government-backed campaign aimed at combating hate speech as Europe sees a surge in online abuse.

The NO Hate campaign chose 31 people aged between 18 and 35 to be trained as internet activists, speaking out against online bullying and harassment as part of an anti-discrimination and anti-radicalization program supported by the Council of Europe.
"Young people are exposed more and more to hate speech on the internet -- not only racist remarks, but also sexist and generally discriminating ones," says Isabelle Simonis, Belgium’s minister of social advancement, youth, women’s rights and equality, who spearheaded the project.

"Perhaps that’s where radicalization starts," she tells AFP.
Simonis says the idea is to "train young people to be able to act directly on the web" when they are confronted with hate speech.
The campaign has particular resonance in Belgium, which is still reeling from Islamic State-claimed suicide attacks at Brussels' airport and a metro station in March, and which was the base for last year's Paris attacks.
But the scheme targets all kinds of hate speech following months of virulent social media abuse during Britain's bitterly fought Brexit campaign as well as a bruising US election race, which was won by Donald Trump.

'Incitement to hatred'
Florian Vincent, 19, is one of the cyber-patrollers. "We don't have a strategy as such, and we’re not employees. It's not fixed work," he explains.
"If we see hate speech while we’re browsing the internet, we are trained to respond to it."
Vincent says the job of a cyber-patroller is to counter hate speech in whatever context, "whether it's an ordinary person posting something on Facebook or if it's on a politician's or a celebrity's website".

Cyber-patrollers are trained to use facts to verify what online harassers may be saying.
He has already put his training to work with a woman who was spouting aggressive anti-refugee sentiment on Facebook.
"I said that she had the right to have her own opinion, but sometimes the way in which she expressed it was an incitement to hatred and that some of her statistics were wrong," he explains.

"It’s really about making people who are using hate speech understand that there are alternative and better ways of expressing their point of view," he adds.
According to Unia, an independent Brussels-based organization that promotes equal opportunities, there were 365 reported instances of hate speech in 2015. Of that number, 92 percent were online, and 126 of them occurred on Facebook and Twitter.
'Not all a joke'

Online threats are not only becoming more common, but they are also becoming more serious. In 2010, there were only 36 serious cases of harassment on social media that were reported to Unia.
By 2015, the number had increased nearly fourfold to 126.
Simonis says the program isn't designed to create an internet police force.
"It's for reinforcing a sense of citizenship amongst young people," she says.
"I want as many young people as possible to be discerning when online and capable of convincing and educating others."
The Belgian government plans to extend the training to minors, although cyber-patrollers under the age of 18 would need to have a responsible adult present so they are not alone when dealing with threatening hate speech.
Vincent thinks the project is a valuable tool against discrimination and should be rolled out in schools.
"We need to demystify it, make it clear that online harassment is real harassment," he says.
"Not everything that is said on the internet should be taken as a joke."

Popular Posts

Contact

anmol3886@gmail.com