Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

April 01, 2022

Cybercriminals Using War to Phish Victims

 

Cybersecurity researchers at Google’s Threat Analysis Group (TAG) claim that government-backed hacking groups in Russia, China, North Korea, and Iran, plus various other cybercriminal groups are using the Russia-Ukraine war to phish victims and steal login credentials, sensitive information and money.

One Russian hacking group named ‘Coldriver’ or ‘Calisto’, is targeting US NGOs, think tanks, Eastern European and Balkan militaries, defence contractors, and even NATO through phishing emails sent from fresh Gmail accounts. Another example is ‘Ghostwriter’ a Belarusian group that orchestrates browser-in-the-browser attacks to spoof legitimate websites and domains to steal credentials.

Cybercriminal Hacker Fraud Theft

TAG has also warned about the ‘Curious Gorge’ hacker group which seems to be linked to the cyberwarfare branch of the Chinese military. They seem to be conducting hacking campaigns against military organisations in Kazakhstan, Mongolia, Russia, and Ukraine.

Other non-state sponsored cybercriminal groups are taking advantage of the war by impersonating military personnel and demanding payment for supposedly rescuing Ukrainian relatives. Google’s TAG has committed to continued action in identifying these malicious actors and share all relevant information to governments and industry so that we are aware of these issues and can try to protect our users as best as we can.

March 30, 2022

Cybersecurity Lessons from 2021

 

SecureWorks, an incident response service provider, covered over 450 incidents last year and recently published its feedback. 85% of the incidents they responded to were financially motivated and a further 5% were seemingly government-sponsored attacks. The remaining attacks were accidental or deliberate actions of employees.

43% of the initial access gained was through threat actors exploiting vulnerabilities in internet-connected devices and credentials theft represented another 18% of initial system access. These credentials can be obtained through the dark web, brokers, credential stealing, brute-force attacks, or password spraying. In previous years, credentials theft was the number one approach to compromising a target, so the focus for security professionals needs to shift to patching vulnerabilities.

The rise in multi-factor authentication may mean that attackers are focusing on exploiting vulnerabilities that do not require authentication. Alternatively, it can be easy for an attacker to exploit proof-of-concept code that is published shortly after a vulnerability is publicly disclosed. This can lead to wide scale exploitation of any vulnerable devices in multiple targets simultaneously.

Despite ransomware attackers being increasingly imprisoned for their actions and the US government prioritising ransomware the same with it does terrorism, SecureWorks has not seen a reduction in ransomware attacks in 2021.

Many of the attacks that relied on credential theft and abuse occurred because the target organisation failed to implement multi-factor authentication mechanisms at all or properly. However, attackers have been able to bypass MFA by exploiting legacy authentication protocols (e.g. IMAP and SMTP) which are either still in use or haven’t been disabled. These protocols cannot enforce MFA and pose a significant security risk to businesses.

Security Vulnerability Exploit

Even when MFA is implemented correctly, users may still eventually decide to approve an MFA request if attackers continuously send them due to “notification fatigue”. To mitigate this issue, consider implementing MFA that request a code from the user rather than a one-click solution.

If an enterprise is using cloud solutions, carefully investigate all of the security components and controls offered by the cloud provider to ensure logging and controlled access is offered by the cloud service. It may be attractive for businesses to implement these cloud solutions, but there are security considerations that must be accounted for before moving resources online.

To prevent cyberattacks going forward, SecureWorks recommends that IT and security professional regularly perform vulnerability scans, control access carefully and make use of IP lists, monitor newly registered domains that spoof or impersonate your company, improve your backup strategies and procedures to mitigate ransomware attacks, implement MFA properly, and implement DKIM and SPF authentication for email clients to avoid fake emails being sent by attackers.

Of course, you should also ensure your systems and software and kept up to date, use the principle of least privilege for account access, and ensure you implement an endpoint detection and response solution.

March 29, 2022

Ransomware Attacker Gets Prison Sentence

 

Maksim Berezan, an Estonian national, has received a 5-year prison sentence for being involved in over 13 ransomware attacks costing victims over $53 million in losses. Berezan was part of a Russian cybercriminal forum where tools and services were regularly exchanged. He was arrested in Latvia back in 2020 and later extradited to the US where he pleaded guilty to conspiracy to commit wire fraud and conspiracy to commit access device fraud. It is believed he targeted at least 7 American businesses.

Police found Berezan had cryptocurrency wallets containing $11 million from ransom payments he had demanded during the attacks along with $200,000 in cash. Living a lavish lifestyle, the criminal had bought luxury cars, sport motorbikes, and jewellery, but he has now been court ordered to repay $36 million in restitution. 

US Department of Justice (DoJ)

The US Secret Service states this is a lesson to ransomware criminals that they are not safe and cannot easily hide from law enforcement and cybercriminal investigators no matter where they are in the world. The US DoJ partnered with the Latvian and Estonian police to help obtain the conviction.

The US Attorney for the Eastern District of Virginia stated “Ransomware attacks are devastating to people and organizations alike, and we have honed our strategies and techniques to target both the individual actors who perpetrate these attacks and the networks that support them”.