Google Remove 9 Malware Infections From Play Store

Malware’s primary obstacle when it comes to mobile devices has always been the infection vector – The act of physically placing itself on a device. Hackers have come up with novel, clever, and complex ideas in the past. None of these have ever been as successful as using a Dropper. An attack using droppers can go unnoticed for quite some time, as was the case with Google as they removed 9 apps from the app store recently. Each app was a host for Malware, issued by a dropper dubbed Clast82.

Droppers are nothing new; they have been active on PCs for many years, though lately have made the mobile market their new home. A dropper will first appear as a normal app with everyday use. This could be a calculator app, a fitness tracker, a media player, or just about anything. The hacker will develop a completely legitimate app to build trust with the community and with Google Play.

Google Play has several strict policies to ensure that apps are legitimate, so building trust is critical for a dropper to succeed.

Once this trust is built, the dropper becomes active. A backdoor will open within the app and change the underlying code, turning it from a seemingly innocent utility to fully-fledged Malware. This bait-and-switch attack vector has sometimes been called a Quasi-Trojan; Like a trojan, it masks a more serious payload. Unlike a trojan, that payload is not present until the hacker decides to activate the backdoor.

The 9 apps removed from the Play Store had some devastating functionality when activated, capable of gaining intrusive access to the financial accounts of victims and full control of their devices.

Clast82 deployed AlienBot Banker and Rogue onto devices that held any of the apps. AlienBot Banker is malware that focuses on harvesting banking credentials from a mobile device. It does this by injecting malicious code into banking apps found on the device, allowing the hacker to take control.

Rogue is an MRAT (Mobile-Remote-Access-Trojan). Rogue generally allows the hacker to control all aspects of the phone and spy on users’ inputs.

The 9 apps that were removed are Cake VPN, Pacific VPN, eVPN, BeatPlayer, QR/Barcode Scanner MAX, Music Player, tooltipnatorlibrary, and QRecorder.

Methodology

 

Malware

 

Clast82 used two primary techniques to bypass Google Plays detection and to upload Malware to the users device.

Firstly, it used FireBase as a platform for Command-And-Control (C&C).

Secondly, it used GitHub as a 3rd party hosting platform to download the payload from.

During Google Plays evaluation period of the apps, the configuration from the Firebase C&C contains an ‘enable’ parameter. Based on the value of the parameter, the malware will decide to trigger malicious behavior or not. During the evaluation, the parameter will be false. Once the period has finished and Google publishes the app, the parameter will change to true.

 

Malware

 

“Disabled” configuration sent from the Firebase C&C

 

Malware

 

Cybersecurity researchers investigating the hackers github uncovered revealed they had created a new developer account for each app, along with different payloads of each of the 9 apps. This allowed them to deploy varied payloads as desired to each app.

 

Malware

 

Hackers Git Repo

With this system in place, an attack followed 5 steps:

  1. Hacker Uploads To Google Play.
  2. Googles’ evaluation is met with a False parameter at the Firebase C&C – No malware is present.
  3. Google approves the app.
  4. Victims install apps, which contacts the Firebase C&C. The parameter changes from False to True.
  5. The device contacts the hackers Github and begins downloading Malware, unbeknownst to the user.

It is believed that the legitimacy of the apps as they were approved stems from the hacker using open-source libraries to develop the apps, effectively doing custom paint jobs on publicly available app source codes.

The Play Store as the Primary Attack Vector For Malware

 

Malware

 

A study in 2019 shed light on hackers using the Play Store as an attack vector Malware. It was found that the Play Store was infact the largest carrier for Malware on Android systems, and found that 67% of malicious apps came from Google’s Play Store. This number debunks the theory that third-party app stores such as Aptoide and APKMirror were harbingers of malware apps – These stores accounted for just 10% of malicious payload deliveries.

The same study analyzed 34 Million app installations for 7.9 Million unique apps. It found that between 10% and 24% of the apps analyzed contained some form of unwanted Malware.

These attacks are making the headlines more frequently it seems.

In February 2020, Google removed 56 apps from the Play Store, which infected 1.7 Million devices with Malware. July 2020 saw the rise of the Joker Malware on the Play Store, a devastating phishing program. PhantomLance, a notorious mobile Spyware platform, successfully carried out a 5-year campaign on the Play Store, which was just discovered a few months ago.

What You Can do For Protection

Protection against Droppers like Clast82 can be tricky because in most cases the user is unwillingly inviting Malware onto their device. As is the case with most forms of cybersecurity defense, knowledge is your key weapon.

When downloading an app from the Play Store, don’t hit ‘Install’ without taking some precautionary steps:

  • Research the developer. Do they seem legitimate?
  • Read the reviews. Remember that sometimes hackers will leave fake reviews – Be aware of this, and use your intuition.
  • Read the permissions before you download. If you feel uncomfortable giving an app as much access as it requests, don’t download!

Along with these steps, users should use the proper security tools to ensure their device is safe. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Hackers Strike Millions of Flyers in Attack That Affects 90% of the Global Aviation Industry

 

Hackers have carried out a large data breach on SITA, an IT Software Supply company that serves 90% of the global aviation industry. SITA confirmed that in late February that its US-based database, which contains information regarding frequent-flyers, was compromised by hackers. Airlines share information regarding frequent-flyers through SITA software, leading to the personal information of millions of customers being exposed.

The breached servers were a part of the. SITA Passenger Service System (SITA PSS).

SITA has stated that each of the affected airlines have been briefed on the breach. Some of the companies who have made public statements about the attack are United, British Airways, Singapore Airlines, and Finnair.

SITA have not revealed details of the attack vector taken by hackers, nor has it disclosed the exact type of data exposed in the attack. Many airlines have issued public statements confirming what types of data have been affected in relation to their passengers.

Company spokesperson Edna Ayme-Yahil stated “SITA PSS was holding the data of airlines that are not its direct customers, but are alliance members, because other airlines that are SITA PSS customers have an obligation to recognize the frequent flyer status of individual passengers and ensure that such passengers receive the appropriate privileges when they fly with them. That obligation arises from the contractual commitments that the other airline has agreed in its contractual arrangements with an alliance organization. It is common practice for alliance members to recognize the frequent-flyer scheme tiers of the passengers they carry. This mandates the sharing of frequent-flyer data amongst alliance members and, consequently, the service providers to those alliance members (such as SITA).”

Hackers See Airlines As Tempting Targets


Hackers

Airlines have long been tempting targets for hackers. The aviation and aerospace industry is involved in cyberattacks frequently due to the personal information they hold in their servers and the lack of priority on company cybersecurity.

In particular, privilege escalation and SQL-injection vulnerabilities are weak points for the industry, account for 57% of the vulnerabilities highlighted to companies by ethical hackers.

The last 12 months have devastating for airlines globally, as they shift focus to simply surviving the Pandemic and staying in business. Hackers are aware of this shift and have turned more of their attention toward airlines to exploit vulnerable systems.

Airlines are a digital-first business and have many legacy systems in place. If there is no priority on maintaining these, they often become rife with exploits as they become out-of-date.

Vulnerabilities in the Software Supply Chain


Hackers

The SITA attack is just another in a long list of attacks on the third-party software supply chain. Notably 2020, the SolarWinds breach was reported on by SaferNet, while in 2021, we have seen the Accellion File Transfer Appliance breach.

Third-party software supply chains are often the weakest link in an organization and so are targeted by hackers. While a company may have tight security control, a third-party vendor may not. This can act as a doorway for hackers to breach internal systems.

Ran Nahmias, co-found of Cyberpion explains, “The proliferated effect of the attack on SITA is yet another example of how vulnerable organizations can be solely on the basis of their connections to third-party vendors. If these kinds of seemingly legitimate connections are not properly monitored and protected, they can result in damaging breaches that unleash highly confidential data, as evidenced in this situation.”

The responsibility is on IT teams to correctly vet third-party vendors. Going forward, software supply chain breaches will become more common, and company leaders must become more vigilant in scrutinizing their security.

Securing Enterprise Systems

Small businesses can use a number of tools to tighten their cybersecurity. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Point Of Sale Malware: The Silent Virus Gripping Retail

Malware can affect any device, and point-of-sale (POS) devices seen in retail are no exception. POS devices are used to finalize a retail transaction, with a customer either swiping or tapping a card and now oftentimes using Apple Pay or Google Pay with their phone. POS devices are used globally, though the trend of customers opting to pay this way is most widespread in the United States.

For the most part, POS devices are not single units; rather, they are a periphery connected to a computer within the retail unit. Most commonly, these computers Windows or UNIX systems connected to the Internet. This interaction is the most frequently seen in the POS world, though modern developments have led to dongle POS readers, wireless transmitters, and more.

The goal of POS Malware is to intercept the card details and wire them back to a hacker. There are several methods used to accomplish this. As card security has advanced, hackers have developed more sophisticated methods to capture details.

The set of security standards used by the payment industry globally assures that most rudimentary Malware attacks are shut down. The key to these standards is enforcing end-to-encryption within the card’s magnetic strip or chip to protect against man-in-the-middle attacks. When a card interacts with the POS device, all its details are encrypted initially. Decryption will only occur in the POS device random-access-memory (RAM).

One of the most common methods for Malware to use here is RAM Scraping. In this case, a POS device is infected with a silent Remote Access Trojan (RAT). The RAT will read the data that is being processed by the RAM and upload it back to the hackers’ server.

RAM Scraping leaves little to no footprints on a system and allows hackers to build a database of potentially millions of credit card credentials without being detected. These credentials can have many uses to a hacker; Most often, they are all sold in blocks on the Dark Web for financial fraud and identity theft.

When card credentials are stolen in this way, it can be difficult to trace it back to the source, or even the location they were stolen from. Like many forms of data harvesting in the cybercrime world, the victim may not be impacted until months, or years have passed. POS Malware is a silent virus in the world of retail, and its future is promising for cybercriminals. There have been many different strains of Malware affecting POS devices, today we look at some of the most destructive ones.

Dexter Malware

 

Malware

Primary Victims: Restaurants, Convenience Stores

Dexter was one of the first major POS Malware strains found in a campaign that affected POS devices globally in 2012, though the attacks were centered on the US.

Dexter was reported in 40 countries in total and affected POS devices connected to Windows systems. Researchers found that card details were sent to the hackers’ command-and-control center (C&C) in Seychelles.

The Dexter malware sends a list of processes running on infected systems to the C&C server. The attackers then check whether any of those processes correspond to specific PoS software and if they do, they instruct the malware to dump their memory and upload the data back to the server.

The memory dumps are then parsed with an online tool that runs on the server and can extract payment card data from them. This is the information written on the magnetic stripes of payment cards and can be used to clone them.

Dexters’ main victims were restaurants and convenience stores, and at one point had siphoned the details of 20,000 credit cards. In 2013, Dexter was rewritten as StarDust, which is still active today.

MalumPOS Malware

 

malware

Primary Victims: Hotels, Restaurants

MalumPOS Malware was first discovered in 2015, though it took until late 2016 for VISA to issue a warning about the virus. While not as active as it once was, MalumPOS is still found today globally.

MalumPOS targets the Oracle MICROS payment system, a popular POS system used in the hospitality and food industry. The Malware is written in the Delphi programming language.

At its height, MalumPOS could potentially infect 333,000 POS devices worldwide and scraped millions of credit cards. Oracle has since put out several patches to protect against MalumPOS, though during the initial infection, the company pleaded with vendors to change default administrator credentials to halt the infection.

MalumPOS infects a POS device through a driver update; it usually disguises itself as ‘Nvidia Display Driver’ or a similar display driver and can appear legitimate. It can go relatively undetected on a device for years.

BackOff Malware

 

malware

Primary Victims: Home Depot, Target, Dairy Queen, UPS

BackOff was an aggressive strain of POS Malware that made headlines in 2014 and 2015, even prompting the Department of Homeland security to issue a statement.

BackOff targeted Windows POS systems. The Malware injects the malicious stub into the explorer.exe file (File Explorer seen on Windows devices) to gain access to the POS machines, and it scrapes the victim’s machine memory from running the processes. It searches this memory for leftover credit card data after a payment card has been swiped.

It had a wide reach, infecting many large chains across the US, including Home Depot, Target, Dairy Queen, and UPS. At one point, 10% of all Dairy Queen stores in the US had BackOff malware and were actively compromising customer card information.

Its spread was unseen at that point in the world of POS Malware; in August 2014 infection rate increased by 57%. The final number of how many cards were compromised is unknown, though researchers put it close to 4 million.

BackOff is rarely present in the major franchise stores but can still be found in POS systems belonging to small businesses. It is actively being developed to contain more features; later editions include advanced Spyware techniques like keylogging.

BlackPOS Malware

 

malware

Primary Victims: Target, Neiman Marcus, Home Depot, Wendys, UPS

BlackPOS is perhaps the most infamous POS Malware created to date and was the catalyst behind the Target Thanksgiving Data Breach of 2013.

BlackPOS infects Windows systems. It is notably more sophisticated in its code and anti-detection efforts than other POS Malware strains. Its source code was also publicly available, meaning the virus has been updated and enhanced many times.

BlackPOS uses faster-searching techniques than its peers and foregoes regex searches. It samples 0x20000h bytes in each pass and continues scanning till it has scanned the entire memory region of the process being inspected. When desired data has been located, it is quietly exfiltrated back to the hackers C&C.

While BlackPOS infected many POS devices, its most well-known attack campaigns were against Neiman Marcus and Target.

Systems at Neiman Marcus were infected from July 2013 until January 2014. Over the course of several months, 1.1 Million customers’ credit card details were stolen.

The Target breach has been, to date, the most successful POS Malware attacks in history and one of the most destructive data breaches across all forms of cybercrime.

During Thanksgiving break of November 2013, Target’s POS system was infected with the BlackPOS malware. It was not until mid-December that the mega-store became aware of the breach in their security. The hackers could get into Target’s systems by compromising a company web server and uploading the BlackPOS software to Target’s POS systems. As a result of this attack, more than 40 million customer credit and debit card information, and more than 70 million addresses, phone numbers, names, and other personal information, was stolen from its mainframes.

Other Notable POS Malware Strains

There is a great diversity in the field of POS Malware, and the last decade has seen many new faces in the scene.

Rdasrv – It was discovered in 2011, and installs itself into the Windows computer as a service called rdasrv.exe. It scans for track 1 and track 2 credit card data using Perl compatible regular expressions which include the customer card holder’s name, account number, expiry date, CVV code, and other discretionary information. Once the information gets scraped it is stored into data.txt or currentblock.txt and sent to the hacker.

Alina – It was discovered in October 2012 and gets installed into the PC automatically. It gets embedded into the Auto It script and loads the malware into the memory. Then it scrapes credit card data from POS software.

VSkimmer – Vskimmer scrapes the information from the Windows system by detecting the card readers attached to the reader and then sends the captured data to the hacker or control server.

FastPOS – FastPOS Malware is a POS malware that Trend Micro researchers discovered. This strikes the POS system very fast, snatches the credit and debit card information, and instantly sends the data to the hacker. The malware has the capability to exfiltrate the track data using two techniques such as key logger and memory scraper.

PunkeyPOS Malware – PandaLabs discovered this malware, and it infects the point of sale system to breach credit and debit card details. PunkeyPOS Malware uses two functions, such as keylogger and RAM Scraper, to steal information at POS Terminal. Once the information is stolen, it is encrypted and sent to the hackers’ C&C.

The Future of POS Malware

 

malware

POS Malware has two future catalysts upcoming which could ensure its proliferation globally – The COVID Retail Reopening and the mass-adoption of Mobile POS (MPOS).

During the pandemic, cybercrime has been on the increase. There was nearly a 40% from 2019 to 2020, though POS Malware had little to no impact on this statistic due to lockdowns. As states and countries gradually easing lockdown regulations, brick-and-mortar stores welcome waves of returning customers.

With this comes an increase in POS Malware. POS cybercrime has always struck best around busy retail periods such as Thanksgiving, and the reopening of businesses will be no different. Businesses must have sufficient cybersecurity in place with this threat.

The other longer-term catalyst is the rise of MPOS. Apple Pay and Google Pay are becoming increasingly common and may eventually overtake physical credit cards. This presents a challenge for security and a massive opportunity for hackers.

No longer is the fear of penetration just around POS devices, but also in the mobile devices themselves. Mobile malware is undergoing rapid development and has begun to target card details stored within our mobile devices. With potential infections on both a phone and POS device, a hacker has two opportunities to strike.

Protection

Protection against POS Malware must be considered by both businesses using POS systems, and customers opting to use MPOS. Malware protection on both ends is required to conduct financial transactions. There is no method of malware protection that is 100% safe, but there are tools out there that can ensure you or your business operate as safely as possible.

SaferNet is one of these tools.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Cloud Cybersecurity Firm Suffer Data Breach at Hands of Extortion Gang

 

Data Breaches within the cybersecurity world are always linked with a particular brand of Malware – Ransomware. This is not the case with the penetration of cloud cybersecurity firm Qualys. The data breach came at the hands of an extortion gang who have previously been linked with the CLOP Ransomware. In this data heist, no Ransomware was used, however.

The breach was made possible by the gang taking advantage of a zero-day vulnerability within the Accellion File Transfer Application (FTA). Security researchers at FireEye had made it known previously that the Accellion FTA had zero-day vulnerabilities present.

The gang used the vulnerability to access files hosted in a segregated environment. As proof, they shared screenshots on their Dark Web website of the files. The files contain customer information of individuals who use Qualys cloud cybersecurity services. The gang has used the same website previously to sell credentials stolen using the CLOP Ransomware.

Qualys have not publicly stated if they have received an extortion message from the gang yet, though an investigation is on-going.

Accellion Vulnerabilities Leading To The Data Breach


digital lock

Last month, FireEye’s researchers disclosed the details of the four vulnerabilities within Accellions FTA. These vulnerabilities have been used by many other gangs, who have performed a wide range of data heists against several companies and also employed extortion tactics.

The four vulnerabilities are CVE-2021-27101, CVE-2021-27104, CVE-2021-27102, and CVE-2021-27103.

CVE-2021-27101: SQL injection via a crafted Host header
CVE-2021-27102: OS command execution via a local web service call
CVE-2021-27103: SSRF via a crafted POST request
CVE-2021-27104: OS command execution via a crafted POST request

While these were patched by Accellion, a further two exploits were discovered on March 1st; CVE-2021-27730 and CVE-2021-27731.

CVE-2021-27730: An argument injection vulnerability accessible only to authenticated users with administrative privileges, and
CVE-2021-27731: A stored cross-site scripting flaw accessible only to regular authenticated users

Hackers Behind The Data Breach


hacker

The group behind the breach has been dubbed as ‘UNC2546‘ by FireEye researchers. The company has been tracking the group since December 2020. UNC2546 has been involved in several data breaches using the zero-day vulnerabilities found in Accellions FTA.

UNC2546 deploy a web shell named DEWMODE to exfiltrate the data. DEWMODE will sit in the FTA and siphon data back to the groups’ control center.

UNC2546 take data and post it on the “CL0P^_- LEAKS” Dark Web website. Another cybercrime group, FIN11, runs the website. The connection between the two has led to speculation that UNC2546 is, in fact, a cell of FIN11.

FIN11 has been active since at least 2016 and has been involved in several ransomware attacks. Notably, they created the infamous CLOP ransomware. Through till 2018, the group targeted the financial, retail, and hospitality sectors. They have always shown interest in financial gain through Ransomware and extortion, hence the ‘FIN’ in their name.

From 2019 onward, FIN11 shifted attention to Point-Of-Sales (POS) attacks. POS malware is a relatively new branch of cybercrime that targets POS card terminals in retail outlets to exfiltrate card information. If a strain of POS malware propagates enough, it can be lucrative to the hackers.

Protection Against Data Breaches

A data breach brought on by zero-day vulnerabilities are common, though in most cases Ransomware, Phishing, and Spyware are the culprits.

It’s important to have the right tools to protect your business and family against Malware attacks like these. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

CCP-Backed Hackers Target Exchange Servers With Zero-Day Exploit

 

Hackers backed by the Chinese Communist Party have taken advantage of zero-day exploits in Microsoft Exchange to gain access and spy on computers, Microsoft researchers say. On Tuesday, the company reported on four zero-day vulnerabilities within their exchange servers that were exploited. Once inside, the hackers gained access to email accounts and installed additional malware to enable long-term access to the victims’ computers. Microsoft is urging users to download new updates to patch the vulnerabilities.

In their report, the researchers have identified the hackers as Hafnium, a group which conduct affairs from China and who are believed to be sponsored by the Chinese government.

It is clear from the attack that the hackers are highly skilled and competent, as to take advantage of the exploits required a great degree of knowledge and research, and much sophistication to actually carry out.

Is it currently not believe that the intended targets are individual Exchange users, rather business accounts.

Zero-Day vulnerabilities, though are seemingly becoming more common, are a fairly common occurrence with all forms of software, though usually affecting large updates to Operating Systems.

When a new product or update is released, it can be released with some weakness or vulnerability within the code itself, which can be exploited by hackers.

Finding these vulnerabilities is tricky. It often requires reverse-engineering beta releases, and having a keen understanding of both the programming language and penetration testing.

In the White-Hat hacking community, hackers often complete Bug Bounties for companies such as Microsoft and Google. In these, the hacker finds a zero-day vulnerability and alerts only the company affected. The company rewards the hacker in the form of a bounty, which can be as much as $100,000.

In the Black-Hat hacking community, identifying the vulnerability is the same, but the outcome is different. Freelance hackers may sell knowledge of the exploit on the Dark Web for hundreds of thousands of dollars, though they often belong to a larger hacking organization that will use the exploit for themselves.

Anatomy of the Exploits


servers

Often when exploits are discovered in a release, it may take some time for Microsoft to push for its users to update. However, given the severity of the four discovered, they have advised immediate updates. The four exploits in question are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065.

CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange which allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server.

CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave Hafnium the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.

CVE-2021-26858 is a post-authentication arbitrary file write vulnerability in Exchange. If Hafnium could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange. If Hafnium could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

Hafnium: The Hackers Behind The Attacks


hacker

The hackers behind the attack, Hafnium, are believed to be backed by the Chinese Government. Unlike groups like Lazarus, Hafnium have been keeping a very low profile and seems to put more effort into hiding their tracks than other organizations have.

Microsoft claims, “Hafnium primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.”

Hafnium has a history of exploiting zero-day vulnerabilities of systems that use internet-facing servers. Usually, when they penetrate a network, they exfiltrate data to file share sharing sites like MEGA.

Microsoft has been tracking Hafnium for a number of months after previous attempts by the group on the exchange servers. There have been several cases in the past of Hafnium trying to interfere with Office 365 users.

Protection Against Hackers

There are many steps to take to ensure your business and family are safe against hackers. Updating systems with the latest patches as Microsoft suggest is one step, another being using the right tools to stay protected.

One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Universal Health Services Report $67 Million Loss To Ryuk Ransomware

Ransomware damages can be a huge chunk of a companies yearly expenditure, and the number is often alarming. This is the case with Universal Health Services (UHS), who revealed they had been victims of a large Ransomware attack in September 2020. The attack had come from the infamous ransomware strain Ryuk and cost the company $67 Million.

UHS is a major healthcare provider, a Fortune 500 hospital that provides private services to 3.5 Million patients patience in over 400 healthcare facilities across the US and the UK.

Delays in services since September prompted many to speculate if a cyberattack had taken place. UHS had declined to comment on the matter previously but revealed the company’s earnings report’s breach on February 25th.

When their systems were infected, UHS was quick to disconnect internal servers from the network to halt the spread of ransomware. Gradually, they began to move patient data via backups to new servers. This lead to a notable slowdown in their services.

The substantial majority of the unfavorable impact was attributable to our acute care services and consisted primarily of lost operating income resulting from the related decrease in patient activity as well as increased revenue reserves recorded in connection with the associated billing delays,” UHS stated.

Also included were certain labor expenses, professional fees and other operating expenses incurred as a direct result of this incident and the related disruption to our operations.”

We also incurred significant incremental labor expense, both internal and external, to restore information technology operations as expeditiously as possible.”

UHS went on to state that patient data was delivered safely from the infected systems.

Ryuks’ Ransomware Campaign

Ryuks’ Ransomware Campaign hacker

We have mentioned Ryuk in a previous article, and it continues its attack campaign against mostly hospitals and other healthcare providers.

Ryuk is a highly sophisticated form of Malware. There are several suspected organizations behind it, ranging from Lazarus Group to other groups in Russia.

Besides its technical complexity, Ryuk is also notable for having a much higher charge of ransom than its predecessors. In its lifetime so far, it has impacted many businesses and organizations globally, often enriching the finances of the hackers behind it.

Ryuk usually is deployed via trojans like Emotet. Unlike its peers, Ryuk does not strike immediately; it takes several days and sometimes weeks to become apparent to the user. In this seemingly dormant time, Ryuk makes several changes to the user’s Operating System to ensure its success.

One of these operations is to disable all Windows System Restore and Windows Registry functionalities, guaranteeing that IT teams can’t restore machines to a previous, safer state. Ryuk also uses the hosts’ network and was able to infect other devices found on the network. In a hospital or corporation, this meant entire buildings could be infected in a short space of time.

The team at UHS was likely aware of Ryuks’ capabilities and had recent backups created. While they have not detailed much of their teams’ response for security reasons, it looks like they acted quickly to transfer data before Ryuk could take full control.

Hospitals As Targets For Ransomware

Hospitals As Targets For Ransomware

Ryuk stepped up its campaign against hospitals last year, hitting roughly 20 companies affiliated with healthcare every week during the third quarter of 2020. It is not the only Ransomware strain involved with targeting hospitals.

Hospitals make the ideal target for Ransomware; they command massive amounts of sensitive patient personal information, which if seized by hackers can sell easily on the Dark Web. They usually operate on interconnected networks while allows Ransomware to propagate quickly. Add these issues with the financial backing healthcare has, and the whole industry has a digital bullseye on its back.

The Pandemic added fuel to this fire; with more hospitals switching to online services, additional attack vectors opened up for hackers.

An increase of 71% of attacks against hospitals last year prompted the FBI to issue a warning report.

Protection Against Ransomware

Healthcare isn’t the only target for Ransomware – The majority of ransomware cases take place against smaller businesses and family homes.

As attacks ramp up, it’s important to use the tools out there to protect your business and your family online. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

 

 

New Ransomware for 2021 Babuk Hits Several Industries

Ransomware has proved to be one of the key malware threats for 2021, only three months into the year. Veterans to the scene like Ryuk still propagate massively, while novices like 2019’s Cuba are making headlines. Among the well-known faces in the world of ransomware is a newcomer – Babuk. Babuk was discovered in January of this year and has hit five major industries – Transportation, Healthcare, Plastics, Electronics, and the Agricultural sector.

Of the attacks it has carried out, just one target has paid the ransom, $85,000. The target in question was Serco.

For those who have not paid, the data is already for sale on the Dark Web.

Babuk uses several attack vectors seen in other Ransomware. Primarily, it utilizes Spear Phishing. The organization behind Babuk gets the emails of managers and executives of a company and starts emailing them, pretending to be a supplier, distributor, or another trusted party. The emails will contain an attachment. Within the attachment will be a popular trojan loader; In two cases, Emotet and Trickbot were reported. Once the attachment is opened, and the trojan is executed, Babuk will deploy on the target machine.

Babuk has also penetrated systems by using exploits. There are fewer people more up-to-date on security news than hackers, who are routinely looking for news on exploits on servers and databases, particularly those relating to Windows systems. Exploits like these mean there’s no requirement to ‘hack’ into the system as such, but rather to walk through a door that’s been left open. One report of a Babuk infection has traced back to an exploit within Remote Desktop access.

Lastly, Babuk has found entry methods via credential purchases on the Dark Web. Corporate accounts, information, and email addresses are all for sale on the Dark Web. Researchers at McAfee claim that several breaches by Babuk have been a result of using stolen credentials like these.

Unsophisticated Ransomware

 

Ransomware

 

Despite the damage Babuk is causing, researchers at McAfee have noted that the ransomware is fairly unsophisticated compared to more complex malware like Ryuk.

Babuk uses a ChaCha8 stream cipher for encryption and Elliptic-curve Diffie-Hellman for key generation. This makes recovery of the files without paying the ransom difficult for certain, but this encryption level is fairly standard.

Though seemingly independent, Babuk does share some core functionality seen in other Ransomware-as-a-Service (RaaS) products. Research points to the likelihood that the gang behind Babuk bought RaaS and have since reverse-engineered it and began to make it their own.

Babuk also contains a number of noticeable bugs, as well as lacking the obfuscation required for large-scale Ransomware campaigns. The researchers have stated the group behind the attacks has, “limited ransomware coding experience.”

Finally, Babuk contains no local-language checks. Often, Ransomware will check the language of the device before deploying. As a general rule of thumb, it will not deploy if the devices’ language is Russian or other Eastern European languages.

Recruitment in the RaaS World

 

Ransomware


Ransom Letter Left by Babuk

As mentioned, the Babuk group seem to be reverse engineering RaaS in order to make it their own.

Attempts at this so far have certainly led to monetary gain, but as the researchers pointed out, the Ransomware itself is not very complex.

The group is seemingly aware of their limitations and has begun recruitment drives on the Dark Web.

Specifically, the Baruk group have begun hiring individuals skilled in ‘winPEAS, Bloodhound, SharpHound, CobaltStrike, and Metasploit’. This list of tools points to them hiring penetration testers, who will likely be tasked with enhancing Baruks’ capabilities to breach a system.

Due to this, McAfee has noted cybersecurity administrators should be on the lookout for suspicious behavior in non-malicious tools, such as PowerShell.

Protection Against Ransomware

As the criminals are gearing up in their recruitment, SMBs and individuals should be gearing up their arsenal of tools to protect against Ransomware like Babuk.

One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Quickbooks users under attack as tax season heralds data-theft surge

Quickbooks, the popular accounting software package, is under attack by a number of different hacking organizations utilizing various attack vectors, one which takes advantage of a cybersecurity design flaw within Quickbooks itself. Tax season is usually a busy one for cybercriminals. With Quickbooks’ proliferation as the go-to accounting platform for SMBs, their choice of target was an obvious one.

The attack campaign, in general, is centered around spear phishing. The targets are not selected randomly; instead, the hackers have carried out research in selecting specific companies. The bulk of this has been done on websites like LinkedIn. Individuals in a company may have their email addresses displayed; these addresses are usually added to a larger attack database for the hackers to use.

Researchers at ThreatLocker encountered the issue this week and identified 3 main attack vectors.

For the first vector, the hackers will send a PowerShell command that runs inside an email. The second is something a little more familiar; an email containing a Microsoft document. Once the document is opened, a macro within will execute. Both vectors run a similar Malware executable that is just 15 lines of code.

When either vector is used successfully, the malware will find out most recently saved Quickbooks files and points them to file share or the local directory. From here, they are uploaded to the hackers servers.

The third attack vector differs from the others as it doesn’t require the user to download Malware; instead, the hackers have taken advantage of a design flaw in Quickbooks cybersecurity. The hacker can run an Invoke-WebRequest, which utilizes weak access permission in the Quickbooks database to capture details. An Invoke-WebRequest is simply a PowerShell command that scrapes details from a webpage or server.

ThreatLocker successfully tracked much of the stolen data back to the Dark Web, where it is being sold as a commodity. Researchers found data on sale for as cheap as $100 for 100 corporate databases. The price has risen into the thousands for a clean database with full financial information.

As for what is being done with the sold data, it could take several forms. The attack is still on-going, so we will likely not know its full extent until later this year.

One such result of the sold data that has been revealed is a classic bait-and-switch social engineering scam. Once a hacker has garnished enough information about a company and their invoices from their Quickbooks database, they use it for other spear-phishing campaigns. Some that have already been reported involved emailing a customer disguised as a supplier and requesting a payment transfer to a new bank account. Another example involves sending an email from an address that appears to be a known supplier, partner, or customer and requesting a bank transfer.

 

Quickbooks Security Design Flaws

 

Quickbooks



Quickbooks is not a newcomer to the accounting software scene and has been available for decades. Recent releases, notably Quickbooks 2019 and Quickbooks 2020, emphasize user-requested features, which gave the platform a greater lead over its competitors.

Early versions of Quickbooks, specifically the 1992 launch, were thought to have poor security standards. While they have worked on their security since then, these recent reports suggest there are still some less-than-secure practices still in place.

This is apparent in the success of using an Invoke-WebRequest on Quickbooks file servers.

When Quickbooks is on a file server, the user is required to use Quickbooks Database Server Manager. If a repair is carried out, all file permissions are hard-rest, and the ‘Everyone’ group is added to permissions. This is frankly disastrous, as the database is left wide-open, and anybody can access it.

This approach requires little technical insight from the hacker; Invoke-WebRequest is one of the basic PowerShell commands.

In their report, ThreatLocker recommends that you routinely check your file permissions, ensuring it is not set to ‘Everyone.’ This is particularly important after carrying out any repairs. Permissions should be set to a single user if possible within the organizations’ structure.

 

Phishing Attacks on SMBs



Quickbooks

The recent attacks on Quickbooks and the vulnerabilities within its design is just another addition to the long list of cybersecurity threats SMBs are facing today.

Email risk is without a doubt the biggest concern when tightening security within an SMB. These concerns have always been present but heightened sharply with the COVID-19 Pandemic. The pandemic restructured the classic office layout as employees began working from home.

This led to an increased dependence on email for communication and using other cloud platforms to work, some of which was rushed in development to be available for companies during this time; this, in turn, leads to security vulnerabilities within.

The Pandemic became open-season for cybercriminals, who have found new and better ways to exploit the chain of communication put in place to ensure employees can work as normal.

Smaller businesses, in particular, are at risk, as they lack the resources to keep up with emerging threats.

Last year, 91% of all successful cyberattacks against SMBs began with a phishing email, while 55% of SMBs said they had been victim to a phishing attack.

According to the National Small Business Association, small businesses annually absorb over $20K in costs per attack, with SMBs spending nearly $900K to clean-up after an actual data breach.

 

Protection Against Phishing And Other Attacks

 

If one thing is clear, its that Small Businesses are Big Targets.

Phishing as an attack threat is ultimately one that can be greatly lessened by education. Making employees aware of email threats, and how to spot them, can go a very long way in protecting a business no matter its size.

Few people can spot every fraudulent email, though, and it’s wise to have the necessary tools to back up employee security where intuition falls short.

One of these tools is SaferNet, which was designed with SMBs in-mind.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

 

 

Hospitals Return To Paper Systems as Ransomware Takes Hold on Health Service

Ransomware has gripped the health service in France, as two hospitals have opted to return to paper systems to continue their work without technology while the infection holds. The hospitals at Dax and Villefranche-sur-Saône were forced to shut off the internet and other networks to stop the ransomware infection from spreading. The hackers also shut off the hospitals’ telephone systems.

The attacks are a part of a wider ransomware campaign on Frances’ health service. Though still early in the year, several French hospitals have been hit with ransomware, prompting a general warning from the Health Minister. President Macron has pledged €1bn to combat cybersecurity issues in the country a few days ago.

The National Information Systems Security Agency (Anssi) has been working to repair the systems at Dax and Villefranche-sur-Saône, though full restorations are expected to take weeks.

Ransomware has targeted the health industry for many years. However, most people only became aware of this during the WannaCry attacks of 2017, which crippled the National Health Service in the United Kingdom.

The chief goal of Ransomware is always to enable the hackers to make money from the attack. Preferably for the hackers, this means that the target will pay the ransom upfront and will have their files decrypted.

If the target does not pay the ransomware, the encrypted files are most commonly returned to the hackers via a backdoor the virus has established. Once on the hackers’ end, the files will be decrypted and sold on the Dark Web.

Medical records are somewhat the bread-and-butter and stolen data that can be sold on the dark web. Often these contain Personally identifiable information (PII). PII has enough content to identify an individual, which is enough to commit identity theft in many cases. This gives medical records measurable value on the dark web, as using these records for nefarious ends can be lucrative.

CybelAngel, a leader in digital threat research, has been studying the ransomware attacks on French hospitals and has identified the medical records being sold on the dark web. Neither of the hospitals at Dax and Villefranche-sur-Saône paid the ransom, so the data is on sale. CybelAngel has reported as many as 500,000 of these records are currently on the Dark Web from the attacks.

Ransomware Attack Vector

Ransomware

Although the hackers’ identity has not been revealed or is unknown, there are some details known concerning the attack vector and nature of the attacks on Dax and Villefranche-sur-Saône.

It is believed the Ransomware was deployed via a remote access service, using login details possibly harvested via phishing – the attack was well-planned in advance.

As for the ransomware itself, it has been confirmed that Ryuk was used.

Ryuk is one of the more sophisticated forms of ransomware. It is usually deployed via a trojan, though it has been reported as using several other methods.

Ryuk can lay dormant in a machine’s registry for potentially weeks before being activated. It is most commonly seen in large multi-network entities such as hospitals. It uses the network to propagate after infecting a single device, so hospitals are ideal for a group using Ryuk.

Ryuk has been linked with high-profile hacking organizations such as Lazarus Group in the past.

Other Ransomware Attacks in France

Ransomware

The last 12 months have seen a sharp increase in Ransomware attacks in France, which have risen 255% since 2019.

The attacks have been on several industries, including the education system and digital service provides, although the hardest hit group has been the healthcare system.

France is not alone in this; nearly every country globally has reported a staggering amount of Ransomware attacks in the last year.

One must view the larger context for these attacks through the lens of the COVID-19 Pandemic. Changes in how hospitals operate and how they handle patients have meant upscaling systems or switches to new systems entirely.

At times like these, where sensitive medical records are being sent from system to system, Ransomware often finds a place to flourish.

Among other targets hit in this new wave of attacks in France has been Mutuelle Nationale des Hospitaliers (MNH). MNH is a healthcare insurance company that provides services to all public and private medical professionals. MNH was hit with Ransomware in early February, and they were forced to cease all operations during the attack.

MNH was hit by the RansomExx group, who use a variation on the popular ransomware family Defray777. The group has previously targeted the Texas Department of Transportation, Brazilian government networks, IPG Photonics, Tyler Technologies, and Konica Minolta. It is unknown if this group were also behind the attack on the hospitals at Dax and Villefranche-sur-Saône.

What You Can Do About Ransomware

A common mistake is believing that all Ransomware attacks are large-scale industrial assaults that don’t target homes or small to medium businesses. In reality, the majority of Ransomware targets these entities. While not as lucrative for the hackers, using smaller targets means government or federal authorities are less likely to intervene, and thus the victim more likely to pay the ransom.

We are seeing a renaissance across the board for all forms of Malware, fueled by a work-from-home society and an increasingly connected community.

In times like these, it is important to have the right tools to ensure you or your business don’t fall victim. SaferNet was built as one of these tools.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members’ devices; including activity, time spent online, and threats blocked.

 

 

5 Data Breaches That Caused Identity Theft

Identity Theft can be absolutely devastating for an individual. Usually, in the world of malware, we know certain things can be harmed. Our devices may need to be replaced, we may lose access to accounts for a few days or even forever, we may even need to pay a ransom for access to our data. The point is, with most types of Malware, we can eventually rebuild, though it may take longer than we anticipate. The fallout from identity theft is much longer.

Once your stolen information is used once, it can take anywhere from a few days to six months for that one incident. But your information is out there for a very, very long time. This means you could end up dealing with identity theft for many years, even decades.

Identity Theft has been around for a very long time and predates our modern technology by thousands of years. There have always been individuals that try to impersonate others for their own gain, financial or otherwise. However, the internet’s birth and wide adoption have led to new attack vectors, dwarfing any possible past attempts.

Now more than ever do we have data tied into our personal identity. Email addresses, banking numbers, phone numbers, social security numbers, home addresses – All of these and more form a picture of us as lines in a database.

And when this information falls into the wrong hands, it can do a lot of damage. Bank accounts can be drained, and your credit rating can get rattled; you can end up with medical bills or even a criminal record. The list of potential mishaps that can arise from identity theft is endless.

To hackers, identity theft represents a lucrative stream of income, and they can very easily cover their tracks. After they have seized personal information, they sell it on the dark web. This information can be sold over time, repeatedly, meaning that if you notice your identity has been stolen and used, it can be used in several instances over a long period of years.

There are some guidelines from the US government in discovering if you are a victim of identity theft if it is not immediately obvious:

  • You stop receiving your regular bills and credit card statements.
  • You receive statements for accounts you never opened.
  • Debt collectors start calling you day and night about debts you’ve never heard of.
  • The IRS alleges you failed to report income for a company you never worked for.
  • You see withdrawals/charges on your bank or credit card statement that you didn’t make.
  • You try to file your taxes only to discover that someone else beat you to it.
  • You try to file your taxes and find someone claimed your child as a dependent already.
  • Your credit report includes lines of credit you never opened.
  • Your credit score fluctuates wildly and for no apparent reason.
  • The most obvious sign—you receive a notification that you’ve been the victim of a data breach.

If you are unsure, it is always best to check with the authorities on the US government’s identity theft website.

There are two primary attack vectors when it comes identity theft online.

The first concerns a personal cyber attack that compromises your data. This takes place on your own devices, though usually, you are not aware of it. There is often a reliance on the user to fall for phishing scams or have inadequate cybersecurity protection. This will be covered in more detail later.

The other attack vector is through data breaches. These are exceptionally sophisticated large-scale attacks, usually on banks and hospitals. When a hacker breaches one of these institutes, they make off with thousands and often millions of records. These are immediately put up for sale on the Dark Web. Today, let’s look at 5 data breaches that caused identity theft on a large

Data Breaches That Caused Identity Theft #5: Yahoo!

 

yahoo data breach

 

The Yahoo! data breach doesn’t seem like an immediately obvious choice – Yahoo! do not operate as a bank or hospital, so do not store as much in-depth information about their users. However, the sheer scale of the breach meant that enough information was sold to commit identity theft.

To date, the Yahoo! breach is the largest and will likely remain so very a long time. While often referred to as one breach, the incident in-fact covers two breaches in 2013 but was not reported on until 2016. It was only in 2017 was the true scale of the damage was revealed.

In 2016, Wired and Vice’s journalists managed to secure an interview with an individual known online as Peace_of_Mind, or simply Peace. Peace revealed that he was working from a website on the Dark Web known as TheRealDeal. TheRealDeal had long been known to authorities; the site was a large part of the cyber arms industry and sold malware-as-a-service and personal data records for millions of people.

The website had been shut down by the time of the interview, and Peace was mostly retired. He informed the journalists that he acted as a broker; hackers would sell information to him, and he would sell to the masses. In the article, Peace names Yahoo! as one of the main sources of the information he sold.

It was only after the publication of the article that Yahoo! responded, stating they were aware of breaches. At first, they claimed 500 million users had their information stolen. In a second breach, they estimated it was about a billion accounts that had been compromised. Finally, in 2017, Yahoo! affirmed that 3 billion accounts had been compromised.

While Peace never revealed who sold him the information, the hackers were eventually caught. The four men accused include Alexsey Belan, a hacker on the FBI Ten Most Wanted Fugitives list, FSB agents Dmitry Dokuchaev and Igor Sushchin who the FBI accused of paying Belan and other hackers to conduct the hack, and Canadian hacker Karim Baratov who the FBI claimed was paid by Dokuchaev and Sushchin to use data obtained by the Yahoo! breaches to breach into about 80 non-Yahoo! accounts of specific targets.

The breach had a huge fallout, especially in the court cases against Yahoo!, many of which are still on-going. Because they did not tell their users there were breaches, Yahoo! has faced harsh criticisms. In 2018, a court settlement stated that anyone who could document that they were a victim of identity theft following the attack could receive money from Yahoo! from the settlement.

Data Breaches That Caused Identity Theft #4: JP Morgan Chase

 

JP Morgan Chase Cyberattack

 

In 2014, the JP Morgan Chase cyberattack and data breach was considered to be one of the most serious penetrations of America’s financial infrastructure to date.

4 hackers, 3 Israeli and 1 American began a series of spear-phishing attacks against JP Morgan Chase. Through these attacks, they intended to gain access to user accounts across Chases’ systems. In total, they got the details of 83 Million accounts, which covered 76 million households across the US.

Luckily, much of the data they stole was not fully revealing. It did not include social security numbers or passwords but did include names, addresses, emails, and phone numbers.

JP Morgan Chase and authorities acted immediately against the breach, and thankfully much of the information taken was unable to be sold online in time. The 4 involved in the scheme were quickly arrested and have since been sentenced.

While, thankfully, this data breach didn’t cause identity theft on a massive scale, it set a precedent. Banks could be breached – easily. The information could be taken, and if a hacker covered their tracks well enough, they had time to sell it.

Following the attack, JP Morgan Chase pledged a $150 Million cybersecurity budget per year and has given free credit monitoring to all involved in the breach to combat future instances of identity theft.

Data Breaches That Caused Identity Theft #3: Marriott Hotels

 

Marriott Hotels Hack

 

The Marriott Hotels breach was particularly harmful and long-lasting.

In 2016, Marriott purchased the Starwood Hotels and Resorts company. However, unknown to Marriott and Starwood was that since 2014 the Starwood databases had been breached by a Remote-Access-Trojan (RAT) and were actively being monitored.

During a routine security check-up in 2018, Marriott noticed unusual database queries within Starwoods database, from an individual with Administrator-level privileges. An investigation took place and it was discovered the person with those privileges did not make those queries – It was someone else controlling the account.

Database forensics revealed just how long the breach had lasted; at this point 4 years. It also revealed the scale – The information of 500 million guest records had been stolen.

For a hotel, this was a disaster. As well as names, emails, phone numbers, and addresses, credit card information and passport numbers were also stolen. Passport numbers in particular represent low-hanging fruit in the world of identity theft.

It is unknown who carried out the attack, but most signs point to Chinese military. Marriott have been involved in a number of class-action lawsuits, and the settlement has delivered a big pay-day for those affected by identity theft.

Data Breaches That Caused Identity Theft #2: Capital One

 

Capital One Firewall Exploit

 

In July 2019, Capital One announced that they had undergone a massive data breach thanks to the actions of one hacker.

Months previous, a Seattle software engineer named Paige Thomas, had used the knowledge she gained while working for Amazon AWS Cloud Services to exploit an issue with Capital One’s internal firewalls and breach their systems. Thomas stole the records of 106 million people in the United States and Canada. This included social security numbers, which are the keys to commit identity fraud in the US.

Immediately after the attack, Thomas sold the data across sections of the Dark Web. Much of this data has yet to been used, so those affected may not even be aware somebody else has their information.

Thomas’s downfall was her hubris; After selling the data, she bragged about the attack in several hacking forums online. A common misconception about the hacking community is that they’re mostly criminals. Instead, the opposite is true, and her identity was revealed by several white-hat hackers within the community. She was swiftly arrested.

Capital One has been criticized for their response to the attack, specifically as they denied social security numbers and account numbers had been compromised, which later proved to be untrue. They are currently involved in many lawsuits as well Amazon and Github, who are accused of having knowledge of the exploit but not acting upon fixing it.

Data Breaches That Caused Identity Theft #1: Equifax

 

Equifax Data Breach

 

The Equifax breach is probably the best-known of all data breaches to have occurred. The personal, financial, and political fallout from the Equifax breach has been staggering.

Equifax is a credit reporting bureau and assesses the financial health of nearly every individual across the US. In March 2017, poor security practices led the data of 150 Million Americans being stolen, along with the personal information of 15 Million British citizens.

Several failures on Equifax’ part made the attack possible. Hackers exploited a vulnerability on the web portal at first; this vulnerability had been known for months yet the company hadn’t patched it out. Following this, the hackers were able to freely move around Equifax servers. This, again, is a cybersecurity flaw – Equifax failed to segment their servers correctly, leading to this kind of movement. Finally, Equifax had failed to renew encryption certificates for months – Which meant the hackers could pull out information undetected.

When Equifax realized the breach, they did not report on it for several weeks. Sales of Equifax stock at the time before the announcement have led to speculation that insider trading took place here.

The data stolen included nearly everything you could know about someone – name, address, email, phone number, social security number, credit card number, even their driver’s license number.

The identity theft fallout from Equifax is not what you’d expect. Following the incident, many in the information security community monitored the Dark Web for bulks of data appearing in stores. This never really happened – There was a trickle of data, but never any large drop. Millions had their data sold, but not the 150 million as expected.

This pointed to a possible culprit – state-sponsored hackers. Sure enough, in a rare move, the Department of Justice charged 4 members of the Chinese military in early 2020. This is considered rare because foreign military intelligence operatives are not often charged with criminal charges.

This has brought about a theory that the Chinese military was not all too interested in selling the data but perhaps were using it for espionage. It is unknown what the Chinese military would do with 150 million social security numbers, but perhaps the story is not fully told yet.

What you can do to Prevent Identity Theft

In the above cases, the individuals who had their information leaked were not at fault, rather it was corporations that were held responsible.

These are cases of large-scale data breaches, but every-day identity theft occurs most often on a personal scale.

Phishing attacks, Spyware, and Botnets are all used against us daily to uncover our details, and most of us do not have adequate protection.

SaferNet was engineered with threats like identity-theft in mind.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.