listen more to learn more.

Thursday, November 24, 2016

Gatak Trojan Continues to Target Healthcare Organizations

Organizations in the healthcare sector continue to be the main targets of the Gatak Trojan, a piece of malware that can steal information and perform backdoor functions, Symantec researchers warn.

Also known as Stegoloader and targeting mainly enterprise networks, Gatak (Trojan.Gatak) has been around since 2011, primarily focusing on organizations in the United States. Spreading through websites that promise licensing keys for pirated software, the malware hasn’t spared international organizations either, and the healthcare sector has suffered the most.

While the majority of the machines infected by this Trojan (62%) are located in enterprise environments, 40% of the top 20 most affected organizations are from the healthcare sector, Symantec says. Previously, however, the threat actors behind the malware have focused on the insurance sector as well.

Gatak spreads bundled with product keys for pirated software, via dedicated websites. The attackers lure victims by supposedly offering product keys for software usually used in professional environments, but the keys don’t work and users end up infected. The legitimate versions of these applications aren’t compromised, since the websites used by attackers aren’t connected with their developers.

Some of the programs used by the Gatak gang as lures include SketchList3D (woodworking design), Native Instruments Drumlab (sound engineering), BobCAD-

CAM(metalworking/manufacturing), BarTender Enterprise Automation (label and barcode creation), HDClone (hard disk cloning), Siemans SIMATIC STEP 7 (industrial 

automation), CadSoft Eagle Professional (printed circuit board design), PremiumSoft Navicat Premium(database administration), Originlab Originpro (data analysis and graphing), Manctl Skanect(3D scanning), and Symantec System Recovery (backup and data recovery).

The malware has two main components: a lightweight deployment module that gathers information on the infected machine and can install additional payloads; and the main module, a fully-fledged backdoor Trojan designed to steal information from the infected computer and achieve persistence.

Gatak authors also use steganography to hide data within image files, and the malware attempts to download a malicious PNG image immediately after installation. The image contains an encrypted message with commands for the Trojan and files to be executed.
The malware also attempts lateral movement in the compromised environments, and researchers noticed that in 62% of cases this occurs within two hours of infection. Researchers believe that this function isn’t automated but carried out manually, while also suggesting that the attackers might not have the resources to exploit all infections immediately or they could prioritize targets.

Most likely, researchers say, the attackers move across an organization’s network by exploiting weak passwords and poor security in file shares and network drives. No evidence of zero-day exploits or sophisticated hacking tools being used has emerged so far, but the attackers were seen infecting computers with other malware, including ransomware and the Shylock (Trojan.Shylock) financial Trojan.

The Gatak threat group is said to be cybercriminal in nature, given the absence of zero-day exploits or advanced malware modules, although they focus on enterprises and their malware has capabilities to support more traditional espionage operations. The attackers are opportunistic, given the distribution method, which shows that they are largely passive, lacking control over who is infected.

It’s also unclear how the attackers monetize on their attacks, but Symantec suggests that they could be selling the personally identifiable information (PII) and other data they manage to exfiltrate from the infected machine. This would also explain their focus on the healthcare, as these records are priced higher than other personal information.
“Healthcare organizations can often be pressurized, under-resourced, and many use legacy software systems that are expensive to upgrade. Consequently, workers could be more likely to take shortcuts and install pirated software. While organizations in other sectors appear to be infected less frequently, the attackers don’t appear to ignore or remove these infections when they occur,” Symantec says.

The security firm notes that Gatak represents a reminder that the use of pirated software can compromise the security of an organization in addition to creating legal issues. It is important for companies to regularly audit the software used on their networks, as well as to educate their employees about the dangers of using pirated or unapproved applications.

Six in Philippines May Face Charges Over Bangladesh Bank Heist Charges

The Philippines said Wednesday it has launched criminal proceedings against six bankers accused of failing to stop the laundering of tens of millions of dollars stolen by cyber-criminals from Bangladesh's central bank.

The electronic thieves in February shifted $81 million from the bank's account with the US Federal Reserve in New York to the Rizal Commercial Banking Corp. (RCBC) in Manila in one of the world's biggest bank heists.

The money was transferred to four accounts at an RCBC branch from where it was funnelled into local casinos, according to regulators who fined the bank a record $21 million in August.

Manila's Anti-Money Laundering Council said it filed a criminal complaint at the justice department against RCBC's retail banking group head at the time, its national sales director and four other bank officials.

"The... respondent officers and employees of RCBC facilitated the suspicious transactions involving the four accounts above, by failing to conduct the requisite investigations and enquiries into the accounts," it read.

The complaint, filed on Friday, also cited the Filipino respondents' alleged "deliberate refusal to know the unlawful origins of the funds".

Justice department prosecutors will decide, based on evidence presented by the money laundering watchdog, whether to file criminal charges in court against the six.
The offense carries a maximum prison term of seven years and fines of up to three million pesos (about $60,000).

No one has been arrested in the Philippines over the heist but the government has recovered about $15 million, some of it from a Manila-based casino operator who has pledged to cooperate with the criminal enquiry.

The recovered funds have been turned over to Bangladesh Bank.

The brazen cyber heist highlighted how the Philippines' banking loopholes have made the corruption-prone nation a dirty money destination.

Philippine law exempts casino transactions from scrutiny by the anti-money laundering council unless a case has been filed in court.

Monday, November 21, 2016

Oracle Buys Cyber Attack Target Dyn

Oracle on Monday announced it is buying Dyn, a Web traffic management firm recently hit with a cyber attack that closed off the internet to millions of users.

Business software and hardware titan Oracle did not disclose financial terms of the deal to acquire US-based Dynamic Network Services Inc, or Dyn.
Oracle planned to enhance its own offerings with Dyn's expertise in monitoring, controlling, and optimizing cloud-based internet applications and managing online traffic.
"Dyn's immensely scalable and global DNS is a critical core component and a natural extension to our cloud computing platform," Oracle product development president Thomas Kurian said in a release.

Dyn was the target of cyber attacks that pounded the underpinnings of the internet in October, crippling Twitter, Netflix and other major websites with the help of once-dumb devices made smart with online connections.

The onslaught incapacitated a crucial piece of internet infrastructure, taking aim at a service entrusted to guide online traffic to the right places by turning website names people know into addresses computers understand.

The hacker was probably a disgruntled gamer, an expert whose company closely monitored the attack said last week.

Dale Drew, chief security officer for Level 3 Communications, which mapped out how the October 21 attack took place, told a Congressional panel that the person had rented time on a botnet -- a network of web-connected machines that can be manipulated with malware -- to level the attack.

Using a powerful malicious program known as Mirai, the attacker harnessed some 150,000 "Internet of Things" (IoT) devices such as cameras, lightbulbs and appliances to overwhelm Dyn systems, according to Drew.

Dyn has more than 3,500 customers including Netflix, Twitter, and CNBC, making tens of billions of online traffic optimizing decisions daily, according to Oracle.

Obama Says NSA Director a 'Patriot,' Looking at Agency's Organization

US President Barack Obama on Sunday refused to say whether he was considering the dismissal of National Security Agency chief Admiral Michael Rogers, but suggested he was looking at how cyber defenses are organized.

"Admiral Rogers is a terrific patriot and has served this country well in a number of positions," Obama said at a press conference in Peru, amid suggestions that key intelligence and defense officials want him to be dismissed after a series of security breaches.

"I generally don't comment on personnel matters here. I can say, generally, that we have spent a lot of time over the last several years looking at how we can organize our cyber efforts to keep pace with how rapidly the environment is changing."

On Saturday, US media reported that top US military and intelligence leaders were pushing Obama to fire Rogers, even as Rogers was apparently being considered for a senior position in President-elect Donald Trump's administration.

US House Intelligence Committee Chairman Devin Nunes has asked Defense Secretary Ash Carter and Director of National Intelligence James Clapper -- the two reportedly behind the push -- to testify before the end of the year.

If Trump nominates Rogers, and he is confirmed by the Senate, he would succeed Clapper as the official who oversees all 16 US intelligence agencies coordinated by the Office of the Director of National Intelligence.

Rogers, who also heads US Cyber Command, has been at the helm of the NSA and its Central Security Service since 2014, in the wake of a massive leak by former intelligence contractor Edward Snowden linked to broad surveillance methods.

Symantec to Acquire LifeLock for $2.3 Billion

Information security giant Symantec said on Monday that it will acquire identity protection firm LifeLock for $2.3 billion. 

Under the terms of the agreement, Symantec will pay $24 per share in a transaction financed with cash on hand and $750 million of new debt. 
LifeLock provides identity and fraud protection services to more than 4.4 million customers. 

While Symantec is shelling out billions to acquire to the leading provider of identity theft protection services, LifeLock has had its share of blemishes over the years.
In March 2010, the FTC slapped LifeLock with a fine of $11 million to settle charges that the company used false claims to promote its identity theft protection services. At the same time, the company agreed to pay $1 million to a group of 35 state attorneys general.

“While LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it,” now former FTC Chairman Jon Leibowitz said at the time.

In late 2015, LifeLock agreed to pay a fine of $100 million after failing to comply with the 2010 federal court order requiring it to secure consumers' personal information and prohibiting deceptive advertising.

Allegations claimed that LifeLock made false claims about protecting the personal information it collects from its customers, including "falsely advertising that it protected consumers' sensitive data with the same high-level safeguards as financial institutions."
As part of its marketing campaigns, LifeLock would often post the Social Security number of its CEO at the time Todd Davis in its advertisements—a show of confidence that the company’s service can protect consumers who may have had their private information exposed, including Social their Security numbers.  However, according to the Phoenix New Times, Davis had been a victim of identity theft at least 13 times.

Despite past issues at LifeLock, Symantec believes the LifeLock service can be a valuable addition to its consumer-focused security offerings.

Symantec CEO Greg Clark said the acquisition would allow it to bundle Symantec’s Norton security software with LifeLock’s protection service. “This acquisition marks the transformation of the consumer security industry from malware protection to the broader category of Digital Safety for consumers,” Clark said in a statement.

“People’s identity and data are prime targets of cybercrime.  The security industry must step up and defend through innovation and vigilance,” said Dan Schulman, Symantec’s Chairman of the Board. “With the acquisition of LifeLock, Symantec adds a new dimension to its protection capabilities to address the expanding needs of the consumer marketplace.”

The transaction is subject to the satisfaction of customary closing conditions, including regulatory approval in the United States and LifeLock stockholder approval.

Mozilla Launches Privacy-Focused Browser for iOS

Mozilla this week released Firefox Focus for iOS, a privacy-focused web browser that gives users an increased level of privacy when browsing the Internet from their smartphones and tablets.

Regardless of whether browsing the web on their computers or on their mobile phones, users are exposed to numerous threats, including many privacy risks. With Firefox Focus, Mozilla attempts to tackle these privacy threats by helping users easily erase traces of their browsing sessions from their iOS devices or block online trackers.
The new application is expected to provide a fast, free, and easy-to-use browsing experience that will put users in control of how their online activities are tracked on their devices. By default, Firefox Focus will block ad, analytics, social and various other trackers that follow users on the web, all without having to change their privacy or cookie settings.

On top of that, the new browser allows users to easily erase their browsing sessions, all with a tap of a button. When searching for information that could prove sensitive in certain situations, regardless of whether it involves engagement rings, flights, or specific merchandise, while also looking to leave no trace on the device, users will be able to erase the session by taping a prominent “Erase” button conveniently placed directly on the screen, in the upper right-hand corner.

“By putting the “Erase” button front and center, we offer users a simple path to healthy online behaviors — protecting their online freedom and taking greater control of their personal data. To further enhance user privacy, Firefox Focus also by default blocks advertising, social and analytics tracking. So, on Firefox Focus, “private” browsing is actually automatic, and erasing your history is incredibly simple,” Mozilla’s Denelle Dixon-Thayer notes in a blog post.
According to Mozilla, because the technology used to track users on the web is blocked in Firefox Focus, users will experience a performance boost when browsing the web, because these trackers can significantly slow down pages. However, because there might be sites that depend on tracking and won’t work without it, the app will allow users to easily open the site in either Firefox or Safari.

“Firefox Focus continues to operate as a Safari content blocker on iOS, and users will be able to take advantage of Tracking Protection on both Safari and Firefox Focus,” Mozilla also says.

Sunday, November 20, 2016

Pentagon, Intelligence Leaders Seek NSA Chief's Removal: Reports

Top US military and intelligence leaders are pushing President Barack Obama to fire National Security Agency chief Admiral Michael Rogers, US media reported Saturday, even as Rogers is apparently being considered for a senior position in the Trump administration.

House Intelligence Committee Chairman Devin Nunes has asked Defense Secretary Ash Carter and Director of National Intelligence James Clapper -- the two reportedly behind the push -- to testify before the end of the year.

President-elect Donald Trump was said to be considering Rogers as director of national intelligence in his incoming administration.

If Trump nominates Rogers, and he is confirmed by the Senate, he would succeed Clapper as the official who oversees all 16 US intelligence agencies coordinated by the Office of the Director of National Intelligence.

Rogers, who also heads US Cyber Command, has been at the helm of the NSA and its Central Security Service since 2014, in the wake of a massive leak by former intelligence contractor Edward Snowden linked to broad surveillance methods.

His decision to meet with Trump on Thursday at Trump Tower shocked senior administration officials, according to The Washington Post, which first reported that Clapper and Carter were seeking his ouster.

Carter has been dissatisfied with Rogers' performance at the NSA during a time that saw major security breaches, including that revealed last month by Booz Allen Hamilton contractor Harold Martin III, who is accused of having orchestrated the largest theft of classified government material.

The Post said there was also a second, previously undisclosed breach that was uncovered in 2015 by an employee of the NSA's Tailored Access Operations. The suspect has been arrested.

Clapper, meanwhile, is seeking a separation of leadership roles at the NSA and US Cyber Command, and wants the NSA to be headed by a civilian.
In his letter to Clapper and Carter, Nunes -- who is from Trump's Republican Party -- defended Rogers, saying he has been "consistently impressed with his leadership and accomplishments."

"His professionalism, expertise and deckplate leadership have been remarkable during an extremely challenging period for NSA. I know other members of Congress hold him in similarly high esteem," Rogers added.
He expressed concern that the Post article may contain "unauthorized disclosures of classified information."

And "any decision to end the dual-hatting relationship between NSA and USCYBERCOM should prompt a further review of NSA's organization," Nunes added.
Pentagon spokesman Peter Cook declined to comment on the reports.
*Updated

Popular Posts

Contact

anmol3886@gmail.com