Archive for June 15, 2023

Reddit Is Down Again…. Who Will They Blame This Time?

Posted in Commentary with tags on June 15, 2023 by itnerd

It seems that Reddit who has lots of issues at the moment is down. Again. Here’s the view from Down Detector:

The question is, who is Reddit going to blame for this outage this time? During the outage that happened earlier this week, Reddit blamed the API protests. What’s their excuse this time?

Hackers Utilize Legitimate PDF Editing Tool in Latest BEC Attack for Financial Gain

Posted in Commentary with tags on June 15, 2023 by itnerd

Today, researchers at Avanan, a Check Point Company published their latest blog post discussing how hackers are sending messages directly from Soda PDF, a popular PDF editing tool commonly seen in BEC 3.0 attacks, to send emails that encourage users to call a phone number, where money will be attempted to be stolen. 

In this attack, an email is sent directly via Soda PDF as an invoice, and contains a download link that goes directly to Soda PDF. In hopes of extracting finances, hackers provided a number for the end-users to call if they believed there had been an error. Calling the number not only leads victims to provide credit card information, but also saves the telephone number for future scams. 

You can find the blog post here: https://www.avanan.com/blog/using-legitimate-pdfs-for-bec-3.0-attacks?hs_preview=ZFbmDiTP-119400800417

New Hacker-Built AI-Powered Security Testing Automatically Identifies Software Defects Before Code Ships

Posted in Commentary with tags on June 15, 2023 by itnerd

ForAllSecure, a hacker organization focused on advancing cybersecurity through research and education, announced Mayhem, an application security platform that addresses not only present challenges but also those that lie ahead.

Mayhem by ForAllSecure revolutionizes security testing – built to deliver easy, comprehensive, actionable application security to developers worldwide. The Mayhem UI comprehensively shows results across application code and APIs.

Built by professional hackers, Mayhem automatically generates thousands of tests to identify defects in apps and APIs, solving critical software vulnerabilities before the code ships for organizations’ application, API, and code security. 

You can read a blog post here: https://www.mayhem.security/blog/introducing-mayhem-security.

Their site is offering the option to download and use the free version of the product now at https://www.mayhem.security/

And you can watch a video below:

The GuidePoint Research and Intelligence Team’s (GRIT) Ransomware Report Is Out For May

Posted in Commentary with tags on June 15, 2023 by itnerd

GuidePoint Security has published the monthly GuidePoint Research and Intelligence Team’s (GRIT) Ransomware Report for May, which found several new branded groups entering the scene, contributing to a cumulative rise in the number of observed ransomware victims.

Key findings include:

  • Four new ransomware groups observed, which claimed 67 victims in the past year and represent nearly 18% of the victim posts observed in May
  • 28 observed groups reporting victims this month with a 13.57% increase in total affected organizations
  • An unusual correlation between two groups that were previously considered unrelated
  • Among the most frequently impacted industries, the most active groups were Lockbit, Alphv, and BianLian

You can read the report here.

Romanian Hackers Resurge with DDoS Botnet, Doxxing, Cryptojacking in Attack Arsenal

Posted in Commentary with tags on June 15, 2023 by itnerd

Cado Security has revealed the discovery of brute-forcing malware payloads, which didn’t have any public reporting and were missing from common repositories, being used as part of a new campaign by Romanian hacking group, Diicot, formerly known as Mexals.

Artifacts from the group’s campaigns contain messaging and imagery related to the Romanian organized crime and anti-terrorism policing unit, a vital significance, given both groups are named Diicot. Combined with Romanian-language strings and log statements in the payloads, Cado researchers attribute the malware to Diicot. 

Cado Labs discovered evidence of the group deploying an off-the-shelf Mirai-based botnet agent named Cayosin, targeted at routers running the Linux-based embedded devices operating system, OpenWRT. An investigation of one of Diicot’s servers led to the discovery of a Romanian-language doxxing video depicting a feud between the group and what appears to be other online personas. 

This report will provide a brief overview of attributing the campaign to Diicot’s distinctive TTPs, along with the execution chain employed by the group in their latest campaign, before focusing on the newest version of their self-propagating SSH brute-forcer. Cado researchers identified four channels used for this campaign and confirmed that the campaign is recent and ongoing.

You can view the report here.

Illinois Hospital Shutting Down In Part Due To A Ransomware Attack In 2021

Posted in Commentary with tags on June 15, 2023 by itnerd

St. Margaret’s Health is shutting down two hospitals and three clinics after suffering a ransomware attack in 2021.  The attack kept their network down for three months and prevented them from billing insurers, Medicaid or Medicare for months. The hospitals include St. Margaret’s Hospital in Spring Valley and Illinois Valley Community Hospital in Peru.

“You’re dead in the water,” said Linda Burt, vice president of quality and community service at St. Margaret’s Health. We were down a minimum of 14 weeks. And then you’re trying to recover. Nothing went out. No claims. Nothing got entered. So it took months and months and months.”

The ransomware attack occurred in February of 2021, shutting down the spring valley hospital computer network and ceasing all web-based operations, including the patient portal. The branch in Peru was not affected because they were on a separate network. Unfortunately, the extended shutdown of Spring Valley combined with the impact from COVID-19 and staff shortages has forced St. Margaret’s health to sell the Peru branch to help pay for expenses incurred in the attack as well as shutting down multiple clinics in the area.

Both the Spring Valley and Peru facilities will shut down on the June 16th.

Amit Patel, SVP, Cyware had this to say: 

   “This is a stark reminder of the worst-case scenario for a small healthcare organization. Without enough resources to invest in robust security, updated systems, and having a clear recovery plan, these important local healthcare resources can easily be put out of business, directly impacting their patients. 

    “This is an industry-wide problem, yet we keep expecting our weakest links to defend themselves. We have to invest in systems to share intelligence, security best practices, and critical alerts across the industry quickly, reliably, and automatically.”

It’s cheaper to have the means to prevent an attack like this than to respond to it. While this is the worst thing that I have heard of, it won’t be the last I fear. Thus I hope it serves as an example to get yourself into a position where you are less likely to be the victim of an attack like this.

Fake Cyber Researchers Publish 0-day PoC’s to Push Malware

Posted in Commentary with tags on June 15, 2023 by itnerd

Since May, VulnCheck has observed hackers on Twitter and GitHub pretending to be cybersecurity researchers from ‘High Sierra Cyber Security’ and publishing fake PoC exploits for zero-day flaws in software like Chrome, Discord, Signal, WhatsApp, and Microsoft Exchange that infect Windows and Linux with malware.

Impersonators promote the GitHub repositories on Twitter and social media accounts that appear legitimate, with the users impersonating real security researchers from Rapid7, and other security firms, even using their real headshots.

In all cases, the malicious repositories host a Python script that acts as a malware downloader dropping a ZIP archive from an external URL to the legit cyber researcher’s computer.

While the success of this campaign is still unknown, VulnCheck notes that the threat actors are persistent, creating new accounts and repositories when the existing ones are reported and removed.

Avkash Kathiriya, SVP of Research and Innovation, Cyware had this to say:

   “Researchers, like the rest of us, need to take zero trust seriously. It’s worth repeating these security 101 tenets: Don’t download questionable files from GitHub. Don’t install any sample malware in a system that is not isolated. Don’t trust what you see on Twitter. If you spend all day researching threats and scam techniques, don’t be surprised when you become the target.”

This advice can be boiled down to safe computing 101. Everyone needs to follow this advice to ensure that we don’t get pwned by a threat actor. And that includes defenders who are trying to get ahead of threat actors.

SpaceCobra group goes after WhatsApp backups using Android spyware GravityRAT: ESET

Posted in Commentary on June 15, 2023 by itnerd

ESET researchers have identified an updated version of the Android-based GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico. GravityRAT is a remote access tool previously used in targeted attacks against users in India. Windows, Android, and macOS versions are available. The actor behind GravityRAT remains unknown; ESET Research tracks the group known as SpaceCobra. Most likely active since August 2022, the BingeChat campaign is still ongoing. In the newly discovered campaign, GravityRAT can exfiltrate WhatsApp backups and receive commands to delete files. The malicious apps also provide legitimate chat functionality based on the open-source OMEMO Instant Messenger app.

Just as in previously documented SpaceCobra campaigns, the Chatico campaign targeted a user in India. The BingeChat app is distributed through a website that requires registration, likely open only when the attackers expect specific victims to visit, possibly with a particular IP address, geolocation, custom URL, or within a specific timeframe. In any case, the campaign is very likely highly targeted.

ESET Research does not know how potential victims were lured to, or otherwise discovered, the malicious website. Considering that downloading the app is conditional on having an account and new account registration was not possible during the investigation, ESET believes that potential victims were specifically targeted.

The group behind the malware remains unknown, even though Facebook researchers attribute GravityRAT to a group based in Pakistan, as previously speculated by Cisco Talos. ESET tracks the group under the name SpaceCobra, and attributes both the BingeChat and Chatico campaigns to this group.

As part of the app’s legitimate functionality, it provides options to create an account and log in. Before the user signs into the app, GravityRAT starts to interact with its C&C server, exfiltrating the device user’s data and waiting for commands to execute. GravityRAT is capable of exfiltrating call logs, contact list, SMS messages, device location, basic device information, and files with specific extensions for pictures, photos, and documents. This version of GravityRAT has two small updates compared to previous, publicly known versions of GravityRAT: exfiltrating WhatsApp backups and receiving commands to delete files.

For more technical information about SpaceCobra and the latest campaign with Android GravityRAT, check out the blogpost “Android GravityRAT goes after WhatsApp backups” on WeLiveSecurity.

Cyware Launches New Global Partner Program

Posted in Commentary with tags on June 15, 2023 by itnerd

Cyware, the leading provider of threat intelligence management, low-code SOAR, and Cyber Fusion solutions for enterprises and MSSPs/MDRs, and threat intelligence sharing communities, today announced the launch of its new Partner Program, CywareOne.

The program aims to grow the partnership between Cyware and its channel and managed security (MSSP/MDR) partners, allowing them to leverage Cyware’s advanced threat intelligence automation, security advisory sharing, low-code vendor-agnostic SOAR, and cyber fusion technologies to deliver exceptional cybersecurity solutions for their clients. This launch comes at a time when globally renowned cybersecurity providers including GuidePoint Security, Ernst & Young, Optiv, Morado, SHI, and others have partnered with Cyware to deliver reliable and robust cybersecurity solutions, enabling organizations to defend effectively against advanced cyber threats.

The CywareOne program offers extensive benefits to partners, including comprehensive training programs, dedicated support, co-marketing opportunities, and competitive discounts. It streamlines the rules of engagement and opportunity management while ensuring the highest level of trust and transparency. These benefits aim to empower Cyware’s partners with the necessary skills and resources to effectively address their clients’ cybersecurity concerns.

Through CywareOne, Cyware aims to create a thriving community of partners united by their commitment to cybersecurity excellence. The program’s launch represents the latest initiative from Cyware in its mission to protect businesses from cybersecurity threats.