24.2.21

Brave browser’s Tor mode exposed users’ dark web activity

A bug in the ad blocking component of Brave’s Tor feature caused the browser to leak users' DNS queries

 


By Amer Owaida

Braveone of the top-rated browsers for privacy, has fixed a bug in its Private Windows with Tor feature that leaked the .onion URLs for websites visited by the browser’s users, according to a report by an anonymous researcher, the browser’s built-in Tor mode – which takes private browsing to a new level by allowing users to navigate to .onion websites on the dark web without having to install Tor – was leaking Domain Name System (DNS) requests for the websites.

“If you’re using Brave you probably use it because you expect a certain level of privacy/anonymity. Piping .onion requests through DNS where your ISP or DNS provider can see that you made a request for an .onion site defeats that purpose,” reads the post.

RELATED READING: 3 ways to browse the web anonymously

While testing the issue, the researcher found that when a request is made for a .onion domain while using Private Window with Tor, the request makes its way to the DNS server and is tagged with the Internet Protocol (IP) address of the requester.

“This shouldn’t happen. There isn’t any reason for Brave to attempt to resolve a .onion domain through traditional means as it would with a regular clearnet site,” said the researcher. This means that when you use Tor with Brave and access a specific Tor website, your internet service provider (ISP) or DNS provider would be able to tell that the request for that specific website was made from your IP address.

According to a tweet by Brave’s Chief Information Security Officer Yan Zhu, Brave was already aware of the issue since it was previously reported on HackerOne. It has since pushed out a hotfix to resolve the Tor DNS issue, which was traced to the browser’s adblocking component, which used a separate DNS query.

Full article: Brave browser’s Tor mode exposed users’ dark web activity | WeLiveSecurity

22.2.21


De watervoorziening beschermen - Hacker-editie

Wat kunnen gemeenten doen om hun watervoorzieningssystemen beter te beschermen?

 


Onlangs stond een aanval op de watervoorziening in Oldsmar, Florida in het nieuws. Nu maken we ons zorgen over mogelijke toekomstige aanvallen en copycat-aanvallen op andere weinig beschermde waterbehandelingssystemen in kleine steden over de hele wereld en wat er kan gedaan worden om deze te stoppen.

In Florida gebruikten criminelen tools voor externe toegang en zo voet aan de grond te krijgen en de chemicaliënniveaus in de watervoorziening te wijzigen, waardoor ze tot potentieel gevaarlijke niveaus werden opgedreven.

Dat is zorgwekkend, omdat hackers normaal gezien specifieke kennis moeten hebben van beheersystemen voor waterbehandeling, wat zeer specifiek is. Dat is geen 'spray and bid'-aanval; het is doelgericht en kost tijd om tot stand te brengen en te implementeren. En hoewel dit incident geen super sluipende zero-day-aanval was (wasn’t a super stealthy zero-day attack), is de kans groot dat iemand al geruime tijd interesse had in het doelwit.

Hoe kan dit gebeuren, vanuit het perspectief van de aanvaller (in dit geval bedoelen we een typische opzettelijke aanvaller die een goed doordachte aanval bedenkt en uitvoert).

De aanvallers identificeren eerst het doelwit, verzamelen informatie en stellen een plan op. Zodra ze toegang krijgen, moeten ze het netwerk doorzoeken op de controlesystemen die rechtstreeks in wisselwerking staan met het waterzuiveringsproces. Dit kan veel tijd en planning vragen.

Zodra potentiële doelen geïdentificeerd zijn, moeten aanvallers begrijpen welke rol die doelen hebben in het chemische proces en welke toegang die systemen hebben tot de fysieke apparatuur voor de waterproductie, of het nu gaat om kleppen, relais, niveausensoren, thermokoppels of andere bedieningselementen.

Vervolgens moeten ze een specifieke aanval opzetten binnen de context die ze gaandeweg kunnen beoordelen. Daarna moeten ze aanvallen op een precies tijdstip dat de meeste kans op succes biedt, terwijl ze ongemerkt toegang houden tot alle systemen in de keten.

In Oldsmar waren er, toen de aanval eenmaal begonnen was, andere systemen die feedback gaven waarmee het personeel op tijd kon worden gewaarschuwd om de aanval te doen mislukken. Dat is het goede nieuws. Het slechte nieuws zou zijn dat er weken of maanden voorafgaand aan de daadwerkelijke vergiftigingspoging, stille aanvallen zouden geweest zijn waarvan niemand iets had gemerkt.

Bij ESET Research vraagt Tony Anscombe zich af waarom de Oldsmar-vestiging geen grondig doorgelicht en geïmplementeerd plan had met de sectorspecifieke richtlijnen voor water- en afvalwatersystemen van de CISA (CISA sector-specific guidance for water and wastewater systems), met maatregelen zoals tweefactorauthenticatie (2FA) en gelijkaardige controles. Het zou erg handig zijn mochten die richtlijnen beschikbaar zijn voor kleine gemeenten zodat ze die snel kunnen toepassen.

Verwacht ondertussen toekomstige  aanvallen tegen andere gemeenten. Pogingen tot ransomware-aanvallen  (Ransomware attempts) zouden een logisch vervolgtrend kunnen zijn.

Wat kunnen kleine steden doen? Ze moeten de tijd nemen om de beschikbare richtlijnen te begrijpen en te implementeren. Dit kan zo simpel zijn als 2FA toevoegen/verplichten, het patchen van systemen, het implementeren van goede veranderingscontroleprocessen (volgens mediaberichten werd TeamViewer vervangen als de remote access-oplossing bij deze waterzuiveringsinstallatie, maar het draaide nog steeds, waardoor de installatie aan het internet werd blootgesteld via een niet-vereiste interface) en het personeel training geven in cyberhygiëne.

Ook een praktische oefening uitvoeren, alsof er een aanval is en “denken als een hacker” om zo te voorkomen dat die binnendringt. Het is ook een goed idee om een plan te hebben voor het geval een ransomware-aanval zou plaatsvinden. Kleine steden worden dan niet geconfronteerd met het onhoudbare vooruitzicht om aan burgers te moeten uitleggen waarom ze zojuist overheidsgeld hebben uitgegeven om een aanval te stoppen die in de eerste plaats niet had mogen plaatsvinden.

11.2.21

 


Operation NightScout: Supply-Chainattack targets online gaming in Asia

ESET Researchers uncover a supply-chain attack used in cyberespionage

operation targeting on-line gaming communities in Asia

 By Ignacio Sanmillan

 Following the publication of our research, BigNox have contacted us to say that their initial denial of the compromise was a misunderstanding on their part and that they have since taken these steps to improve security for their users:

·                           use only HTTPS to deliver software updates in order to minimize the risks of domain                        hijacking and Man-in-the-Middle (MitM) attacks

·       implement file integrity verification using MD5 hashing and file signature checks

·       adopt additional measures, notably encryption of sensitive data, to avoid exposing users’ personal information

BigNox have also stated that they have pushed the latest files to the update server for NoxPlayer and that, upon startup, NoxPlayer will now run a check of the application files previously installed on the users’ machines.

ESET assumes no responsibility for the accuracy of the information provided by BigNox.

During 2020, ESET research reported various supply-chain attacks, such as the case of WIZVERA VeraPort, used by government and banking websites in South Korea, Operation StealthyTrident compromising the Able Desktop chat software used by several Mongolian government agencies, and Operation SignSight, compromising the distribution of signing software distributed by the Vietnamese government.

In January 2021, we discovered a new supply-chain attack compromising the update mechanism of NoxPlayer, an Android emulator for PCs and Macs, and part of BigNox’s product range with over 150 million users worldwide.

This software is generally used by gamers in order to play mobile games from their PCs, making this incident somewhat unusual.

Three different malware families were spotted being distributed from tailored malicious updates to selected victims, with no sign of leveraging any financial gain, but rather surveillance-related capabilities.

We spotted similarities in loaders we have been monitoring in the past with some of the ones used in this operation, such as instances we discovered in a Myanmar presidential office website supply-chain compromise on 2018, and in early 2020 in an intrusion into a Hong Kong university.

About BigNox

BigNox is a company based in Hong Kong, which provides various products, primarily an Android emulator for PCs and Macs called NoxPlayer. The company’s official website claims that it has over 150 million users in more than 150 countries speaking 20 different languages. However, it’s important to note that the BigNox follower base is predominantly in Asian countries.

BigNox also wrote an extensive blogpost in 2019 on the use of VPNs in conjunction with NoxPlayer, showing the company’s concern for their users’ privacy.

We have contacted BigNox about the intrusion, and they denied being affected. We have also offered our support to help them past the disclosure in case they decide to conduct an internal investigation.

Am I compromised?

·       Who is affected: NoxPlayer users.

 

Complete article on

https://www.welivesecurity.com/2021/02/01/operation-nightscout-supply-chain-attack-online-gaming-asia/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

 Hacker attempts to poison Florida city’s water supply

While the incursion was thwarted in time, cyberattacks targeting critical infrastructure are a major cause for concern

 Amer Owaida

Last Friday, an unknown attacker accessed the computer systems of a water treatment facility in Oldsmar, Florida, and attempted to poison the city’s water supply by manipulating the chemical levels of sodium hydroxide.

This substance, commonly referred to as lye or caustic soda, is used across various industries and can be found in liquid drain cleaners, detergents and is also used to control water acidity. However, if ingested, it can cause spontaneous vomiting, chest and abdominal pain, difficulty swallowing with drooling, and corrosive injuries.

Speaking at a press conference about the attack, Pinellas County Sheriff Bob Gualtieri said that at about 8:00 AM on Friday a plant operator noticed that someone remotely accessed the system he was monitoring. Since the system is often accessed using specialized software by authorized personnel to troubleshoot problems remotely and for monitoring purposes, the operator didn’t give it much thought. The plant serves approximately 15,000 residents.

However, at approximately 1:30 PM local time the operator noticed that the system was being accessed again. This time the perpetrator accessed various functions that control the water being treated including part of the software that controls the levels of sodium hydroxide in the water. They then proceeded to change the levels from 100 parts per million to 11,100 parts per million, after which they exited the system.

“The plant operator immediately reduced the level back to the appropriate amount of 100 parts. Because the operator noticed the increase and lowered it right away, at no time was there a significant adverse effect on the water being treated. Importantly the public was never in danger,” said the sheriff.

While the name of the program used to access the system wasn’t specified, according to Reuters reporter Chris Bing, the hackers were able to infiltrate the systems through TeamViewer, widely used software for remote support and access.

Oldsmar mayor Eric Seidel said that the good news is that the monitoring protocols they have in place work. “Even had they not caught them, there’s redundancies in the system that would have caught the change in the pH level,” he added.

The Pinellas County Sheriff’s office is investigating the attack together with the Federal Bureau of Investigation (FBI) and the United States Secret Service. So far, no suspects have been identified and it’s unclear whether the attack originated from the US or abroad; however, they are following up on leads.

The breach of the water treatment plant has raised concerns about possible further attacks; all government authorities in the Tampa Bay area with critical infrastructure components were requested to actively review their computer security protocols.

31.1.21

 

Trois patches Apple contre des menaces zéro‑day exploitées

La société émet des mises à jour d'urgence pour corriger les bogues affectant des appareils allant des iPhones aux montres Apple.

 


Amer Owaida

Apple a mis à jour ses systèmes d’exploitation iOS et iPadOS pour corriger trois failles de sécurité de type zéro-day qui sont activement exploitées dans la nature. Le trio de failles concerne différentes versions d’iPhones et d’iPads et la dernière génération d’iPod touch.

« Apple a connaissance d’un rapport selon lequel ce problème aurait été activement exploité », précise l’alerte de sécurité d’Apple, qui décrit chaque faille de sécurité qui est résolue avec la sortie de la version 14.4 d’iOS et d’iPadOS.

La liste des appareils concernés comprend les iPhone 6 et plus, les iPad Air 2 et plus, les iPad mini 4 et plus et la 7e génération d’iPod touch. Le titan de la technologie basé à Cupertino a également publié des mises à jour de sécurité pour l’une des vulnérabilités sur une série de ses autres offres, y compris Apple Watch (watchOS 7.3) et Apple TVs (tvOS 14.4).

Comme d’habitude, on ne sait rien des auteurs et des cibles de ces attaques zéro-day, qui exploitent les failles du noyau du système d’exploitation et du moteur de navigation WebKit.

La première faille, identifiée CVE-2021-1782 et située dans le noyau du système d’exploitation, est un bogue de condition de course qui pourrait conduire à une escalade des privilèges, qui pourrait être exploitée par un attaquant utilisant une application malveillante. En clair, cela signifie qu’un attaquant pourrait utiliser l’application pour obtenir des privilèges supplémentaires dans le système d’exploitation de l’appareil, ce qui lui permettrait de faire toutes sortes de dégâts.

Pendant ce temps, les deux autres failles de sécurité, indexées comme CVE-2021-1871 et CVE-2021-1870, résident dans le composant WebKit, le moteur de navigation web open-source d’Apple utilisé par le navigateur Safari, Mail, et diverses autres applications iOS et iPadOS. Selon la description du bogue, il provient d’un « problème de logique » qui pourrait être exploité par un attaquant distant et lui permettre d’exécuter du code arbitraire. Selon Vulmon, le duo de failles pourrait être exploité « en persuadant une victime de visiter un site web spécialement conçu ».

Au-delà des trois zéros jours, qui ont tous été mis au jour par des chercheurs anonymes, Apple a également publié des correctifs de sécurité pour les failles affectant ses produits Xcode et iCloud pour Windows.

L’équipe d’intervention d’urgence informatique de Hong Kong (HKCERT) a émis une alerte classant les vulnérabilités comme « à risque extrêmement élevé » et invitant les utilisateurs des appareils Apple concernés à appliquer les mises à jour immédiatement. Si vous n’avez pas activé les mises à jour automatiques, vous pouvez mettre à jour vos appareils manuellement en allant dans le menu Paramètres, puis en appuyant sur Général et en allant dans la section Mise à jour du logiciel.

Apple a précédemment détruit trois autres vulnérabilités zéro-days qui étaient activement exploités dans la nature en novembre de l’année dernière.

 

21.1.21

 

FBI warns of voice phishing attacks stealing corporate credentials

Criminals coax employees into handing over their access credentials and use the login data to burrow deep into corporate networks

Amer Owaida

The United States’ Federal Bureau of Investigation (FBI) has issued a warning about campaigns where threat actors target employees worldwide with voice phishing (also known as vishing) attacks in order to steal their network credentials and elevate user privileges.

The warning can in part be attributed to the fact that the COVID-19 pandemic has forced many companies to shift to telework, which may not allow for comprehensive monitoring of network access points and privilege escalation.

The Bureau highlighted a campaign that goes back to December 2019 and involved attackers targeting employees at large businesses in the US and elsewhere through Voice over IP (VoIP) platforms as well as a company chatroom in order to coax credentials into corporate networks.

“During the phone calls, employees were tricked into logging into a phishing webpage in order to capture the employee’s username and password,” reads the FBI’s description of one attack vector, which often involves spoofed caller ID numbers that conceal the criminal’s location and identity.

Before long, the threat actors found that they could burrow deeper into the networks than they’d initially believed and that they even had the ability to elevate permissions on the compromised accounts.

In these scenarios, attackers can wreak all manner of havoc on a company’s systems such as implanting malware, sifting through the company’s data to search for proprietary data, or gaining access to account credentials of executives with the aim of conducting Business Email Compromise (BEC) fraud. Needless to say, any of this could cost any company dearly.

Meanwhile, in another case, cybercriminals first contacted an employee via the company’s chatroom and duped the person into logging into a fraudulent Virtual Private Network (VPN) page. Using the captured account credentials, they then accessed the company’s network, where they searched for an employee with the ability to change usernames and emails.

The cybercriminals were successful in identifying their target via a cloud-based payroll service and went on to phish the victim’s credentials using the chatroom tactic as well.

RELATED READING: Strengthening the different layers of IT networks

The federal law enforcement agency also shared advice on how companies could mitigate the risks of such attacks. This includes implementing multi-factor authentication, actively scanning and monitoring for unauthorized access, network segmentation, and periodic reviews of employee network access.

In August 2020, the FBI together with the Cybersecurity and Infrastructure Security Agency (CISA) issued a similar advisory warning about a surge in vishing attacks targeting staff at multiple companies. During these attacks, the threat actors also used similar tactics including fraudulent VPN pages to obtain account credentials.

14.1.21

Operation Spalax: Targeted malware attacks in Colombia

ESET researchers uncover attacks targeting Colombian government institutions and private companies, especially from the energy and metallurgical industries

In 2020 ESET saw several attacks targeting Colombian entities exclusively. These attacks are still ongoing at the time of writing and are focused on both government institutions and private companies. For the latter, the most targeted sectors are energy and metallurgical. The attackers rely on the use of remote access trojans, most likely to spy on their victims. They have a large network infrastructure for command and control: ESET observed at least 24 different IP addresses in use in the second half of 2020.

These are probably compromised devices that act as proxies for their C&C servers. This, combined with the use of dynamic DNS services, means that their infrastructure never stays still. We have seen at least 70 domain names active in this timeframe and they register new ones on a regular basis.

The attackers

The attacks we saw in 2020 share some TTPs with previous reports about groups targeting Colombia, but also differ in many ways, thus making attribution difficult.

One of those reports was published in February 2019, by QiAnXin researchers. The operations described in that blogpost are connected to an APT group active since at least April 2018. We have found some similarities between those attacks and the ones that we describe in this article:

·       We saw a malicious sample included in IoCs of QiAnXin’s report and a sample from the new campaign in the same government organization. These files have fewer than a dozen sightings eeach.

·       SSome of the phishing emails from the current campaign were sent from IP addresses cCorresponding to a range that belongs to Powerhouse Management, a VPN service. The same IP aaddress range was used for emails sent in the earlier campaign.

·       The phishing emails have similar topics and pretend to come from some of the same entities – for example, the Office of the Attorney General (Fiscalia General de la Nacion) or the National Directorate of Taxes and Customs (DIAN).

·       Some of the C&C servers in Operation Spalax use linkpc.net and publicvm.com subdomains, along with IP addresses that belong to Powerhouse Management. This also happened in the earlier campaign.

However, there are differences in the attachments used for phishing emails, the remote access trojans (RATs) used and in most of the operator’s C&C infrastructure.

There is also this report from Trend Micro, from July 2019. There are similarities between the phishing emails and parts of the network infrastructure in that campaign and the one we describe here. The attacks described in that article were connected to cybercrime, not espionage. While we have not seen any payload delivered by the attackers other than RATs, some of the targets in the current campaign (such as a lottery agency) don’t make much sense for spying activities.

These threat actors show perfect usage of the Spanish language in the emails they send, they only target Colombian entities, and they use premade malware and don’t develop any themselves.

Attack overview

Targets are approached with emails that lead to the download of malicious files. In most cases, these emails have a PDF document attached, which contains a link that the user must click to download the malware. The downloaded files are regular RAR archives that have an executable file inside. These archives are hosted in legitimate file hosting services such as OneDrive or MediaFire. The target has to manually extract the file and execute it for the malware to run.

We’ve found a variety of packers used for these executables, but their purpose is always to have a remote access trojan running on the victimized computer, usually by decrypting the payload and injecting it into legitimate processes. An overview of a typical attack is shown in Figure 1. We have seen the attackers use three different RATs: Remcos, njRAT and AsyncRAT.

Read the full article on https://www.welivesecurity.com/2021/01/12/operation-spalax-targeted-malware-attacks-colombia/