Archive for July 21, 2023

INKY Fresh Phish Details A New HTML Smuggling Phish Kit

Posted in Commentary with tags on July 21, 2023 by itnerd

INKY has published a Fresh Phish talking about a new HTML Smuggling Phish Kit that their researchers discovered. 

Attack Flow Overview:

  • Origin: Hijacked accounts and Freemail users
  • Payload:  HTML attachments 
  • Techniques: Credential harvesting, HTML smuggling
  • Target: Microsoft account holders

You can read it here.

Tampa General Hospital Pwned… 1.2 Million Patients Affected

Posted in Commentary with tags on July 21, 2023 by itnerd

According to a notice posted this week on the hospital’s website, Tampa General Hospital stated that it discovered a cyberattack on May 31st.  They say the attackers were in their network for three weeks and that the breach affects approximately 1.2 million patients.

Stolen patient information varied but may have included names, addresses, phone numbers, dates of birth, SSNs, health insurance information, medical record numbers, patient account numbers, dates of service and limited information about treatment.

The hospital’s statement did not name the attackers, but DataBreaches reported that the Snatch Ransomware gang had added the hospital to its leak site, and claimed they had acquired 4 TB of the hospitals files.Meanwhile, the hospital’s notice said that their security team had been able to prevent the encryption of any of their files but did not mention a ransom demand.

Al Martinek, Customer Threat Analyst at Horizon3.ai had this to say:  

“Cyber threat actors do not typically use sophisticated hacking tools and techniques like zero-day exploits to gain access to a network; most often, they simply log in with legitimate user credentials gleaned from previous data breaches. According to CrowdStrike, 62% of all detections indexed by the fourth quarter of 2021 were malware-free – meaning attackers were “living off the land,” using legitimate credentials and built-in tools to evade detection instead of sophisticated malware.  

“Nefarious actors exploit credentials in many ways. They can:

  • Take advantage of weak password strength requirements or weak account lockout thresholds
  • Capture and then crack hashes
  • Take advantage of accounts that reuse compromised credentials
  • Use the default credentials that remain unchanged in a variety of web applications and systems processes

   “Some threat actors even go so far as to buy cleartext credentials available on the dark web. Once they gain initial access, they then appear as legitimate users and can move laterally within a network to gain further access and establish persistence, steal sensitive data, bring down systems, and/or hold the organization hostage through ransomware.”

Ani Chaudhuri, CEO, Dasera follows up with this:

First and foremost, it is crucial to acknowledge the immense challenge hospitals like Tampa General and the healthcare industry face in safeguarding sensitive medical information amidst the relentless barrage of external and internal threats. The recent breach is a stark reminder of the complexities in ensuring robust patient data security across the board. However, it is essential to recognize that this challenge extends far beyond the healthcare sector, as data breaches have become a pervasive issue faced by companies worldwide. From multinational corporations to small businesses, organizations of all sizes and industries grapple with the daunting task of securing sensitive data in the face of increasingly sophisticated cyber threats.

Securing healthcare data requires a comprehensive and multifaceted approach considering the ever-evolving technological vulnerabilities and the persistent threats cybercriminals pose. Hospitals like Tampa General are responsible for protecting patient confidentiality and must invest in robust security measures to prevent unauthorized access.

While we await further details regarding the breach, it is evident that the unauthorized party gained access to a substantial amount of personal information, including Social Security numbers, addresses, and medical records. This breach exposes patients to the risk of identity theft and financial fraud and undermines patients’ trust and confidence in the hospital’s commitment to data security.

In light of this breach, all affected individuals should protect themselves immediately. Monitoring financial accounts closely, reviewing credit reports regularly, and remaining vigilant for any suspicious activity is crucial.

Tampa General Hospital and healthcare organizations worldwide must use incidents like this as catalysts for change. Learning from such breaches and proactively enhancing data security practices is vital. Cybersecurity requires continual investment in advanced technologies, comprehensive training programs, and stringent security protocols.

Let us view this unfortunate event as an opportunity for growth and improvement, reinforcing the critical importance of safeguarding patient data. We should work together to build a more resilient healthcare ecosystem that prioritizes the privacy and security of every individual’s sensitive information.

Healthcare is an easy target for threat actors as they are often resource constrained when it comes to defending against cyber threats. That has to change as this event, and ones like it are far from trivial given the damage that they cause to those affected.

Estee Lauder Appears To Have Been Pwned By TWO Ransomware Groups

Posted in Commentary with tags on July 21, 2023 by itnerd

Earlier this week, Estee Lauder published a statement that it suffered an apparently serious ransomware breach, after both the Alphv/BlackCat and Clop ransomware gangs claimed to have compromised the cosmetic giant.

Cybersecurity analyst/ researcher Dominic Alvier posted screenshots to twitter  of the leak sites of both gangs that appear to have gone live on Tuesday July 18th.

Estee Lauder said it was focused on remediation and warned that the incident would cause disruption to its operations.

After becoming aware of the incident, the company proactively took down some of its systems and promptly began an investigation with the assistance of leading third-party cybersecurity experts.“[…] the company believes the unauthorized party obtained some data from its systems, and the company is working to understand the nature and scope of that data,” the statement said.

On Tuesday, BlackCat added Estée Lauder to their list of victims with an irritated message towards the company’s silence to their extortion emails:“We first wrote to the ELC leadership on 15 July 2023 to their corporate and personal emails. We sent further emails from the same address, but received no reply,” said the BlackCat ransomware group.

Carol Volk who is a BullWall executive had this comment:  

“What’s to prevent multiple Ransomware groups from claiming an attack and seeking payoffs? With no visibility into this type of slow-motion extortion, companies can only improve their defense posture and have a solid after-action plan for restoring their data. The last line of defense is containment, shut down and restoration.”

Brad Hong, Customer Success Lead, Horizon3.ai follows up with this:  

“This is one of the most interesting developing case studies of recent ransomware history–two individual ransomware groups, uncoordinated, managed to get into a brand name enterprise company at the same time. Initial reports indicate that they did not hack into ELC’s infrastructure from the same attack vector.  

“While it might seem obvious that the moral of the story is to patch highly exploited vulnerabilities, like MOVEit, as a priority, it’s unfortunately common place to see organizations pigeonholed on the wrong things, and if not this threat actor, then the next one could be successful if limited only to their imagination.  

“This only emphasizes the need to continuously validate the strength and extent of security through offensive techniques. At the end of the day, APTs are groups of humans too, and their techniques change as they adapt to the rest of the world. Defending against one group doesn’t grant you blanket defense against another. While it would’ve been valuable to patch the suspected exploited MOVEit instance at ELC, testing the true blast radius of this highly warned vulnerability, by continuously running find-fix-verify loops from the attacker’s perspective, ELC, like any organization, would have a much better understanding of the totality of potential paths to impact.”

Now that multiple ransomware groups appear to be using the same exploit (in this case MOVEit) to pwn companies, a world that was already dangerous has become even more dangerous. Which means that taking the right action to protect yourself is even more important.