Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

April 01, 2022

Cybercriminals Using War to Phish Victims

 

Cybersecurity researchers at Google’s Threat Analysis Group (TAG) claim that government-backed hacking groups in Russia, China, North Korea, and Iran, plus various other cybercriminal groups are using the Russia-Ukraine war to phish victims and steal login credentials, sensitive information and money.

One Russian hacking group named ‘Coldriver’ or ‘Calisto’, is targeting US NGOs, think tanks, Eastern European and Balkan militaries, defence contractors, and even NATO through phishing emails sent from fresh Gmail accounts. Another example is ‘Ghostwriter’ a Belarusian group that orchestrates browser-in-the-browser attacks to spoof legitimate websites and domains to steal credentials.

Cybercriminal Hacker Fraud Theft

TAG has also warned about the ‘Curious Gorge’ hacker group which seems to be linked to the cyberwarfare branch of the Chinese military. They seem to be conducting hacking campaigns against military organisations in Kazakhstan, Mongolia, Russia, and Ukraine.

Other non-state sponsored cybercriminal groups are taking advantage of the war by impersonating military personnel and demanding payment for supposedly rescuing Ukrainian relatives. Google’s TAG has committed to continued action in identifying these malicious actors and share all relevant information to governments and industry so that we are aware of these issues and can try to protect our users as best as we can.

March 27, 2022

The LAPSUS$ Group

 

Microsoft and Okta have this week disclosed breaches involving the data extortion group ‘LAPSUS$’. This group first surfaced in December 2021 when attempting to extort Brazil’s Ministry of Health, but has recently made headlines again after claiming they were behind the NVIDIA, Samsung, and Vodafone hacks. The group announced it was released Microsoft source code, but Microsoft announced it was able to interrupt the group’s download before it could finish and thus limited the broader impact. Apparently, no customer data was involved, and the attack was launched through a single account compromise which granted the group limited access. Microsoft states they do not rely on secret code, and a release or viewing of source code does not lead to elevated organisation risk.

LAPSUS$ mainly gains illicit access to targets through social engineering by tricking or bribing employees or partners of the organisations they’re targeting, including customer support employees. Microsoft refers to the group as “DEV-0537”, and they found the group is bribing willing accomplices to provide their credentials and authentication information or allow the installation of remote management software so the hackers can take control of authenticated systems.

LAPSUS$ Group Hacker Code

The group has its own Telegram channel with over 45,000 subscribers and the hackers actively recruit insiders at large telcos, software companies, hosting firms, and call centres in this channel and through other social media channels such as Reddit. Some employees are being offered up to $20,000 a week. LAPSUS$ claims it is not state-sponsored, but the individuals are clearly highly experienced and have a wide range of technical knowledge.

The attackers have targeted personal accounts, which are typically used for second-factor authentication or password recovery, to gain access to corporate systems or gain additional credentials. In other scenarios, LAPSUS$ has called an organisation’s help desk and convinced personnel to reset a privileged account’s credentials. As many organisations outsource their help desk support, the group is actively exploiting these relationships to help gain access to corporate systems.

The group has also used SIM swapping to access privileged accounts at target companies. The attackers bribe or trick mobile company employees into transferring a phone number to their device so they can then intercept one-time passwords or prompt a password reset via SMS. LAPSUS$ has also searched public repositories for exposed passwords, purchased credentials and session tokens from online forums, and made use of the “Redline” malware to steal passwords.

It appears a member of the group was also involved in the breach on Electronic Arts (EA) last year where 780GB of source code was supposedly held at ransom. This attack was achieved by buying authentication cookies for an EA Slack channel from a marketplace on the dark web.

‘WhiteDoxbin’ is the supposed leader of the group who started out trading zero-day vulnerabilities. Last year they purchased Doxbin, a website that allows personal information of individuals to be posted. Apparently, the new owner was not able to keep the site functioning properly, and has been targeted by the site’s users as a result. Since then, they have sold the forum back to its previous owner for a loss, but not before leaking the whole Doxbin dataset via its Telegram channel. The site’s users again responded by providing a thorough dox of ‘WhiteDoxbin’ – including videos outside a house in the UK and the personal information of family members.

Recent developments include 7 people in the UK being arrested in connection to the hacking group, according to the City of London Police.

Google Stops Hackers

 

Google has announced that it has prevented 2 North Korean hacking groups from exploiting a zero-day bug in its Chrome browser. The bug (CVE-2022-0609) was patched in February, but it was being exploited a whole month earlier than this, with reports it was being used as early as January 4th 2022. The US agency, CISA, mandated that federal agencies must patch the bug in February. The North Korean hacking groups suspected at using the exploit are linked to Lazarus – another North Korean group accused of hacking Sony Pictures and attacking the SWIFT international bank-messaging system.

It is suspected that all of these groups are working for the same entity (potentially the North Korean government) and have a shared supply chain, thus they are all able to use the same exploits. However, each group seems to use different techniques and have different missions when deploying attacks. The hackers linked their exploit kits inside hidden iframes embedded on both websites they owned and websites they had compromised. This kit contained multiple different stages and components.

Anonymous Hacker Group

The groups have primarily targeted US tech, cryptocurrency, news media, and fintech organisations, but similar companies in other countries may also have been targeted according to Google. The groups have also targeted web-host providers, software vendors, and domain registrars with fake job offered in emails that impersonate recruiters from the likes of Oracle, Disney, and Google. These emails contained links to spoofed versions of job board websites that are popular in the US for hiring tech talent.

Once the group was discovered, Google added all known websites and domains to their Safe Browsing service which prevented users from further exploits. Google also sent alerts to all users that were targeted through Gmail and Workspace. A recent Google acquisition, Mandiant, has identified the hacking groups as Lab 110, TEMP.Hermit, APT38, Andariel, and Bureau 325 – all operating under North Korea’s foreign intelligence agency which deals with technology, operations, and reconnaissance. Mandiant claims that North Korea is borrowing China’s strategy of cajoling hacker groups to work with the government.

Each one of these groups is designated to target separate industries and gather intelligence for the purposes of geopolitical strategy or raise revenue for North Korea’s ballistic missile programs through cryptocurrency theft. Information collected through these attacks may also be used to develop vaccines, bypass sanctions, fund other weapon programs, and produce other strategies and internal items relevant to the North Korean regime.