The Human Stories Behind Cybercrime, Part 2

Recently, SaferNet covered the stories of regular individuals and their brushes with cybercrime. We all have stories like these, which can make them the most impactful. Today, we’ll look at more in Part 2.

These stories were collected from around the web, including Heimdall Security, Telegraph UK, NY Times, Reddit, Buzzfeed, Medium, The Atlantic, Reader’s Digest, and various blogs.

Note: Names and some locations of the stories shown here have been changed to respect the individual’s privacy.

An individual in the UK loses money to a TV license phishing scam:

“When Jerry Tack received an email saying the TV license needed paying, he didn’t think twice about it.

Nothing seemed suspicious about the website he clicked on, so he entered his bank details – and began a chain of events that would lose him £9,900.

Jerry, from Hampshire, was among thousands contacted in what police called a “particularly nasty” fraud.

But the banks say they cannot reimburse customers who have mistakenly authorized payments to fraudsters.”

An American Woman Gets Hacked and Cyberstalked:

“When I first read the email from my hacker, I couldn’t stop screaming. I didn’t know what to do; I was in a state of complete shock and terror. I had sensed something was wrong, but this was my horrifying confirmation.

I was out to dinner with my friends when I got a Facebook notification that somebody in another state had logged into my account and tried to change my password. Thirty minutes later, I got an email from who I assumed to be the culprit. It said if I didn’t do what was asked of me, “every photo I have of you” was going to be posted on my social accounts, which he had gained control of. I had no idea what he was talking about until I scrolled down to the very end of the email.

There were two photos of me in my bedroom taken through my webcam. I later found out he had been spying on me for over a year, from my senior year of high school to when I received that first email during my freshman year of college.

I called my mom, who contacted the police immediately. They told me they were going to catch the hacker, but that it could be a slow process.

Meanwhile, I was busy wondering how this could happen in the first place. I must have opened an email with a link in it that allowed him to place malware, or malicious software, on my computer, which granted him complete access to my laptop. He was able to trace the keystrokes on my keyboard so he could learn my passwords and see what sites I was going to, and, creepiest of all, he was able to access my webcam 24/7.

I used to keep my computer open on the floor of my bedroom to play music while I was studying, changing, going back and forth from the shower—he saw all of that.

I was convinced this was some random creepy guy from a different country. Then I found out it was someone from my high school. I went to a huge school with over 3,000 students and never had any personal communication with him, though I knew who he was. The fact that I would pass him in the hallways at the same time he was doing such a horrific thing to me is so scary.

And sadly, I wasn’t the only one he did this to. There were 12 other victims, two of whom also went to school with us. I haven’t been able to confront him, and I don’t know that I want to. He plead guilty to hacking and extortion, and a trial date has been set for next month. I’m not sure what his sentence will be.”

A woman has her video surveillance Ring setup hacked after using a leaked password:

“After a Brookhaven couple’s Ring security camera was hacked, the terrified woman said a strange man yelled that he was watching her via the camera. The doorbell company says that the camera wasn’t hacked, but that the couple used a password that had been leaked or compromised.

The woman, who didn’t want to be identified, shared the video from the incident with local TV stations and on social media. The victim said she and her boyfriend installed the camera to watch their dog, Beau, while they’re at work.

When she noticed a light on the camera, she texted her boyfriend to ask why he was watching, and he replied that he wasn’t. That’s when the stranger spoke to her through the camera: “I can see you in the bed! C’mon! Wake the [expletive] up!”

The couple found someone had hacked their account on four occasions.”

An individual in Chicago falls for a phishing email and loses $2000:

“Alison Senft of Kendall County says someone hacked into her bank account and used the Zelle payment app to steal $2,000. Then her bank told her there’s nothing they can do, and she can’t even get ahold of Zelle.

Reporters discovered the fraudsters used an email registered to a Big Ten university to carry out a phishing attack.

That stress started in late November, when she discovered someone had used the payment app Zelle to transfer $2,000 out of her Fifth Third Bank account just in time for the holidays.

“If I could find this person, I would show them my children, and say ‘This is who you’re stealing from. This is who you are taking money from,’” she said.

She filed a fraud claim, but Fifth Third Bank said the transaction appears valid and they won’t refund her, even though the recipients had a phone number with a California area code.

“Don’t know anybody there,” Senft said. “I have called Zelle, I don’t know, probably 20 times; but I cannot get in contact with a person. But Fifth Third just keeps telling me, ‘contact Zelle.’”

She did get a response when she sent a Facebook message to Zelle, from someone saying they’d look into it.

But then when she tried to follow up, she suddenly couldn’t message them, and she’s somehow blocked from commenting on their posts.

“I was so frustrated. Please just, like, let me talk to you, tell this story, and give me some sort of answer,” Senft said.”

Jim on coming across what he thought was a trusted website:

“A couple of years ago, I bought some clothes online. The company seemed trustworthy and had a HTTPS secured website. I felt safe entering my card details. When I bought my item, I received a confirmation email and got the item in the mail. Everything you would expect

A few weeks later I was woken up by my phone beeping. I had two-factor authentication and someone was making multiple attempts to log into my email.

This worried me, so I checked my banking app. I found multiple unauthorized charges. I called my bank to get my credit card shut off. This left me without any money until payday, and I had to borrow money from friends until then.

After contacting the authorities, I found out it was likely that the shopping website was a front, or was compromised. I had handed over criminals my email and banking information willingly. I felt sick.”

Paul realizes the danger of using the same password for all his online services:

“I was signed up to many online services, like video games, social media, streaming site etc. I’m not certain how my details were stolen, but I found out my credit card was no longer working with international purchases. I started getting emails that all of my monthly subscription charges couldn’t go through.

I called my bank and they told me my card had been blocked for suspicious purchases. For example, there was a charge for a Dollar General in California, but I lived in the UK, and had never traveled there.

I realized that I had used the same password for everything, so when it was compromised on one site, it was compromised everywhere. The hackers must have seen my associated email and tried it across different banks and websites.

The incident scared me into better habits. I used multiple different passwords, 2FA where possible, and a VPN. I know being 100% isn’t possible but I have peace of mind knowing I am much more secure.”

Tom from the US on being duped by a fake Amazon website:

“A while back I was looking to buy an expensive item from Amazon, but I wasn’t sure about closing the sale because the price information seemed outdated and I was unsure if the item would work with my other equipment.

I wasn’t sure how to contact the seller, and tried searching for a phone number for Amazon on their website, but couldn’t find any. So, I googled it. I found a website that seemed just like Amazons, it had the logo and website address that seemed to fit. It had a number which I called. The man who answered seemed genuine and seemed to care a lot about my situation. After a few minutes of conversation, he asked to screen share into my computer. In retrospect, this seems dumb, but I had done it with so many other companies I agreed. He said he couldn’t find the item on his database and wanted to see it on my computer.

He got into my computer. I am not very tech-savvy so I wasn’t sure what he was doing. I saw files moving across my computer, and he brought up what he said was my IP address, and told me I had a virus.

He said it would cost $200 to remove the virus. At this point, I knew the call was not legitimate. I called him out on it, but wasn’t sure how to remove his access from my computer.

I noticed a lot of the files on my desktop started being deleted rapidly. Many of these were years of memories and photos of me and my grandchildren. I panicked and pressed the shut down button to turn off the computer.

I tried using System Restore a few times but it never worked. I lost of a lot of memories and I was very hurt by what happened. I know that you shouldn’t click links on emails or on Facebook, but I didn’t know hackers and scammers could get you through a search engine”

Sandra on getting her card details stolen online twice:

“I checked my bank account one day in 2011 after receiving some alerts and couldn’t believe my eyes when I saw I was $5000 in debt on my credit card. I called my bank and they told me I had made purchases in Germany for high-end electronics, which I hadn’t.

The next time happened in 2017, where I had $11000 taken from my credit card for purchases in China – It wasn’t me again.

I thought the first time was a fluke, but after the second time, I have become much more cautious online. I now use a VPN and I’m very wary about links I click”

Mark on a series of threatening emails made against his family:

“A couple of years ago, my family and I started receiving some very threatening, blackmail emails. We even got emails from our own email accounts. The person told us that they had hacked our emails and had access to all our accounts.

They told us they could see everything we did online, including accessing adult websites, which we had not. They said they had accessed our webcam and had taken footage of us also.

They demanded thousands of dollars to not send images and our personal information around the web, but I called their bluff.

I was still worried because the person had access to our email accounts. I changed all our passwords and started using a VPN. We no longer get the threatening emails, and have more peace of mind.”

Rita on a hacker taking over her email account and using it to send phishing emails:

“A number of years ago, my email account was hacked. I believed it was because I had clicked on an email link I shouldn’t have. I also had the same password on many accounts, which meant the hacker could get into other accounts of mine.

I got alerts in work from purchases on my card and panicked. I logged into my email (the hacker hadn’t changed the password!) and noticed my ‘Sent’ list was sending what now seemed like bogus links to everybody in my contacts list. It was then I realized they had gotten into my email and from there into my other accounts.

I had to ask my boss for the remainder of the day off so I could work through things with the bank to reverse purchases. I was on the phone and went through several managers to try to get everything back.

In total, it took nearly a full week to get my accounts back, and there were a few I never did.”

Nathan taking a financial hit from what he suspects was a compromised website:

“A few years ago, I was on vacation with my fiance in Europe. One night, I got a text alert from my bank saying that my bank was charged almost $1000 for the purchase of a camera. I was suspicious of the text itself, so I call my bank. They confirmed the text was from them, and the charge really had gone through.

I talked for a while with my bank, but had to wait nearly a month for the transaction to reverse.

Thinking back, I had been doing research for work previous to our trip, and ended up on websites that were full of ads, and generally felt like they were sketchy. I believe I may have received a keylogger or some kind of virus from these sites that could catch my credit card information.

I am much keener on security now, I have heavily secured both my fiance and I’s computers and phones. We both use VPNs and take fewer risks online.”

A journalist from the US on falling for a classic coffee-shop scam:

“I was in a coffee shop not long ago, doing some work on my laptop. I connected to the wifi, not realising it was a fake access point set up by hackers. I ended up staying in the coffee shop for most of the day, and during that time I logged into two different bank accounts I had.

Only a few hours after leaving, the bank notified me to say one of the accounts was used to make online purchases around the country.

It was heartbreaking because I hadn’t seen the notifications when they came through initially, and by the time I realised it many purchases had been made.

It took a long time to work through the fraudulent transactions with the bank. It was a nerve-wracking and frustrating experience.”

Caleb on ignoring some transactions due to his use of Amazon:

“A while back, I saw some odd transactions of my bank account. This was during the COVID lockdown, and I had been making a lot of Amazon purchases. Because of that, I disregarded the transactions as items I bought and hadn’t arrived yet.

Over the following days, many more transactions came in – From websites ranging from womens’ cosmetics to fashion.

I realised it was a scam, and notified my bank and the police. I didn’t get a full refund, and the hacker made off with just over 500 euro.

I felt really stupid. I had been using a VPN on my phone for a long time but had stopped for a few weeks because I thought it was draining the battery. It was in that time the hacker most have got the information off my phone somehow.”

Josine on using the same password:

“I was hacked about a year ago. It was because I used the same password on multiple sites.

One of the sites was hacked, and the passwords were leaked. As far as I know, hackers sold these passwords to other hackers, along with the associated email address.

I began getting locked out of multiple accounts. Thankfully I did notice it pretty early, so I was able to recover all of the accounts.

I’ve since changed all my passwords, and have multiple. I’ve also used 3 different emails for different websites, just to be safe.”

Colin on a hacker using a script in tandem with his email and password:

“About two years ago, I got a notification from my bank that a $1299 charge had been made with BestBuy. I logged into my BestBuy account and saw the order, and it was due to ship to my address. I contacted BestBuy and they refunded my account. When they had, I changed my password and deleted my credit card information from their website.

Later on that night, I got an email saying I had a new Netflix login. I went to check out the account, and there was a new device on it I didn’t recognize. I disconnected all my devices and changed my password.

I went back to sleep and woke up to hundreds of emails – easily over 500. Every email was from a different legitimate website, mostly welcome messages. Obviously, it wasn’t me who signed up for any of them.

I used the same password for BestBuy and Netflix. I realized the hacker had gotten my details and possibly used a script to try to log into as many services as possible, many of which ended up being services I had never used so it just signed me up.

It took me days to go into every single account I had and get a unique password for each, as well as take my credit card info off the websites. For safety, I decided to cancel my card and get a new one too.”

Kevin on his girlfriend receiving a high-fidelity phishing text:

“My girlfriend and I have been saving up for a 6-month trip next year, using separate bank accounts. We live in a major city in Europe and rent makes up a large amount of our paychecks, so it can be difficult to save anything without cutting corners and being frugal at every turn.

Recently, my girlfriend got a text from her bank. She followed the link, and it took her to a high-fidelty page that looked exactly like the banks. She even asked me to look over it – We both work in IT and are very aware of scams. She entered her credentials, and the browser opened her banking app, making it seem like nothing was wrong.

A few days later, she realised 10,000 euro had been taken from her account – All her savings for the trip thus far. She was distraught, and I was angry at the hackers and myself for not picking up at it.

We went to the police and contacted the bank. The police told us they couldn’t do anything except put out a warning for others regarding the text. The bank told us they would need to investigate the issue which could take 72 hours.

We spent the next 3 days feeling extremely down and stressed. Thankfully, the bank reimbursed the money. We are even more cautious now, knowing that months, and sometimes years of worked can be wiped clean in a mistake that might only take a few seconds.”

Protection From Cybercrime

As you’ve read, cybercrime has a very real human element at the end of it. Every day, thousands of new victims are made. It is important that business owners and families have the best tools for the job when it comes to protecting their devices. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Pegasus Spyware Invades iPhones and Blackmails Victims

Pegasus Spyware is being used in a new extortion scam that seeks to blackmail iOS users. The data collected by Pegasus Spyware is used to scare victims into paying so that the data is not released. A month ago, Amnesty International disclosed that Pegasus spyware was installed on fully updated iPhones through a zero-day zero-click iMessage vulnerability.

A zero-click vulnerability is a hack that is performed without any interaction by the user. These are extremely dangerous and high-priority issues for teams once they are discovered.

Amnesty believes that Pegasus Spyware is used by governments to monitor the communication of politicians, journalists, human rights activists, and business executives worldwide.

This week, a threat actor has been emailing iOS users informing them their devices was compromised with a ‘zero-click’ vulnerability to install the Pegasus spyware software.

The scammer explains that Pegasus Spyware has been used to monitor the victim’s activities and that they have created videos of them during “the most private moments” of their lives.

The email warns that if a 0.035 bitcoin (approximately $1,600) payment is not paid, the threat actors will send the videos to the recipient’s family, friends, and business associates.

The full text of the email is as follows:

You can read the full text of this email below:

“Hi there
Hello, I’m going to share important information with you.

Have you heard about Pegasus? You have become a collateral victim. It’s very important that you read the information below.

Your phone was penetrated with a “zero-click” attack, meaning you didn’t even need to click on a malicious link for your phone to be infected. Pegasus is a malware that infects iPhones and Android devices and enables operators of the tool to extract messages, photos and emails, record calls and secretly activate cameras or microphones, and read the contents of encrypted messaging apps such as WhatsApp, Facebook, Telegram and Signal.

Basically, it can spy on every aspect of your life. That’s precisely what it did. I am a blackhat hacker and do this for a living. Unfortunately you are my victim. Please read on.

As you understand, I have used the malware capabilities to spy on you and harvested datas of your private life. My only goal is to make money and I have perfect leverage for this.

As you can imagine in your worst dream, I have videos of you exposed during the most private moments of your life, when you are not expecting it.

I personally have no interest in them, but there are public websites that have perverts loving that content.
As I said, I only do this to make money and not trying to destroy your life. But if necessary, I will publish the videos. If this is not enough for you, I will make sure your contacts, friends, business associates and everybody you know see those videos as well.

Here is the deal. I will delete the files after I receive 0.035 Bitcoin (about 1600 US Dollars). You need to send that amount here [Wallet Address]

I will also clear your device from malware, and you keep living your life. Otherwise, sh*t will happen. The fee is non negotiable, to be transferred within 2 business days.

Obviously do not try to ask for any help from anybody unless you want your privacy to be violated. I will monitor your every move until I get paid. If you keep your end of the agreement, you won’t hear from me ever again.

Take care.”

Fortunately, there are currently no payments to the wallet address contained in the email. It is possible that other emails may have different addresses which have been paid.

While it is most likely this truly is a scam – That is to say, that the targets don’t have Pegasus Spyware installed – these types of activities have proven lucrative. Similar scams have generated thousands of dollars for the hackers behind them.

Though these types of emails can elicit fear in people, it is always best to mark them as scams and delete the email, as they are rarely truthful.

Pegasus Spyware Analysis

Note: This Analysis was carried out by LookOut.

The attack is very simple in its delivery and silent in delivering its payload. The attack starts when the attacker sends a website URL (through SMS, email, social media, or any other message) to an identified target. The user only has to take one action–click on the link. Once the user clicks the link, the software silently carries out a series of exploits against the victim’s device to remotely jailbreak it so that the espionage software packages can be installed.

The user’s only indication that anything happened will be that the browser closes after the link is clicked. The espionage software contains malicious code, processes, and apps that are used to spy, collect data, and report back what the user does on the device. Pegasus spyware can access and exfiltrate messages, calls, emails, logs, and more from apps including, but not limited to:

 

In order to accomplish this, Pegasus spyware, once it jailbreaks the user’s phone, does not download malicious versions of these apps to the victim’s device in order to capture data, rather it compromises the original apps already installed on the device. This includes pre-installed apps such as Facetime and Calendar and those from the official App Store.

Usually, iOS security mechanisms prevent normal apps from spying on each other, but spying “hooks” can be installed on a jailbroken device. Pegasus Spyware takes advantage of both the remote jailbreak exploit and a technique called “hooking.” The hooking is accomplished by inserting Pegasus Spyware’s dynamic libraries into the legitimate processes running on the device. These dynamic libraries can be used to hook the apps using a framework called Cydia Mobile Substrate, known to the iOS jailbreak community, and which Pegasus Spyware uses as part of the exploit.

A user infected with Pegasus spyware is under complete surveillance by the attacker because, in addition to the apps listed above, it also spies on:
• Phone calls
• Call logs
• SMS messages the victim sends or receives
• Audio and video communications that (in the words a founder of NSO Group) turns the phone into a “walkie-talkie”

Access to this content could be used to gain further access into other accounts owned by the target, such as banking, email, and other services he/she may use on or off the device. The attack is comprised of three separate stages that contain both the exploit code and the espionage software. The
stages are sequential; each stage is required to successfully decode, exploit, install, and run the subsequent stage. Each stage leverages one of the Trident vulnerabilities in order to run successfully.

STAGE 1 Delivery and WebKit vulnerability
STAGE 2 Jailbreak
STAGE 3 Espionage software

The third stage deploys a number of files deployed in a standard unix tarball (test222.tar), each of which has its own purpose:

• ca.crt – root TLS certificate that is added to keystore (see Appendix A)
• ccom.apple.itunesstored.2.csstore – Standalone javascript that is run from the command line at reboot and is used to run unsigned code and jailbreak the kernel on device reboot
• converter – injects dylib in a process by pid. It is a renamed version of the cynject from the Cydia open-source library
• libaudio.dylib – The base library for call recording
• libdata.dylib – A renamed version of the Cydia substrate open-source library
• libimo.dylib – imo.im sniffer library
• libvbcalls.dylib – Viber sniffer
• libwacalls.dylib – Whatsapp sniffer
• lw-install – Spawns all sniffing services
• systemd – Sends reports and files to server
• watchdog
• workerd – SIP module

The attack investigated works on iOS up to 9.3.4. The developers maintain a large table in their code that attacks all iOS versions from 7.0 up to and including iOS 9.3.3. While the code we investigated did not contain the appropriate values to initially work on iOS 9.3.4, the exploits we investigated would still work, and it is trivial for the attackers to update the table so that the attack will work on 9.3.4.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

LockBit Ransomware Gang Publish 103GB Of Bangkok Air Customer Data After Attack

LockBit Ransomware has breached Bangkok Air, according to a press release by the aviation company last Thursday. The following day, the LockBit Ransomware gang released a countdown clock, threatening to release stolen data unless ransom demands are met. The gang claims to have 103GB worth of files from Bangkok Air, and is promising to release them on Tuesday.

Dark Web intelligence firm, DarkTracer, tweeted a screenshot of a countdown from the LockBit Ransomware gang. At the time of the tweet, the clock showed four and a half days left.

“LockBit ransomware gang has announced Bangkok Airways on the victim list,” DarkTracer tweeted. “It announced that 103GB of compressed files will be released.”

A day before the announcement by the LockBit Ransomware gang, Bangkok Airways publicly acknowledged that it had been blasted with a cyberattack a week ago, on Monday, Aug. 23. It’s still investigating the incident “as a matter of urgency,” the company said in a press release and is working on beefing up its defenses.

“Upon such discovery, the company immediately took action to investigate and contain the event, with the assistance of a cybersecurity team. Currently, the company is investigating, as a matter of urgency, to verify the compromised data and the affected passengers as well as taking relevant measures to strengthen its IT system.” the company said in their press release.

The personal data includes:

  • Passenger name
  • Family name
  • Nationality
  • Gender
  • Phone number
  • Email address
  • Other contact information
  • Passport information
  • Historical travel information
  • Partial credit-card information
  • Special meal information

The LockBit Ransomware gang allegedly did not succeed in accessing Bangkok Airway’s operational or aeronautical security systems, the company said. The company apologized, saying that “Bangkok Airways Public Company Limited takes the protection of passenger’s data very seriously and the airline is deeply sorry for the worry and inconvenience that this malicious incident has caused.”

Bangkok Air has notified the proper authorities, including the Royal Thai police.

LockBit Ransomware Analysis

NOTE: This analysis of Lockbit Ransomware was carried out by McAfee

The file found in the investigation of Lockbit Ransomware was a dropper renamed as a .png file. When first opening the .png files we were expecting a real image file, with perhaps some steganography inside, but what we saw instead was the header of a portable executable, so no steganography pictures this time. The PE was compiled in Microsoft Visual C# v7.0 / Basic .NET, .NET executable -> Microsoft.

Entropy-wise is tidy too, not showing any stray sections or big spikes in the graph. This behavior indicates that the writer of the Lockbit Ransomware did not use obfuscation.

This file is a .NET launcher. Examining the Main() function in the code shows that an array containing a particularly long AES encrypted base64 string (in the variable named ‘exeBuffer’) carries the executable for the actual ransomware.

This encrypted string is decrypted using the key ENCRYPTION29942. The first 32 bytes of the long ExeBuffer string are used as the salt in the encryption scheme, where ENCRYPTION29942 is the passphrase.

The script checks for the existence of vbc.exe on its designated host. Usually, this binary is a digitally signed executable from Microsoft; however, in this case, the malware uses it for process hollowing.

By statically analyzing the file we can spot the usage of:

  • NtUnmapViewOfSection
  • LockBit Ransomware uses this API in order to unmap the original code in execution
  • NtWriteVirtualMemory
  • The malware writes the base address of the injected image into the PEB via NtWriteVirtualMemory
  • VirtualAllocEx
  • To allocate the space before injecting the malicious code
  • The VBC utility is the visual basic compiler for Windows and LockBit Ransomware uses it to compile and execute the code on the fly directly in execution. If the vbc utility does not exist on the system, the malware downloads the original vbc.exe file from the same malicious URL as seen before. After executing vbc.exe, the malware replaces the objects in memory with the code for deploying the ransomware (as deduced from the exeBuffer).

The list of services LockBit Ransomware tries to stop are:

  • DefWatch (Symantec Antivirus)
  • ccEvtMgr (Norton AntiVirus Event Manager)
  • ccSetMgr (Common Client Settings Manager Service of Symantec)
  • SavRoam (Symantec Antivirus)
  • sqlserv
  • sqlagent
  • sqladhlp
  • Culserver
  • RTVscan (Symantec Antivirus Program)
  • sqlbrowser
  • SQLADHLP
  • QBIDPService (QuickBooksby Intuit.)
  • QuickBoooks.FCS (QuickBooksby Intuit.)
  • QBCFMonitorService (QuickBooksby Intuit.)
  • sqlwriter
  • msmdsrv (Microsoft SQL Server Analysis or Microsoft SQL Server)
  • tomcat6 (Apache Tomcat)
  • zhundongfangyu (this belongs to the 360 security product from Qihoo company)
  • vmware-usbarbitator64
  • vmware-converter
  • dbsrv12 (Creates, modifies, and deletes SQL Anywhere services.)
  • dbeng8 (Sybase’s Adaptive Server Anywhere version 8 database program)
  • wrapper (Java Service?)


If one of these services is found by the malware querying the status of it, with the function “QueryServiceStatusEx”, LockBit will get all the depending modules when correct and safe and it will stop the service with the function “ControlService”.

The ransom note is rather compact because the author hardcoded the content right in the code without using any obfuscation or encryption. The text file containing the ransom note is created in every directory after encryption and called Restore-My-Files.txt.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Ransomware Attacks Up 288% This Year As FBI Issues Warning Before Labor Day

2021 has proven to be another record-breaking year for Ransomware attacks, which have increased 288% in the last year. To add to this, the FBI has released a joint statement with CISA, urging organizations not to let down their defenses against ransomware attacks during weekends or holidays, especially with regards to the upcoming Labor Day weekend.

The agencies said they “observed an increase in highly impactful ransomware attacks occurring on holidays and weekends—when offices are normally closed—in the United States, as recently as the Fourth of July holiday in 2021.”

Though both agencies did not disclose any information regarding potential ransomware attacks within upcoming holidays, they gave examples of recent attacks which occurred on such days – Colonial Pipeline, JBS, and Kaseya.

JBS, the world’s largest beef producer, shelled out $11 Million to the now-defunct REvil Ransomware gang after a Memorial Day hack.

Colonial Pipeline paid $4.4 Million to the Darkside Ransomware gang, in what was possibly the most storied Ransomware incident of the year. The attack occurred on Memorial Day.

On the fourth of July weekend, REvil Ransomware pulled off one of their largest – and final – attacks, striking dozens of Kaseya customers which affected 1500 businesses.

As shared by the two agencies:

  • In May 2021, leading into Mother’s Day weekend, malicious cyber actors deployed DarkSide ransomware against the IT network of a U.S.-based critical infrastructure entity in the Energy Sector, resulting in a week-long suspension of operations. After DarkSide actors gained access to the victim’s network, they deployed ransomware to encrypt victim data and—as a secondary form of extortion—exfiltrated the data before threatening to publish it to further pressure victims into paying the ransom demand.
  • In May 2021, over the Memorial Day weekend, a critical infrastructure entity in the Food and Agricultural Sector suffered a Sodinokibi/REvil ransomware attack affecting US and Australian meat production facilities, resulting in a complete production stoppage.
  • In July 2021, during the Fourth of July holiday weekend, Sodinokibi/REvil ransomware actors attacked a U.S.-based critical infrastructure entity in the IT Sector and implementations of their remote monitoring and management tool, affecting hundreds of organizations—including multiple managed service providers and their customers.

Soaring Ransomware Attacks

Holidays are the least of worries when it comes to Ransomware attacks, which soared by 288% between the first and second quarters of 2021, according to new data from NCC Group.

Analyzing incidents dealt with by its own Research Intelligence and Fusion Team (RIFT) throughout 2021, the firm claimed nearly a quarter (22%) of data leaks in the second quarter came from the Conti group.

Avaddon Ransomware was the runner-up, at 17% of incidents.

Nearly half (49%) of victims were based in the US, which continues to be a hotspot for ransomware attacks. 7% were in France, and 4% in Germany.

Christo Butcher, lead for for threat intelligence at NCC Group, stated that no organization in any sector is safe from ransomware today.

“We’ve seen targets range from IT companies and suppliers to financial institutions and critical national infrastructure providers, with ransomware-as-a-service increasingly being sold by ransomware gangs in a subscription model,” he added.

“It’s therefore crucial for organizations to be proactive about their resilience. This should include proactive remediation of security issues, and operating a least-privilege model, which means that if a user’s account is compromised, the attacker will only be able to access and/or destroy a limited amount of information.”

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

New BrakTooth Flaws Leave Millions of Bluetooth-enabled Devices Vulnerable

Braktooth is the name given to a new set of security vulnerabilities that affect Bluetooth devices and can enable a hacker to execute arbitrary code or crash devices via denial-of-service (DoS) attacks.

Braktooth (referring to the Norwegian word “Brak” which translates to “crash”) contains 16 weaknesses which span across 13 Bluetooth chipsets from 11 vendors such as Intel, Qualcomm, Zhuhai Jieli Technology, and Texas Instruments, covering an estimated 1,400 or more commercial products, including laptops, smartphones, programmable logic controllers, and IoT devices.

Braktooth was discovered by cybersecurity researchers from SSET (Automated Systems SEcuriTy) at the Singapore University of Technology and Design (SUTD).

“All the vulnerabilities […] can be triggered without any previous pairing or authentication,” the researchers noted. “The impact of our discovered vulnerabilities is categorized into (I) crashes and (II) deadlocks. Crashes generally trigger a fatal assertion, segmentation faults due to a buffer or heap overflow within the SoC firmware. Deadlocks, in contrast, lead the target device to a condition in which no further BT communication is possible.”

Of the 16 vulnerabilities, the most severe is CVE-2021-28139, which affects the ESP32 SoC used in many Bluetooth-based appliances ranging from consumer electronics to industrial equipment. Due to a lack of an out-of-bounds check in the library, an attacker can inject malicious code on vulnerable devices.

Other Braktooth vulnerabilities can result in Bluetooth functionality getting entirely disabled, or cause a DOS condition in laptops and smartphones employing Intel AX200 SoCs. “This vulnerability allows an attacker to forcibly disconnect slave BT devices currently connected to AX200 under Windows or Linux Laptops,” the researchers said. “Similarly, Android phones such as Pocophone F1 and Oppo Reno 5G experience BT disruptions.”

Bluetooth speakers, headphones, and audio modules can be sent into a bricked-state byBraktooth, where the user will be unable to turn them back on. The Braktooth attacks can be carried out using a readily available Bluetooth packet sniffer that costs less than $15.

A handful of companies including Espressif and Infineon have released firmware patches to protect vulnerable devices, while Intel, Qualcomm, and others are still investigating and a patch is in the works. Texas Instruments doesn’t intend to release a fix unless “demanded by customers.”

Braktooth Vulnerability Analysis

Note: This analysis was carried out by ASSET.

The attacker only requires (1) a cheap ESP32 development kit (ESP-WROVER-KIT [31]) with a custom (non-compliant) LMP firmware and (2) a PC to run the PoC tool. The PoC tool communicates with the ESP32 board via serial port (/dev/ttyUSB1) and launches the attacks according to the specified target BDAddress () and exploit name parameter ().

Below are the devices used for evaluation of Braktooth. The sample code is provided by vendor to test the development board. This is not applicable (N.A) on products running a fixed application.

Below is a summary of new vulnerabilities and other anomalies found (Vx: Vulnerability, Ax: Non-compliance) which make upBraktooth.

A summary of Braktooth appears in Table 2. In each row, we use the prefix V to identify a security vulnerability and A to indicate an anomalous behaviour (i.e., faulty target responses) that deviates from the Core Specifications [27]. Moreover, Table 2 outlines the respective CVEs, affected devices, protocol layers, and the violated compliance. In summary, we discovered 16 new security vulnerabilities belonging toBraktooth. For all the discovered vulnerabilities, we have followed a responsible disclosure process.

The impact of our discovered vulnerabilities is categorized into (I) crashes and (II) deadlocks. Crashes generally trigger a fatal assertion, segmentation faults due to a buffer or heap overflow within the SoC firmware. Deadlocks, in contrast, lead the target device to a condition in which no further BT communication is possible.

This may happen due to the paging scan being forcibly disabled (V16), state machine corruption on V6 or entirely disabling BT functionality via arbitrary code execution (ACE) on V1. Our results affect popular BT vendors (i.e, Intel, Qualcomm, Cypress, Texas Instruments) and relatively less known (i.e., Bluetrum, Jieli Technology, Harman), which are still employed in many consumers products such as BT speakers, keyboards, toys, etc.

V1 affects ESP32, which is used in many products ranging from consumer electronics to industrial equipment such as programmable logic controllers (PLCs). Hence, the impact is significant, as the attacker only requires knowledge of the target BDAddress to launch the attack. Indeed, all the vulnerabilities V1-V16 can be triggered without any previous pairing or authentication. Moreover, the impact of V1-V16 reaches beyond the devices listed in Table 2, since any other BT product employing an affected SoC is also vulnerable.

Multiple Link Manager Protocol (LMP) flooding attacks (e.g., V4, V12) and V15 were detected across SoCs from different BT vendors. Since the affected vendors are majors in their fields (i.e., Intel & Qualcomm), it indicates that there is a lack of flexible tools for over-the-air testing even in 2021. Besides, the Core Specifications only allows a limited “LMP test mode” [27] that restricts the SoC to operate with few LMP procedures.

The most critical vulnerability ofBraktooth (V1 in Table 2 – 8.1) affects ESP32 SoC [30], which is used in many Wi-Fi and Bluetooth IoT appliances such as Industry Automation, Smart Home, Fitness, etc. The attack is illustrated in Figure 3. A lack of out-of-bounds check in ESP32 BT Library [9] allows the reception of a mutated LMP_feature_response_ext. This results in the injection of eight bytes of arbitrary data outside the bounds of Extended Feature Page Table (“E. Features Table” in Figure 3).

An attacker, which knows the firmware layout of a target device, can write a known function address (JMP Addr.) to the offset pointed by Features Page (“Feat. Page” in the LMP_feature_response_ext packet) field. It turns out that the BT Library stores some callback pointers within the out-of-bounds Features Page offset and such a callback is eventually invoked during the BT connection.

While exploiting this vulnerability, we forced ESP32 into erasing its NVRAM data (normally written during product manufacturing) by setting JMP Addr. to the address of nvs_flash_erase. Such erase function is always included in ESP32 SDK [7] and therefore, it is present in any ESP32 firmware. Similarly, disabling BT or BLE can be done via esp_bt_controller_disable and Wi-Fi via disable_wifi_agc.

Additionally, general-purpose input/output (GPIO) can be controlled if the attacker knows addresses to functions controlling actuators attached to ESP32. As expected, this has serious implications if such aBraktooth attack is applied to Bluetooth-enabled Smart Home products.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

SEC & FBI Warn Of Hurricane Ida Identity Theft Scams

The US Securities and Exchange Commission as well as the Federal Bureau of Investigation have warned citizens and investors to be “extremely wary” of both potential investment and identity theft scams related to the aftermath of Hurricane Ida.

The alert to investors was posted from SEC’s Office of Investor Education and Advocacy, which regularly issues warnings about the latest fradulent schemes prevalent in the country.

Scammers and cybercriminals are likely to set their targets on individuals and companies who recieve compensation from insurance companies as a result of damage done by Hurricane Ida.

“For example, the SEC brought a number of enforcement actions against individuals and companies who made false and misleading statements about alleged business opportunities in light of damage caused by Hurricane Katrina in 2005,” the SEC warning reads.

“Some of those cases involved pump-and-dump scams where fraudsters used bogus “news” to pump up the stock price of small companies so they could sell their own shares at artificially high prices.”

To protect yourself from investment fraud attempts, you should ask anyone approaching you with an investment opportunity if they’re licensed and if their investment is registered with the SEC or with a state.

“Take a close look at your entire financial situation before making any investment decision, especially if you are a recipient of a lump sum payment. Remember, your payment may have to last you and your family for a long time.”

The SEC alert was released just after a similar warning by the FBI’s New Orelans office, which issued two warnings in the last week – Both around alerting the public about an increased risk of fraudsters trying to capitalize on the Hurricane Ida natural disaster and carry out identity theft.

“Unfortunately, hurricane or natural disaster damage often provides opportunities for criminals to scam storm victims and those who are assisting victims with recovery,” the FBI warned.

The FBI also provided a set of measures those impacted by a natural disaster can take to avoid getting scammed, including to:

  • Not respond to unsolicited (spam) emails.
  • Be skeptical of individuals representing themselves over email as officials soliciting donations.
  • Not click on links within an unsolicited email.
  • Be cautious of emails claiming to contain pictures in attached files, as the files may contain viruses—only open attachments from known senders.
  • Not provide personal or financial information to anyone who solicits contributions; providing such information may compromise your identity and make you vulnerable to identity theft.
  • Be cautious of emails claiming to offer employment for which you did not expressly apply.
  • Thoroughly research housing ads before sending money to a potential landlord.

The Dangers of Identity Theft

Identity Theft can be absolutely devastating for an individual. Usually, in the world of malware, we know certain things can be harmed. Our devices may need to be replaced, we may lose access to accounts for a few days or even forever, we may even need to pay a ransom for access to our data. The point is, with most types of Malware, we can eventually rebuild, though it may take longer than we anticipate. The fallout from identity theft is much longer.

Once your stolen information is used once, it can take anywhere from a few days to six months for that one incident. But your information is out there for a very, very long time. This means you could end up dealing with identity theft for many years, even decades.

Identity Theft has been around for a very long time and predates our modern technology by thousands of years. There have always been individuals that try to impersonate others for their own gain, financial or otherwise. However, the internet’s birth and wide adoption have led to new attack vectors, dwarfing any possible past attempts.

Now more than ever do we have data tied into our personal identity. Email addresses, banking numbers, phone numbers, social security numbers, home addresses – All of these and more form a picture of us as lines in a database.

And when this information falls into the wrong hands, it can do a lot of damage. Bank accounts can be drained, and your credit rating can get rattled; you can end up with medical bills or even a criminal record. The list of potential mishaps that can arise from identity theft is endless.

To hackers, identity theft represents a lucrative stream of income, and they can very easily cover their tracks. After they have seized personal information, they sell it on the dark web. This information can be sold over time, repeatedly, meaning that if you notice your identity has been stolen and used, it can be used in several instances over a long period of years.

There are some guidelines from the US government in discovering if you are a victim of identity theft if it is not immediately obvious:

  • You stop receiving your regular bills and credit card statements.
  • You receive statements for accounts you never opened.
  • Debt collectors start calling you day and night about debts you’ve never heard of.
  • The IRS alleges you failed to report income for a company you never worked for.
  • You see withdrawals/charges on your bank or credit card statement that you didn’t make.
  • You try to file your taxes only to discover that someone else beat you to it.
  • You try to file your taxes and find someone claimed your child as a dependent already.
  • Your credit report includes lines of credit you never opened.
  • Your credit score fluctuates wildly and for no apparent reason.
  • The most obvious sign—you receive a notification that you’ve been the victim of a data breach.
  • If you are unsure, it is always best to check with the authorities on the US government’s identity theft website.

Protection

In some cases, a victim cannot be faulted for identity theft. For example, those affected by the data breach handed their information over to companies in good faith in the story above. Unfortunately, these companies, or more specifically the vendor, failed in protecting this information. However, many other times, business owners and families are singled out and targeted in their offices and homes.

For times like these, it is critical that you have the right tools to protect yourself. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Notorious Revil Ransomware Gang Resurfaces After Hiatus

The servers for the notorious ransomware strain REvil Ransomware have suddenly switched back online following a 2 month absence. The REvil Ransomware gang is one of the most profilic cybercriminal gangs, and operates from Russian. The gang is accused of leading a flurry of attacks in the past few years, with attacks in the last 12 months soaring. One of the most notable attacks this year was against meat supplier JBS, who paid a $11 million ransom to the gang.

On July 2nd, the REvil ransomware gang, aka Sodinokibi, used a zero-day vulnerability in the Kaseya VSA remote management software to encrypt approximately 60 managed service providers (MSPs) and over 1,500 of their business customers. The gang demanded $5 million from MSPs in exchange for the decrypter, and $70 million for a master decrypter for all Kaseya victims.

Later that week, the gang faced increasing pressure from law enforcement as US President Joe Biden held a summit with Russian Prime Minister Vladimir Putin, who agreed to tackle ransomware gangs within Russian borders.

Shortly after the summit, the REvil Ransomware gang dissapeared, and their servers and infrastructure were shut down. At the time, it left victims who wanted to negotiate with no clear path to do so.

Soon, Kaseya recieved the master decrypter from a “trusted third party”, which enable victims to decrypt all affected devices. It is still unknown who supplied this, though it is believed that Russian intelligence received the decryption key from the threat actors and passed it along to the FBI as a gesture of goodwill.

While the cybersecurity community were in good spirits following the apparent downfall of REvil Ransomware, both the Tor payment/negotiation site and REvil’s Tor ‘Happy Blog’ data leak site suddenly came back online this week.

The most recent victim on the blog was added on July 8th, 2021, just five days before REvil’s mysterious disappearance.

The Tor negotiation site is not yet fully operational, though shows a login screen which does not allow victims to log in.

The gang’s decoder is still offline at this time.

It is unclear what’s next for REvil Ransomware, but it seems that celebrations this summer were premature.

REvil Ransomware Analysis

REvil Ransomware is a Ransomware-as-a-Service (RaaS), meaning it can be sold on a subscription basis and is usable by just about anybody. In 2020, it extorted large amounts of money for corporations and individuals. According to researchers, it is the most widespread ransomware strain. Groups using have a knack for shaking down businesses that don’t meet their demands, often through threats or leaking dating.

REvil Ransomware, also known as Sodinokibi, first appeared in April 2019 and rose to prominence after another RaaS gang called GandCrab shut down its service. REvil was first advertised on Russian-language cybercrime forums. The main actor associated with advertising and promoting REvil ransomware is called Unknown aka UNKN.  In the early days of REvil, researchers and security firms identified it as a strain of GandCrab, or at least established multiple links between the two. An alleged member of the group, using the handle Unknown, confirmed in an interview that the ransomware was not a new creation and that it was built on top of an older codebase that the group acquired.

The group behind REvil Ransomware and other groups selling RaaS often do so on a commission basis. Usually, this means a cut of between 20% and 30% of the money earned through infecting victims with ransomware.

In 2020, the IBM Security X-Force Incident Response reported that 1 in 3 Ransomware infections were caused by REvil Ransomware.

In February 2021, the REvil ransomware operation posted a job notice where they were looking to recruit people to perform DDoS attacks and use VOIP calls to contact victims and their partners.

In March, a security researcher known as 3xp0rt discovered that REvil has announced that they were introducing new tactics that affiliates can use to exert even more pressure on victims.

These new tactics include a free service where the threat actors, or affiliated partners, will perform voice-scrambled VOIP calls to the media and victim’s business partners with information about the attack. The ransomware gang is likely assuming that warning businesses that their data may have been exposed in an attack on of their partners, will create further pressure for the victim to pay.

REvil Ransomware is also providing a paid service that allows affiliates to perform Layer 3 and Layer 7 DDoS attacks against a company for maximum pressure. A Layer 3 attack is commonly used to take down the company’s Internet connection. In contrast, threat actors would use a Layer 7 attack to take down a publicly accessible application, such as a web server.

It is highly configurable, and it can be customized to behave differently depending on the host. This makes it a highly attractive RaaS client. Some of its features include:

  • Exploits a kernel privilege escalation vulnerability to gain SYSTEM privileges using CVE-2018-8453.
  • Whitelists files, folders and extensions from encryption.
  • Kills specific processes and services prior to encryption.
  • Encrypts files on local and network storage.
  • Customizes the name and body of the ransom note, and the contents of the background image.
  • Exfiltrates encrypted information on the infected host to remote controllers.
  • REvil Ransomware uses Hypertext Transfer Protocol Secure (HTTPS) for communication with its controllers.

REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. If the configuration instructs a sample to execute this exploit, it will allocate executable memory, decrypt the exploit code in the newly allocated region and invoke it.

Protection Against Ransomware

REvil Ransomware and other Ransomware clients are some of the most common and deadly cybersecurity threats out there today. Families and businesses should be aware of these threats, and equip the right tools to tackle them. One of these tools is SaferNet.

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

New Meris Botnet Breaks Records With 21.8 Million Requests Per Second

Meris Botnet, a new distributed denial-of-service (DDoS) virus, emerged over the summer and began a barrage of attacks on internet giant Yandex and has recently peaked its attack speed at 21.8 million requests per second. Meris Botnet gets its power from tens of thousands hacked devices that researchers believe to be networking equipment. It gets its name from Latvian, where Meris means ‘plague’

Last week Russia media covered the attack on Yandex, and described it as being the largest in the history of the Russian internet – also called RuNet. RuNet is the Russian segment of the internet, created to function independently of the worldwide web. Its purpose is to maintain the unified country-wide communication infrastructure running in case of a cyber attack from a foreign adversary. It is actively monitored by Russian authorities.

Details on the attacks were published lately in joint research from Yandex and its DDoS protection partner, Qrator Labs. Information collected by the researchers showed that Meris Botnet has a striking force of 250,000 devices under its control.

“Yandex’ security team members managed to establish a clear view of the botnet’s internal structure. L2TP tunnels are used for internetwork communications. The number of infected devices, according to the botnet internals we’ve seen, reaches 250000” stated researchers at Qrator Labs.

Initial research put the number at 30000, which is the amount Meris Botnet has used in most cases. However, it is believed that the botnet operators are using lower numbers for now as to not parade the full power of their botnet.

Qrator pointed out that compromised hosts in Meris Botnets’ collection are “not your typical IoT blinker connected to WiFi”, but more capable devices that require an Ethernet connection. This speaks volumes about the development behind Meris Botnet – Usually, botnets will go for ‘low-hanging fruit’ when looking for IoT devices to infect.

Meris Botnet was also responsible for generating the largest volume of attack traffic that Cloudflare recorded and mitigated, which peaked at 17.2 million requests per second. This was broken by the botnets later September 5th attack, which as stated reached 21.8 million RPS.

Meris Botnet’s attacks on Yandex began in early august with a hit of 5.2 million RPS and gradually increased:

2021-08-07 – 5.2 million RPS
2021-08-09 – 6.5 million RPS
2021-08-29 – 9.6 million RPS
2021-08-31 – 10.9 million RPS
2021-09-05 – 21.8 million RPS

Meris Botnet Analysis

Note: This analysis was carried out by Qrator Labs.

To deploy an attack, the researchers say that Mēris relies on the SOCKS4 proxy at the compromised device, uses the HTTP pipelining DDoS technique, and port 5678.

As for the compromised devices used, the researchers say that they are related to MikroTik, the Latvian maker of networking equipment for businesses of all sizes.

Most of the attacking devices had open ports 2000 and 5678. The latter points to MikroTik equipment, which uses it for the neighbor discovery feature (MikroTik Neighbor Discovery Protocol).

Qrator Labs found that while MikroTik provides its standard service through the User Datagram Protocol (UDP), compromised devices also have an open Transmission Control Protocol (TCP).

This kind of disguise might be one of the reasons devices got hacked unnoticed by their owners,” Qrator Labs researchers believe.

Distribution of open ports 5678. The darker shows where there are more devices. Source: Qrator Labs

When searching the public internet for open TCP port 5678, more than 328,000 hosts responded. The number is not all MikroTik devices, though, as LinkSys equipment also uses TCP on the same port

Port 2000 is for “Bandwidth test server,” the researchers say. When open, it replies to the incoming connection with a signature that belongs to MikroTik’s RouterOS protocol.

MikroTik has been informed of these findings. The vendor told Russian publication Vedomosti that it is not aware of a new vulnerability to compromise its products.

The network equipment maker also said that many of its devices continue to run old firmware, vulnerable to a massively exploited security issue tracked as CVE-2018-14847 and patched in April 2018.

However, the range of RouterOS versions that were observed in attacks from Meris botnet varies greatly and includes devices running newer firmware versions, such as the current stable one (6.48.4) and its predecessor, 6.48.3.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

Medical-Tech Giant Olympus Infected With BlackMatter Ransomware

BlackMatter Ransomware has struck Olympus, a leading medical technology company. Olympus announced last week it was investigating a “potential cybersecurity incident” that impacted some of its EMEA (Europe, Middle East, Africa) IT systems last week. The company employs 31,000 individuals worldwide and has been active for over 100 years, making developments in the medical, life sciences, and industrial equipment industries.

“Olympus is currently investigating a potential cybersecurity incident affecting limited areas of its EMEA (Europe, Middle East, Africa) IT systems on September 8, 2021,” the company said in a statement published Saturday, three days after the attack.

“Upon detection of suspicious activity, we immediately mobilized a specialized response team including forensics experts, and we are currently working with the highest priority to resolve this issue. As part of the investigation, we have suspended data transfers in the affected systems and have informed the relevant external partners.”

Olympus also stated that they’re still working to discover the extent of the damage caused by the BlackMatter Ransomware attack.

Though the company themselves have not confirmed BlackMatter Ransomware was the culprit, ransom notes left on impacted systems point to the gang as the perpitrators.

BlackMatter Ransomware was initially considered to be a newcomer on the scene when it appeared in late July 2021, though it is now confirmed that it is simply a rebrand of Darkside Ransomware.

The Darkside operation shut down after the Colonial Pipeline attack earlier this year as the gang were facing pressure from both international law enforcement and the US government.

BlackMatter Ransomware Analysis

This analysis of Darkside was carried out largely by researchers at Cybereason. It was completed before the gang retired. As BlackMatter Ransomware and DarkSide share the same codebase, the analysis is valid.

Like many other ransomware variants, BlackMatter follows the double extortion trend, which means the threat actors not only encrypt the user’s data, but first exfiltrate the data and threaten to make it public if the ransom demand is not paid. This technique effectively renders the strategy of backing up data as a precaution against a ransomware attack moot.

After gaining an initial foothold in the network, the attackers start to collect information about the environment and the company. If it turns out that the potential target is on the attacker’s list of prohibited organizations to attack (ie: hospitals, hospices, schools, universities, non-profit organizations, or government agencies), they don’t move forward with the attack.

If not on the prohibited list, the attackers continue to carry out the operation. The attackers begins to collect files, credentials and other sensitive information, and exfilitrate it. Following this, the attackers use PowerShell to download the BlackMatter Ransomware binary as “update.exe” using the “DownloadFile” command, abusing Certutil.exe and Bitsadmin.exe in the process.

In addition to downloading the BlackMatter Ransomware binary into the C:\Windows and temporary directories, the attacker also creates a shared folder on the infected machine and uses PowerShell to download a copy of the malware there.

After successfully gaining a foothold on one machine in the environment, the attacker begins to move laterally in the environment, with the main goal of conquering the Domain Controller (DC).

Once the attackers make it to the DC, they start to collect other sensitive information and files, including dumping the SAM hive that stores targets’ passwords

In addition to collecting data from the DC, the attackers use PowerShell to download the BlackMatter binary from the shared folder created on the previously infected host.

When the BlackMatter ransomware first executes on the infected host, it checks the language on the system, using GetSystemDefaultUILanguage() and GetUserDefaultLangID() functions to avoid systems located in the former Soviet Bloc countries from being encrypted.

Darkside Ransomware checking if the installed language is Russian

After gaining an initial foothold in the network, the attackers start to collect information about the environment and the company. If it turns out that the potential target is on the attacker’s list of prohibited organizations to attack (ie: hospitals, hospices, schools, universities, non-profit organizations, or government agencies), they don’t move forward with the attack.

If not on the prohibited list, the attackers continue to carry out the operation. The attackers begins to collect files, credentials and other sensitive information, and exfilitrate it. Following this, the attackers use PowerShell to download the BlackMatter Ransomware binary as “update.exe” using the “DownloadFile” command, abusing Certutil.exe and Bitsadmin.exe in the process.

In addition to downloading the BlackMatter Ransomware binary into the C:\Windows and temporary directories, the attacker also creates a shared folder on the infected machine and uses PowerShell to download a copy of the malware there.

After successfully gaining a foothold on one machine in the environment, the attacker begins to move laterally in the environment, with the main goal of conquering the Domain Controller (DC).

Once the attackers make it to the DC, they start to collect other sensitive information and files, including dumping the SAM hive that stores targets’ passwords

In addition to collecting data from the DC, the attackers use PowerShell to download the BlackMatter binary from the shared folder created on the previously infected host.

When the BlackMatter ransomware first executes on the infected host, it checks the language on the system, using GetSystemDefaultUILanguage() and GetUserDefaultLangID() functions to avoid systems located in the former Soviet Bloc countries from being encrypted.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.

SOVA Android Banking Trojan Takes Flight With Big Dreams

A new Android banking trojan dubbed SOVA (“Owl” in Russian) has emerged and is active development according to researchers at ThreatFabric. Though still in the early stages, SOVA is looking to be extremely sophisticated for Android malware and may pose a serious threat upon release. SOVA seeks to incorporate distributed denial of service (DDoS), man in the middle (MiTM) and ransomware functionality into its arsenal – on top of existing banking overlay, notification manipulation and keylogging services.

Researchers at ThreatFabric note that the hackers ambitions for SOVA are sky-high.

“This malware is still in its infancy [first appearing in August, now only on version 2] and it is undergoing a testing phase…prospecting serious and worrying plans for the near future,” they said in a Friday analysis, noting that the malware’s roadmap is laid out in underground forum posts advertising its availability for testing.

“SOVA is…taking a page out of traditional desktop malware,” they added. “Including DDoS, man in the middle and ransomware to its arsenal could mean incredible damage to end users, in addition to the already very dangerous threat that overlay and keylogging attacks serve.”

Analysis of SOVA showed that the coding and development choices behind the virus are highly sophisticated.

“Regarding the development, SOVA also stands out for being fully developed in Kotlin, a coding language supported by Android and thought by many to be the future of Android development,” according to ThreatFabric. “If the author’s promises on future features are kept, SOVA could potentially be the most complete and advanced Android bot to be fully developed in Kotlin to this day.”

SOVA, like many other malware strains, relies on legitimate software to function. In SOVA’s case, it uses RetroFit for its communication with the command-and-control (C2) server.

“Retrofit is a type-safe REST client for Android, Java and Kotlin developed by Square,” researchers said. “The library provides a powerful framework for authenticating and interacting with APIs and sending network requests with OkHttp.”

SOVA makes use of a banking trojan mainstay – Overlays. However, the malware uses multiple overlays to imitate a number of banking institutes worldwide.

“According to the authors, there are already multiple overlays available for different banking institutions from the U.S. and Spain, but they offer the possibility of creating more in case of necessity from the buyer,” researchers noted. Also, version 2 contains functionality to target users of some Russian banks – drawing ire from other forum users, ThreatFabric reported.

“When it is started for the first time, the malware hides its app icon and abuses the Accessibility Services to obtain all the necessary permissions to operate properly,” researchers explained. Some of those permissions allow it to intercept for SMS messages and notifications for instance, to better hide from the victim – and on the roadmap is also the ability to circumvent two-factor authentication.

One feature that sets SOVA apart from its contemperoarys is its ability to steal session cookies. This allows the virus to piggyback on valid logged-in banking sessions, thus skirting the need to have banking credentials to access victim’s accounts.

Still ahead on the roadmap, SOVA’s authors said that they will soon add “automatic three-stage overlay injections.”

“It is not clear what the three stages imply, but it could mean more advances and realistic process, maybe implying download of additional software to the device,” researchers noted.

ThreatFabric concluded by pointing out that SOVA could become one of the most dangerous threats in the Android ecosystem.

“The second set of features, added in the future developments, are very advanced and would push SOVA into a different realm for Android banking malware,” they said. “If the authors adhere to the roadmap, it will also be able to feature…DDoS capabilities, ransomware and advanced overlay attacks. These features would make SOVA the most feature-rich Android malware on the market and could become the ‘new norm’ for Android banking trojans targeting financial institutions.”

SOVA Analysis

Note: This analysis was carried out by ThreatFabric.

Currently, ThreatFabric identified five samples of SOVA in the wild, with a total of three different malware versions.

The string highlighted, underneath the file’s hash, is the name the file was uploaded to VirusTotal with. The file name is ‘vormastor test crypted.apk’. As mentioned in the introduction, we conclude that this malware family is still in its testing phase and has been for a few weeks. This is confirmed by a post by the author and seller of SOVA, who was already looking for testers at the end of July.

At the beginning of September, this same user published the first post aimed at selling the bot. In the same thread, the seller is being criticized by other members for having Russian banks within the list of targets. From this thread it also seems that the future versions of this Android malware could switch back to Java, to address some compatibility issues with the obfuscation software they are using.

According to the authors, there are already multiple overlays available for different banking institutions from the USA and Spain, but they offer the possibility of creating more in case of necessity from the buyer.

The main objective of SOVA is to gather the victim’s PII.

SOVA tries its best to remain undetected. To achieve this, SOVA abuses the overlay mechanic to trick victims into revealing their passwords, and other important private information. In an overlay attack, users type their credentials in what they think is a legitimate banking app, effectively giving them to a page controlled by the attacker. SOVA also has the possibility to steal session cookies from the device. This feature is not unheard of but is definitely not common on modern Android Trojans.

Like most of the banking trojans, SOVA heavily relies on Accessibility Services. When it is started for the first time, the malware hides its app icon and abuses the Accessibility Services to obtain all the necessary permissions to operate properly.

Functionalities of the bot, as advertised by its authors, include:

  • Steal Device Data.
  • Send SMS.
  • Overlay and Cookie injection.
  • Overlay and Cookie injection via Push notification.
  • USSD execution.
  • Credit Card overlays with validity check.
  • Hidden interception for SMS.
  • Hidden interception for Notifications.
  • Keylogger.
  • Uninstallation of the app.
  • Resilience from uninstallation from victims.

The features that SOVA offers are in line with the standard for Android malware that we are used to see in 2021. However, as previously mentioned, the criminals behind this bot are very proactive and have also released a detailed roadmap of the features to be included in the future releases ofSOVA:

  • Automatic 3 stage overlay injections.
  • Automatic cookie injections.
  • Clipboard manipulation.
  • DDoS
  • Improved Panel Health.
  • Ransomware (with overlay for card number).
  • Man in the Middle (MitM).
  • Normal Push notifications.
  • More overlays.
  • VNC.

The following list includes all the commands that can be send by the C2 to the bot:

Like the large majority of Android banking trojans, SOVA relies on Overlay attacks to steal PII from its victims. If the user is trying to access a banking application included in SOVAs active target list, the malware will be notified with Accessibility Services, and will display a WebView overlay posing as the intended banking application.

In the following graph you can observe the country distribution of the targets:

Another interesting feature of SOVA, which is uncommon in Android malware, is the ability to steal cookies. Cookies are a vital part of web functionality, which allow users to maintain open sessions on their browsers without having to re-input their credentials repeatedly. A malicious actor in possession on a valid session cookie has effectively access to the victim’s logged in web session.

Protection

SaferNet is the perfect solution to the cybersecurity issues that individuals, families, and businesses face today. It not only connects every device using a secure, 24/7 always on, military grade VPN, but it also stops outside cyberthreats, malware and viruses as well. On SaferNet, all users are protected anywhere in the world, all the time, on any cellular or Wi-Fi network. In addition to SaferNet’s VPN and cyber protection, it also offers a range of employee or parental/family internet controls including internet filtering, monitoring, scheduling, and blocking access to websites or even entire website categories

Typically, a business or family would need 3 separate services for a VPN, Malware Protection, and Internet Controls; SaferNet offers all 3 features in one service. SaferNet truly is an endpoint security presence that can be implemented in minutes around the world, on phones, laptops, tablets, and computers at an economical price point that caters to all sizes of businesses and families. SaferNet guarantees a smooth setup and installation process that takes only minutes, and an easily accessible control hub for you to monitor all your employee’s or family members devices; including activity, time spent online, and threats blocked.