Showing posts with label Krebbs. Show all posts
Showing posts with label Krebbs. Show all posts

Thursday, April 23, 2020

APWG 4th Quarter Report 2019

Fraud and confidence schemes of the modern day: Phishing

History:

Prior to sophisticated electronics and computers, fraudsters or con men found ways with far less technical means to swindle people out of anything of value.  Then came the Internet. 
Phishing has its roots in the 1790's, and more recently 1990's with Vic Commodore computers, AOL, credit cards number thefts and the Warez community.  "The Warez Scene" as it is known was a group of people specializing in distribution of pirated content dating back to 1975.  Phishing attempts were crude in the early days.  As phishing became more prominent criminal elements started to get focused: first on selecting specific companies as targets, then focusing on extorting top tier executives and eventually the complete hostage taking of companies technical assets (software, hardware, networks) with the introduction of ransomware.   

The internet just made all of this a lot easier. In 1995 random credit generators existed with the use of algorithms.  For a more complete reading see Ed Skoudis' Malware timeline that tracks the growth of technology, industry and subterfuge.  January 2, 1996 the term phishing was for the first time posted on a Usenet group on AOL.  By September of 2003 hackers and con men began registering domains of popular companies, by October of 2003 Pay Pal users found malware contained on clickable emails and the Minmail Virus was introduced to the public.  

2004 produced another first as email solicitations for the U.S. Presidential campaign of John Kerry came in from bogus sites in India and Texas.  Phishing was now making its debut in US Presidential campaigns.  Fraudsters continued to use phishing in the years following and in its pursuits found novel ways to leverage the internet like link manipulation, web site cloning, filter evasion, website forgery, covert redirect and much more.

Today APWG provides an annual report for phishing and much of the same rings true about fraud and con men.  They find a soft spot and prey on their victim.  They are patient, technically smart and hungry for a win while the rest of us are just trying as best as we know how to avoid them at all cost.  

Who is APWG?

The APWG is registered as a U.S. based 501(c)6 corporation (a business oriented not for profit) as defined by the the IRS internal revenue code.  On its web site APWG states, it is a international coalition unifying the global response to cybercrime across industry, government, law enforcement and NGO communities.

APWG.EU the institution's European chapter established in Barcelona in 2013 as a non-profit research foundation incorporated in Spain and managed by an independent board, including APWG founding directors; and the STOP. THINK. CONNECT. Messaging Convention, Inc., a US-based non-profit 501(c)3 corporation jointly managed by APWG and Washington, D.C.-based N.C.S.A..

What is Phishing?

Phishing as defined by the APWG (anti phishing working group) is a crime employing both social engineering and technical subterfuge to steal consumers’ personal identity data and financial account credentials. Social engineering schemes prey on unwary victims by fooling them into believing they are dealing with a trusted, legitimate party, such as by using deceptive email addresses and email messages. These are designed to lead consumers to counterfeit Web sites that trick recipients into divulging financial data such as usernames and passwords. Technical subterfuge schemes plant malware onto computers to steal credentials directly, often using systems that intercept consumers’ account user names and passwords or misdirect consumers to counterfeit Web sites.

What are the numbers?

Thousands of URL's emanating from hundreds of thousands of web sites


APWG tracks phishing sites which can consist of hundreds if not thousands of URL's all leading to the same attack destination.  Web sites reported for Q2 and Q3 2019 represented a larger number of web sites than those reported Q4 for 2019 on a quarter by quarter basis for that year.  However a year to date look at Q4 2019 Vs Q4 2018: 162,155 Vs 138,328 respectively represents a 14.694% increase.  The summer months of July, August and September 2019 showed the months greatest increase roughly between 80-90 thousand phishing web sites reported per month.

 Greg Aaron, APWG Senior Research Fellow and President of Illumintel Inc., stated “July though October was the worst period for phishing that the APWG had seen in three years, and then phishing levels settled back down to more normal levels.”

In the news: COVID-19

"Cyber-criminals are already targeting healthcare organizations—specifically hospitals—with phishing campaigns, ransomware, and other malicious acts that can adversely impact health information technology, medical response, and patient safety. As cases of the virus began to increase in the US, so too did the amount of email-based phishing campaigns referencing COVID-19." https://cyber.nj.gov/alerts-advisories/cyber-threats-cybersecurity-for-healthcare-during-covid-19

"Threat actors are targeting Small and Midsize Businesses (SMBs) with phishing emails in an attempt to deliver the Remcos remote access trojan (RAT). Aimed at SMBs that may be experiencing financial problems from COVID-19 shutdowns, the threat actor impersonates the US Small Business Administration (US SBA)." https://cyber.nj.gov/alerts-advisories/threat-actors-target-smbs-using-government-grant-phishing-emails

"After three years, the Zeus Sphinx banking trojan has resurfaced in coronavirus-themed phishing campaigns containing information on government relief payments." https://cyber.nj.gov/alerts-advisories/zeus-sphinx-banking-trojan-and-other-covid-19-financial-relief-phishing-campaigns

"Google found there were 149,195 active phishing websites in January. That number rose by 50 percent in February to 293,235 websites. Now, in March, there are 522,495—a 350 percent increase since the beginning of the year." https://www.pcmag.com/news/phishing-attacks-increase-350-percent-amid-covid-19-quarantine

"The COVID-19 pandemic has created an environment ripe for fraudulent activity, with threat actors leveraging fears of the virus to perpetrate a variety of malicious and criminal exploitation. Observed scams and fraud have included selling fraudulent personal protective equipment (PPE), hawking fake cures and tests, spreading disinformation, phishing campaigns, and other related scams. The Intelligence Bureau (IB) assesses that this activity will continue, and it will potentially pivot to leverage changing government responses to the pandemic and shifting needs for supplies. Additionally, the IB assesses that cyber-enabled crime will also evolve to prey upon the public’s need to remain updated on the stream of ever-changing COVID-19-related information and may shift from COVID-19 themed outbreak to recovery lures."  NYPD SHIELD, 04/23/20
Attribution: 4/23/20 conference call

Sectors:

The most targeted sectors for 2019 was shown as a pie chart as follows:

  • Saas / web mail 30.80%
  • Payment card industry 19.80%
  • Financial institutions 19.40%
  • Social media 6.80%
  • E commerce / retail 5.4%
  • Cloud storage / file hosting 3.4%
  • Telecom 3.3%

Business email compromise campaigns:

As noted by APWG: In a BEC (Business email compromise) attack, a scammer targets employees who have access to company finances, usually by sending them email from fake or compromised email accounts (a “spear phishing” attack). The scammer impersonates a company employee or other trusted party, and tries to trick the employee into sending money.  APWG states attackers could prepare for weeks for such an attack inside financial systems, personnel systems and other area likely to produce a positive harvest of legitimate looking emails.  The BEC attack is said to cost the industry billions of dollars. Wire transfers can be 5 to 20 times larger in the amount of money gained by attackers over gift cards whose amounts are generally much smaller.  The use of gift cards is stated to be used as a way of laundering other funds to buy physical goods which can later be sold rather than put them into cryptocurrency exchanges, which is said to be another popular way of laundering money.

Schemes:

The following is a list of schemes in priority:

  • Gift card (click here: Google play cards scheme {most request} decreased but eBay, Target, Best Buy, and Sephora all saw increases)  62%
  • Direct transfer 22%
  • Payroll diversion 16%
Taken from a conference call 4/23/20:

Analysis:

Deception of others and stealing (confidence schemes, con games) is not uncommon, however use of the internet since the 1990's has created miles of new paths to travel for those with criminal intent.  Our nation has and is enduring heart-ships heretofore not contemplated (9/11, COVID-19).  Duping of unsuspecting victims will continue to happen using these incidents and a great many others to pry money out of the hands of unsuspecting victims. It is said 93% of data breaches are still caused by phishing incidents with the cost estimated at 1.6 million dollars for mid sized companies. These incidents will continue for some time to come.  Awareness training should continue as a mitigation strategy to reduce the incidents.

Update 4/23/20: Corporate email 


Per conference call today 4/23/20 thanks to everyone on the call.  We are also reviewing a NYPD Shield report 4/20/20 and when we have a green light will post highlights on this page.

Selected Terms:

  • APWG: Anti Phishing Working Group
  • BEC: business email compromise
  • SSL: Secure sockets layer, standard security technology for establishing a encrypted link between a server and client (web site)
  • Saas: Software as a service
  • gTLD: Generic top level domains legacy, such as: .com, .org, .Asia, .biz
  • nTLD: New generic top level domains examples: .work, .icu
  • ccTLD: Country code domains examples: .UK, .MX
  • NCSA: National cyber security alliance
  • Spear phishing: email spoofing attack that targets a specific organization or individual, seeking unauthorized access to sensitive information
  • Whale phishing: is a specific type of phishing attack that targets high-profile employees in order to steal sensitive information from a company
  • Smishing phishing: criminals sending text messages via telephones
  • Viinishing phishing: is an actual telephone conversation
  • Angler phishing: Fake URL's, cloned web sites, social media etc.


Thursday, April 16, 2020

Zooming not so fast....slow down

Video Conferencing Software/Weak Security?


Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms

Zoom, the video conferencing software maker learned a lot of lessons this past month as a result of legions of new visitors who stopped by and signed up as new customers.  The software company Zoom updates from the past weekliterally exploded with new customers during Mid March 2020 as a result of the COVID -19.  However a number of security incidents started happening and with that a fire hose of commentary poured into their email boxes, security blogs, conference calls and forums.  Security professionals came on strong.  One security practitioner commented that the right out of the box the default settings needed serious review and the general public was at the point of the spear - buyer beware.  Waiting rooms, passwords, and many other enhancements all focused on security and reducing risk were heard from all quarters.  

To the credit of Zoom, now known as that easy, cheap video conferencing software have made the changes to improve security (change to many of the default settings, like requiring password as a default for all meetings, establishing a waiting room so you can verify participants and sprinkling of the message not to share passwords, etc) and reduce the risks to many of its users. Zoom has taken it on the chin for many in this functional area: "Video Conferencing Brands" while the rest of the pack gets the opportunity to take another look at security.  Zoom brought on a security professional and kinder days seem to be in the future. Zoom also has a HIPAA compliant application separate from what general users get to use.  See the photo above for the last known update from Zoom.  Zoom is growing and has been sending out improvements as they become available.

Video Conference Software:

Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms



Here are some additional products for consideration:
  • GoToMeeting
  • Webex Teams
  • Skype for business
  • Google Hangouts
  • Join.Me LogMeIn
  • Amazon Chime
  • Microsoft Teams
  • Cisco Webex Meetings
  • Updox
  • Vsee
  • Zoom for healthcare
  • Spruce health care messenger
  • Apple Face Time
  • Doxy.me
  • Face Book Messenger Chat
  • Blue Jeans - recently purchased by Verizon
Check out each of these products and note well during a declared national emergency many if not all maybe used without compliance penalty.  However, after the emergency is over please do use HIPPA compliant software.  See shorturl.at/fijHL for future updates at U.S. H.H.S. dot gov.


NIST - Navigating the Conference Call Security Highway



Today 4/25/20 I reviewed an article from Dr Eric Cole, Secure Anchor Consulting. These are some of his thoughts:

Zooming now household word
Due to pandemic March/April 2020 video conferencing increases 1000 fold.  "Zooming" takes on a life of its own for all brands of video conference calling software.
ZOOM BOMBING:  DEFINED
Is where a person joins into Zoom video conferencing calls uninvited and either 1.) listens in, 2.) gathers important info to use at a later time or 3.) become disruptive to your meeting or event.
How do you protect a Zoom call?
    1. Remember you are a target, 2. Cyber security is your business, 3. Make sure your software is up to date. 

    • Make sure your computer operating system is up to date
    • Make sure your Zoom app is up to date and other apps as well
    • Make sure you are using anti-virus software and its up to date
    • Do not post Zoom links in the public eye
    • Don't click on links you don't know
    • Setting up meetings:
      • Use strong passwords
      • Do not share the meeting ID
      • Use a non obvious meeting ID
      • Use the waiting room function
      • Lock the meeting once everyone is in

New Post: 5/5/20


Jeff Furman my "go to guy" for Project management hosts a blog and has some Zoom fun and other suggestions check it out here:  https://www.linkedin.com/pulse/so-your-internet-crashes-middle-zoom-session-what-you-jeff-furman/

Take a peek at the: Project Management Answer book click the link.

New Post: 5/7/20 am

On a conference call today.  Discussion of fat client verses thin client again for VT software (for the young at heart this seems to reoccur every 5-10 years), functionality services were discussed (I think more of what you are used to using drives the most favorite product discussion) and end to end encryption took place.   Zoom came up and given that it is slowly improving its security posture some note it is moving into the "pack" of other VT implementations given that it will become less of a pick up and use utility because of security concerns.  Those with more security concerns and less functionality can look here: https://www.infosecnews.org/national-security-agency-releases-guide-to-secure-video-conferencing

New Post: 5/7/20 pm

Take a look at this very comprehensive post from Citizen Lab:
https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/

Then this video by none other than: Dr Eric Cole

A few weeks ago there was a lot in the news about ZOOM Bombing. So ZOOM took action and set up some default security to 'appease the masses'. But here's the thing... they did too little, too late AND ZOOM meetings are still being targeted.
It's not over! The adversary is still on the prowl and creating havoc.
I recorded a quick video for you to share with your organization to help keep the awareness around how to protect against ZOOM Bombing.

Dr Coles Tips:


#security  #cybersecurity @Zoom @NIST #VideoConferenceCalling #VT #DrEricCole  #zoombombing


Last edit: Monday, 5/5/20 0930 hours











Friday, October 21, 2016

Cyber Security Month: Looking for Answers Part II?


NEW YORK METRO JOINT CYBER SECURITY CONFERENCE
NY Metro Joint Cyber Security Conference
I recently attended the Third Annual New York Metro Joint Cyber Security Conference (http://nymjcsc.org/), held in mid-town Manhattan.  Security conferences are now a dime-a-dozen, but this event is unique in that it is a collaborative effort developed by a consortium of eight leading security, audit, and risk focused, NY metropolitan area, not-for-profit professional associations. Each organization brings its best to the table, creating a rare combination of expertise and diversity of talent.  

There were many informative sessions – some standing room only – but some of the greatest value was in the interaction with the other professionals.  For example, in sessions, we learned that security professionals must adopt the language of Directors to be understood by a Board.  The Internet Security Alliance is even working on metrics for Boards to use in evaluating security risks and controls.  But, after all the talk of security maturity models, cyber risk management frameworks, and “cyber balance sheets,” CISOs (Chief Information Security Officers) will tell you that Boards still “just don’t get it” and don’t seem to be that interested.  Perhaps CISOs as a group aren’t very good at explaining how greater focus on preventing and mitigating cyber threats is in the self-interests of very diverse sets of Directors.  Maybe, despite approaching the problem with the best of business concepts and lingo, CISOs just don’t have influence with Directors.  (As one CISO put it, “formulas don’t work.  Relationships do.”) Or, perhaps it’s because, as one speaker put it, there is not a single instance of a cyber breach that has been demonstrated to have a material impact on a company.  In the end, the surprising takeaway may not be that CISOs are becoming more adept at speaking the language of the Board, but that some Boards are beginning to listen at all.
This sold-out event offered excellent, high-quality presentations with plenty of actionable content.  If you weren't able to attend, you can still benefit from the recordings of many of the sessions.  They are available at http://livestream.com/internetsociety/nymjcsc/.  Presentation slides may be found at http://tinyurl.com/z3fz44d. I would highly recommend reviewing them.
And, don't forget to sign up early for next year's conference.  It's one of the best values in information security education that you'll find anywhere.  Follow www.nymjcsc.org and @NYMJCSC for details.

Phil Froehlich is Chief Operating Officer of Integris Security and a member (who listens) of the Executive Board of New York Metro InfraGard.

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/

Wednesday, December 3, 2014

The Rear View Mirror

Typical in the information technology sector everyone is always focused on what’s next, the latest, hottest new application, the coolest mobile telephone and of course the work around that just makes life a little easier.  Not to be ignored are all those newly fashioned functions and features. Technology at the speed of life forever changing our lives for the better, right?  Forward looking for ever.

2014 hopefully has hopefully taught us some very important lessons that should not be ignored even if we were not directly impacted.  A look in the rear view mirror can sometimes be very revealing.  We are so focused on what’s coming directly ahead of us that we refuse to see what’s going on right behind us.  So for 2014 let me list a couple of things which could have made this a better year in the security space.

Network segmentation: You can’t get there from here should be the mantra, no? Did we learn anything this past year? Network segmentation is the act or profession of splitting a computer network into subnetworks, each being a network segment or network layer. Advantages of such splitting are primarily for boosting performance and improving security.   Please review a great eWeek article clicking here.

Service Level Agreements: Service agreements are important and a quick web search can be helpful to identify some key questions for developing such important tools for your company. The Outsourcing Center has developed ten key questions for developing effective service level agreements. It’s a solid read and you’ll find plenty of similar research on the web. A service-level agreement (SLA) is a part of a service contract[disambiguation needed] where a service is formally defined. Particular aspects of the service - scope, quality, responsibilities - are agreed between the service provider and the service user. A common feature of an SLA is a contracted delivery time (of the service or performance). As an example, Internet service providers and telcos will commonly include service level agreements within the terms of their contracts with customers to define the level(s) of service being sold in plain language terms. In this case the SLA will typically have a technical definition in terms of mean time between failures (MTBF), mean time to repair or mean time to recovery (MTTR); identifying which party is responsible for reporting faults or paying fees; responsibility for various data rates; throughput; jitter; or similar measurable details. {Attribution: Wikipedia}

Too big to fail: While not at all a technical term your company would do well to heed this warning. No company is too big to fail. No one. In our recent newsletter we talked about the breach of the week. The roadway is littered with companies failing over and over again until everyone in the industry is just tired of hearing of another breach. The breaches become “white noise” a distraction from the good work being performed by many security professionals in the field. Fight complacency, challenge everything and everyone with respect and “ASK Questions”. It won’t make you popular but it will certainly make you a very, very valuable employee.  Please read the ARS Technica article   HERE because it puts good perspective of what can happen after a breach. 

Alarms: Alarms are invitations that are yelling out, “come investigate me” I’m making noise and need your direct undivided attention. Please don’t ignore alarms. The story goes like this: Hey did you hear that alarm go off? Yeah, I’m getting a cup of coffee – you want anything? Hey, maybe I’ll come with you. Great! How many times do we ignore the obvious? Alarms are put in place for a reason to warn us, right? If the alarms are not configured appropriately and are creating noise, then someone has to go in and make a determination to turn them down and accept the consequences or turn them up and act each time they alert. 

Egress Filtering: Is that a freight train of information running out of our company? Egress filtering is protecting what’s going out as well as protecting others from malware coming from inside your own company. In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled. Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network. In a corporate network, typical recommendations [2][3][4][5] are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy. Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks. The purpose is to prevent computers on the internal network from IP address spoofing. Such "spoofing" is a common technique used in "Denial of Service" attacks. {Attribution: Wikipedia}

Enumeration: Thanks to Wikipedia we know that Network enumeration is a computing activity in which usernames and info on groups, shares, and services of networked computers are retrieved. It should not be confused with network mapping, which only retrieves information about which servers are connected to a specific network and what operating system run on them. Network Enumeration is the discovery of hosts/devices on a network, they tend to use overt discovery protocols such as ICMP and SNMP to gather information, they may also scan various ports on remote hosts for looking for well-known services in an attempt to further identify the function of a remote host. The next stage of enumeration is to fingerprint the Operating System of the remote host.

We hope that this short laundry list helps each of you.  We understand the complications of local, national and global enterprises.  None of this is easy, but neither is dealing with the stockholders and the media if your company falls victim to a breach or other such incident.

Thursday, October 9, 2014

Cyber Security Awareness Month

Now not half way into DHS Cyber Security Awareness Month and the industries leading computer organizations in NYC have hit the ground running with their first joint conference, a success,  ushered in without nearly breaking a sweat.

NY Metro InfraGard, ISSA, ISACA, OWASP, Cloud Security and others joined together with over 300 security professionals in Brooklyn, NY at St Francis College.  The lectures showcased outstanding sessions on Active Directory and a number of security and related discussions.
The all day event produced a Women in Security panel as the
afternoon plenary event.

Most attendee's remarked that this was the opening for the 2015 joint Cyber Security Conference which all believe will now be an annual event.  Congratulations to the organizing committee who persisted and stayed on course to make this important event happen.  A big thank you to St Francis College in Brooklyn for moving heaven and earth to make this happen and for being flexible during the days events.

We look forward to seeing more of this next year.

Friday, June 6, 2014

Blackshades - an international hazard

It is important to note that as I start this discussion readers are reminded that while malware today is portrayed as dangerous, destructive and part of a criminal enterprise viruses, worms and trojans were and sometimes continue to be little pieces of code which help automate things.

The very first virus written wasn't an assault on a major banking institution, rather is enabled a programer to automate repetitive or tedious tasks.

With that said, The FBI has recently reported in a sterilized press release that International Blackshades - has been taken down.  What we don't read in the release is perhaps as instructive as what is placed on paper.  Thus a good reason to dig a bit deeper and try to wrap a little context around all the fanfare.  This isn't about using limited FBI resources on taking down just any cyber criminals.

For those of you who followed me at InfraGard we produced a weekly IGtv program wherein I spoke with security professionals from the world over.  In this weekly Internet show I interviewed a number of professionals from RSA Security's Israel lab.  During these reports and discussions we learned that the world of malware had developed from a freakish once and while mad scientist type of thing to a very purposeful blackmarket type of business operation.  Blackshade is not some backroom mad scientist, rather they are business people selling software and as we will learn much more.  They are careful to insist that those buying their software signoff on a statement of use and legal disclaimers carefully avoiding international and in country laws.  Because they are in fact a software company and a very good one at that, right?

Blackshades develops many different types of software and one that focuses our attention is RAT (remote application tool).  Their are many variations of the RAT and the focus of our post here is the Blackshades NET.  In reseaching Blackshades we found it useful to also take a look at DarkComet, another RAT with some pretty good potential but not nearly as powerful as Blackshades.  However, DarkComent has a history in international affairs which would be useful in reading as we move forward to learn more about Blackshades.  We can see how the development of software has worked its way into State Sponsored Actors.  Recall how Russia used technology to kill communication lines prior to the invasion of Georgia and now the Ukraine.  DarkComet has played a role in Syria.  So pay close attention when we talk about functionality of Blackshades in comparison to DarkComet, it becomes increasing important why the FBI would get involved and purposefully release a sterile press release on the takedown.

Blackshades is distributed through some common social media channels as well as phishing attacks, P2P channels and much more.  All very common and known to the industry.  Its functionality dwarfs DarkComet in comparasion.  As Malwarebytes states:

"The BlackShades web site mentions a lot of the functionality the RAT is capable of, from various system administration functions to surveillance functions and computer security.  It doesn’t actually mention ALL of its functionality, as we will discuss, and I think that they might have a hard time explaining on their website the purpose of some of the following functions."
This software toolkit is explosive and is used to hijack websites with its Ramsomeware which basically locks you out of your site or maybe encrypts everything (no key provided) until such time as you pay the fee.   Another interesting aspect of Blackshades is the Facebook Controller which basically takes over your account and posts for you.  Remember, it is said that one in fourteen people in the world are on FB.  Most FB users aren't aware that "always on" means that if the software is exposed to you even if you are logged off the web and you're still on FB Blackshades will for sure takeover.  Logging in and out is a pain, but in today security environment is a MUST do.  So when a nation state is acting, it uses many channels to build or tare down a point of view, a surveillance, etc.. This tool has built in DDOS and other attack capabilities as well as java exploits.  But more importantly as Brian Krebbs, reported:
“Blackshades was a tool created and marketed principally for buyers who wouldn’t know how to hack their way out of a paper bag,” wrote Brian Krebs of Krebs on Security. “The product was sold via well-traveled and fairly open hacker forums, and even included an active user forum where customers could get help configuring and wielding the powerful surveillance tool.”

As stated in Symantec, the Blackshades tools (rats) are popular with cyber criminals and state actors like Libya and Syria.  For forty to fifty dollars one can aquire a very effective software product which can be very destructive, but a product which has helped underground elements to extract millions of dollars from companies the world over as well as some governments.

In summary, Blackshades is a more nefarious piece of software then its predecessors that infected over 500,000 computers world wide then anyone is letting on and in hindsight the FBI takedown is a signal to those "business people" lookout we're watching and we're on top of it.  Ninety arrests in 19 different counties is telling about the scope and depth.  Uncertain is whether this is nipping at the edges or taking out the C/C capabilities and principles involved.  Most likely the FBI is both happy for the case and noticeably reluctant to say game-over.  This snake will continue to sliver in and out and pick up again under another name with more willing players looking to strike it rich quick.  Malware is no longer the mad scientist, its hit Main Street and the profit center.  Malware is making millions for some of those willing to take the risk of getting caught.  Malware has also made the center stage as a component of state actors.  International cyberwarfare is our now reality and has been for some time now.  If you weren't aware you'd do well to read up.

LINKS:

http://www.symantec.com/connect/blogs/blackshades-coordinated-takedown-leads-multiple-arrests

http://resources.infosecinstitute.com/darkcomet-analysis-syria/

http://abcnews.go.com/Technology/fed-cyber-sleuths-stop-gameover-zeus-cryptolocker-crime/story?id=23964827

http://www.washingtonpost.com/news/morning-mix/wp/2014/05/20/5-scary-things-about-blackshades-malware/?tid=pm_national_pop

More Info:

In the Bureau's custom of sharing the most accurate, vetted information, they updated others today with the latest figures:

Arrests: 103
Searches: 375
Interviews: 163
18 countries involved
Approximate victim computers globally: 700,000