20.8.19


Ransomware wave hits 23 towns in Texas
The attack, which has victimized mostly smaller local governments, is thought to have been unleashed by a single threat actor
As many as 23 government organizations across Texas are reeling from an apparently “coordinated ransomware attack”, an alert by the Texas Department of Information Resources (DIR) reveals.
The incident occurred last Friday and for the most part affected smaller local governments, reads the alert’s update. The attack appears to have been unleashed by “one single threat actor”, said the agency, before adding that state‑owned systems and networks were spared. The scope of the damage isn’t immediately clear, however, as the DIR stopped short of disclosing much in the way of additional details about the incident.
As a result, there’s no word on which specific entities were hit or which ransomware strain took root in their computer systems. Nor did the DIR say how the simultaneous attack on almost two dozen entities transpired. Other unknowns include the attack’s perpetrator(s), the amount of the demanded ransom, whether paying up has been weighed as an option, and, indeed, how the recovery efforts are progressing.
(Separately, the city of Borger has disclosed that it is one of the victims, whereas the National Public Radio has quoted a DIR spokesman as saying that none of the affected municipalities has paid up.)
“Investigations into the origin of this attack are ongoing; however, response and recovery are the priority at this time,” reads the alert’s uppate.
Response teams from multiple Texan authorities as well as from federal agencies such as the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) are all working on bringing the affected systems back online. The situation prompted Texas Governor Greg Abbott to order a level 2 “escalated response”, which is one step below the highest level of alert – a level 1 “emergency.”
As shown by a recent report by threat intelligence provider Recorded Future, ransomware attacks on state and local governments in the US have been growing at a fast clip. Atlanta, Baltimore and two Floridian cities, for example, have all seen their municipal systems crippled by various ransomware strains. Whereas the first two chose to claw back their systems, Riviera Beach and Lake City decided to pay the ransoms up front, highlighting the tough choices that ransomware victims face.
Just weeks ago, the US Conference of Mayors, which represents more than 1,400 mayors from cities around the country, vowed not to cave in to cyber-extortionists in case their systems are hit by ransomware.
For precautions that organizations in general can take to defend against this type of threat, please refer to Ransomware: Expert advice on how to keep safe and secure. Enterprises, although not only them, may be particularly interested in our comprehensive white paper, Ransomware: An enterprise perspective.

19.8.19


Piratage aérien – édition BlackHat

Les constructeurs d’avions maison et les  experts en cybersécurité peuvent-ils aider le transport aérien ? Pourquoi l’idée n’a-t-elle pas encore pris son envol ?


Je construis actuellement un avion expérimental. Oui, j’ai l’intention de l’utiliser pour m’envoler. N’ayez pas peur, je ne suis pas le seul! En fait, ce segment d’inventeurs pourrait facilement s’avérer un précieux composant anti-piratage pour les industries des gros jets et des petits avions.

L’industrie du transport aérien est paralysée par la peur de la mauvaise presse, surtout en matière de piratage. Avec l’arrivée d’un plus grand nombre de nouveaux avions équipés de systèmes câblés (et sans fil), il y aura de plus en plus de réseaux qui voleront dans les airs près de votre siège dans la cabine.

Ce ne sont pas tous les réseaux qui contrôlent les choses critiques. En effet, beaucoup d’entre eux sont impliqués dans des choses assez simples comme changer la couleur des lumières de l’habitacle. Quel est le risque pour les systèmes de commandes de vol? C’est exactement ce que l’industrie automobile pensait il y a dix ans : Qu’est-ce qui pourrait arriver de si grave avec le contrôle des véhicules s’ils étaient piratés?

Jusqu’à ce qu’il le fasse. À BlackHat, il y a quelque temps, nous avons pu voir des vidéos de véhicules qui ont dérapé à la suite d’un piratage. Heureusement, l’industrie automobile s’est adaptée à la réalité du piratage, et (certains) ont même parrainé des opportunités de piratage comme le village du piratage automobile à DefCon plus tard dans la semaine. La tournure des événements a été très positive. En s’engageant plus ouvertement dans la culture du piratage, la technologie automobile a commencé à mieux se défendre contre le piratage, ce qui contribue à notre sécurité à tous.

L’industrie du transport aérien n’a pas été aussi accueillante. Bien que stationner un jet dans une salle de DefCon soit difficile, il semble que peu de progrès aient été faits pour accueillir chaleureusement la recherche sur le piratage. Il n’est pas invraisemblable de rendre disponibles certains systèmes actuellement utilisés dans les avions, mais il semble y avoir une inertie culturelle qui ne s’est que légèrement réchauffée à cette idée.

Nous avons donc maintenant une séance d’information ici à BlackHat au sujet de la manipulation des systèmes de guidage en vol des petits avions. Ce genre de système est souvent utilisé dans des avions comme le mien. Mais contrairement aux processus typiques de divulgation de la fabrication, qui peuvent être, euh, insatisfaisants et peu accueillants, ceux qui travaillent sur leurs propres avions, dont ils sont considérés comme les constructeurs, sont des candidats de choix pour aider à régler les choses.

Après tout, nous n’avons pas vraiment de gros problèmes d’inertie en matière de relations publiques, nous voulons simplement régler le problème. Nos actions ne s’effondreront pas. Nous pouvons publier les résultats sur des listes et des groupes enthousiastes aux États-Unis, comme l’Experimental Aircraft Association (EAA), où les gens échangent des idées à un rythme assez rapide, et deviennent ainsi une sorte de groupe de test bêta ad hoc.

Est-ce que ça peut marcher? Tout à fait. Il y a environ 40 ans, les groupes de construction de maisons et les groupes expérimentaux ont commencé à pirater des avions pour améliorer leur performance. De nos jours, un avion de construction artisanale pourrait être construit avec des ailes à flux laminé en fibre de carbone avec des volets à fentes Fowler pour une manipulation à basse vitesse dans un avion à grande vitesse qui détruirait absolument les performances des avions légers lourdement réglementés que l’industrie aéronautique produit encore aujourd’hui, qui sont encore largement basés sur une technologie vieille de 70 ans. A moitié prix.

Un modèle de construction artisanale, le Lancair IV-P, utilisant le même moteur que celui utilisé pour faire voler un avion certifié à environ 200 milles à l’heure, navigue à environ 350 milles à l’heure. Il est embarrassant de constater à quel point les améliorations en matière de piratage informatique peuvent être bénéfiques pour une industrie.

Il est temps de faire participer l’industrie, non pas pour pointer des fautes du doigt, mais pour régler les problèmes. Et nous sommes là pour vous aider. Si vous acceptez de nous laisser faire.

14.8.19

In the Balkans, businesses are under fire from a double-barreled weapon


ESET researchers discovered a campaign that uses two malicious tools with similar capabilities to ensure both resilience and broader potential for the attackers.

We’ve discovered an ongoing campaign in the Balkans spreading two tools having a similar purpose: a backdoor and a remote access Trojan we named, respectively, BalkanDoor and BalkanRAT.

BalkanRAT enables the attacker to remotely control the compromised computer via a graphical interface, i.e., manually; BalkanDoor enables them to remotely control the compromised computer via a command line, i.e., possibly en masse. ESET security products detect these threats as Win{32,64}/BalkanRAT and Win32/BalkanDoor.

A typical victim of this campaign, which uses malicious emails as its spreading mechanism, ends up having both these tools deployed on their computer, each of them capable of fully controlling the affected machine. This rather uncommon setup makes it possible for attackers to choose the most suitable method to instruct the computer to perform operations of their choice.

The campaign’s overarching theme is taxes. With the contents of the emails, included links and decoy PDFs all involving taxes, the attackers are apparently targeting the financial departments of organizations in the Balkans region. Thus, although backdoors and other tools for remote access are often used for espionage, we believe that this particular campaign is financially motivated.

The campaign has been active at least from January 2016 to the time of writing (the most recent detections in our telemetry are from July 2019). Some parts of the campaign were briefly described by a Serbian security provider in 2016 and the Croatian CERT in 2017. Each of these sources focused only on one of the two tools and only on a single country. However, our research shows that there is a significant overlap in targets and also in the attackers’ tactics, techniques and procedures.

Our findings show that the mentioned attacks have been orchestrated and we consider them a single long-term campaign that spans Croatia, Serbia, Montenegro, and Bosnia and Herzegovina.

Our research has also shed more light at the malware used in this campaign and provided some context. We’ve discovered a new version of BalkanDoor with a new method for execution/installation: an exploit of the WinRAR ACE vulnerability (CVE-2018-20250). Further, we’ve seen both malicious tools digitally signed with various certificates the developers paid for to add perceived legitimacy. One of them, issued to SLOW BEER LTD, was even valid at the time of writing; we’ve notified the issuer about the misuse and they revoked the certificate.

In this article, we will describe some notable features of both BalkanDoor and BalkanRAT. Our analysis shows that the former runs as a Windows service, which allows it to unlock the Windows logon screen remotely and without the password or start a process with the highest possible privileges. The latter misuses a legitimate remote desktop software (RDS) product and uses extra tools and scripts to hide its presence from the victim, such as hiding the window, tray icon, process and so on.

Targets and distribution
Both BalkanRAT and BalkanDoor spread in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina. (These countries, along with Slovenia and former Macedonia, formed the country of Yugoslavia until 1992.)

Find the complete article on:


13.8.19

#MissionChampion: ESET becomes Champion Partner of top German Bundesliga team, Borussia Dortmund



Leading European IT security vendor joins BVB defense

ESET, a cybersecurity vendor with its headquarters in Bratislava, Slovakia is the new Champion Partner of the Borussia Dortmund (BVB) football club – the highest possible level of partnership. Sponsoring and cooperation plans are long-term and will last for the next three seasons of the Bundesliga, the top tier league of German football. ESET will be supporting the fans of the eight-time German Champion with activities and initiatives at all 17 home matches in the Bundesliga.

“Borussia Dortmund is one of the most popular and well-liked teams in European club football,” happily noted Richard Marko, CEO of ESET. “Just like BVB, ESET is also passionate and dedicated towards its fans. That’s why sponsoring Borussia Dortmund is an ideal place to meet so many enthusiastic supporters who want to enjoy great football whether that’s on the field or while staying cyber safe and streaming online .”

Hans-Joachim Watzke, CEO of Borussia Dortmund, also announced: “ESET and Borussia Dortmund are united by their international appeal. Here, two brands popular in their respective backgrounds meet. ESET stands for exactly those values that BVB embodies: reliability, passion, courage and integrity. From the very beginning our meetings were characterized by focus and mutual trust. We are very happy to welcome ESET to our team of Champion Partners.”

True love meets true security
The Internet has significantly changed the way people experience their lives, and football is no exception. ESET joining forces with BVB brings the worlds of football and internet safety closer. This is especially important to the new spectrum of possibilities and activities like streaming matches on the go, connecting with fellow fans abroad, or hunting for rare collectables which have become a massive part of fandom and the game itself.

Activities for fans throughout the season
Fans can expect great activities during BVB matches surrounding the topic of “cybersecurity and soccer” both online and offline. So, let’s cheer on the black and yellow this August 17 as they battle for a home victory against Augsburg.


8.8.19

InterSystems IRIS data-platform gebruikt om Chinese astronomische observatieplatform te bouwen


InterSystems meldt dat Beijing Skyline Technology, een pionier in de Chinese astronomische dienstensector, met succes het eerste intelligente platform voor astronomische observatiediensten in China heeft geïmplementeerd. Het platform is gebouwd op het IRIS-dataplatform van InterSystems en verbindt de binnenlandse telescopen van zowel professionals als amateurs met elkaar.

Via IRIS kan gelijk welke toegelaten telescoop toegang krijgen tot het Skyline intelligente astronomische observatie platform,  waardoor "gedeelde" astronomische telescopen kunnen gebruikt worden zowel door amateurs als professionals in de astronomie. Dit opent een wereld aan mogelijkheden: astrofielen kunnen de nachtelijke hemel zien vanuit perspectieven van over de hele wereld terwijl professionele astronomen ten volle gebruik kunnen maken van het potentieel van gedeelde apparatuur om hemelse gegevens te verkrijgen voor observatie en computeronderzoek.

Het hart van InterSystems IRIS is een hoog performante database, die lifecycle data management, native interoperabiliteit, transactionele en analytische verwerkingscapaciteiten biedt. Ontworpen voor cloudapplicaties, kan IRIS de steeds grotere werklast, hoeveelheid data, types en gelijktijdige gebruikerstoegangen effectief adresseren, zodat ontwikkelaars een voorkeursoptie krijgen om snel applicaties te ontwikkelen.
IRIS wordt geleverd met de ingebouwde mogelijkheid om structurele en niet-structurele analyses en AI-modellen te bouwen, alsook een flexibele database met meerdere modellen geoptimaliseerd voor AI-engineering. Zo zijn wetenschappers in staat om gegevens, nodig om AI-modellen te bouwen en in dienst te nemen, snel en eenvoudig vast te  leggen, samen te voegen en te normaliseren.
Met IRIS biedt het Skyline-platform de mogelijkheid om gegevensbeheer uit te voeren en inzicht te krijgen  in de astronomische gegevens die meerdere telescopen verzamelen. Zo kunnen sterrenkijkers AI-modellen maken met behulp van enorme aantallen astronomische gegevens. Ze kunnen efficiënt speculeren over hemelevoluties en zoeken naar exoplaneten en supernova’s
“ Ik weet hoe IRIS presteert en juist daarom werken we samen,” zei  Li Qingshan, oprichter van Skyline. “ Met IRIS  kunnen we enorme hoeveelheden data analyseren. Het gebruik van AI bij de exploratie van de hemel is een van de belangrijkste toekomsttrends en we  hechten veel waarde aan het potentieel van IRIS voor gegevensinzichten en AI-mogelijkheden.”
“Partners ruimere mogelijkheden bieden is ons doel,” zei Luciano Brustia, Country Manager InterSystems voor Australia, Continentaal China en Korea. “Skyline heeft een tool nodig dat kan gebruikt worden om efficiënt en gemakkelijk toegang te hebben tot verschillende soorten data en zo diepe inzichten te ontwikkelen. IRIS biedt werkelijk de hoge betrouwbaarheid, interoperabiliteit, veiligheid en schaalbaarheid die nodig zijn om zowel uitdagingen als opportuniteiten in het tijdperk van AI aan te kunnen.
Het intelligente astronomische observatieplatform van Skyline werd gepresenteerd op de “China International Big Data Industry Expo 2019” in Guiyang en bezorgde bezoekers een andere ervaring op het sterrenkijken.
Voor meer informatie, bezoek InterSystems.com/

Over Skyline
Skyline is een professioneel bedrijf,  gespecialiseerd in oplossingen voor astronomische observatie. Skyline levert allerlei apparatuur en diensten aan amateurastronomen, vulgarisatiegroepen op alle niveaus en professionele onderzoeksinstellingen in de astronomie.
Skyline heeft langdurige relaties opgebouwd met tientallen amateur- en professionele organisaties op het Chinese vasteland. Met professionele technische vaardigheden helpt het gebruikers om hun doelen te bereiken.
In combinatie met de snelle ontwikkeling van moderne IT-technologieën, heeft Skyline met behulp van IRIS een intelligent astronomisch observatieplatform ontwikkeld om de efficiëntie van astronomische apparatuur te verbeteren en ook effectief massale observatiegegevens te gebruiken.
Men is van mening dat het platform de efficiëntie van astronomische observatie en het gebruiksgraad van gegevens aanzienlijk zal verbeteren. Voor meert informatie, bezoek http://www.itelescope.cn.

Un dangereux spambot capture l’écran de victimes françaises quand elles regardent du contenu à connotation sexuelle en ligne, a découvert ESET




Des chercheurs d’ESET ont découvert des campagnes de spam qui propagent des logiciels malveillants et ciblent des personnes. La charge malveillantes, dénommée Varenyky par l’équipe d’ESET, implique pas mal de fonctionnalités dangereuses. Varenyky ne propage pas que du spam mais peut également voler des mots de passe et espionner les écrans de ses victimes lorsqu’elles  regardent du contenu de nature sexuelle en ligne.

Pour ce bot, le premier pic de télémétrie ESET se situe en mai 2019 et après des recherches approfondies, les chercheurs ont identifié le logiciel malveillant spécifique utilisé pour propager ce spam. « Nous pensons que le spambot est en plein développement car il a beaucoup évolué depuis la première fois que nous l’avons vu. Comme d’habitude, nous conseillons aux utilisateurs d’être prudents lorsqu’ils ouvrent des pièces jointes de sources inconnues et de s’assurer que les logiciels système et de sécurité sont mis à jour, » explique  Alexis Dorais-Joncas, responsable du centre R&D d’ESET à Montréal .

Pour atteindre leur but, les opérateurs du spam Varenyky utilisent une fausse facture malveillante en pièce jointe, qui incite les victimes à faire une ‘vérification humaine’ du document . Ensuite, le logiciel espion exécute la charge malveillante. Apparemment, Varenyky ne cible  que les utilisateurs francophones en France. La qualité de la langue utilisée est très bonne, ce qui indique que les opérateurs parlent couramment le français.

Après la contamination, Varenyky exécute le logiciel Tor, qui permet une communication anonyme avec le serveur de commande et de contrôle. A partir de ce moment-là, l’activité criminelle fonctionne à pleine puissance. « Cela démarre de deux façons : l’une est responsable pour la propagation du spam et l’autre peut exécuter sur l’ordinateur les missions venant du serveur de commande et de contrôle, » ajoute Dorais-Joncas. « Ici, un des aspects les plus dangereux est la recherche, dans les applis exécutées sur le système de la victime, de mots clefs spécifiques tels que bitcoin ainsi que des mots liés à la pornographie. Lorsqu’il trouve de tels mots, Varenyky  fait une capture d’écran et celle-ci et ensuite transmise au serveur C&C, » comment Dorais-Joncas.

Dans le passé, nous avons vu de fausses campagnes de sextorsion, mais les capacités actuelles pourraient certainement mener à de véritables campagnes de sextorsion. Alors qu’au début les opérateurs de Varenyky n’utilisaient pas cette approche, ils l’utilisent depuis la fin juillet. De plus, les cybercriminels comptent sur le bitcoin pour monétiser leurs méfaits.

“Une autre fonctionnalité remarquable est que Varenyky peut voler des mots de passe en utilisant une appli que nous considérons comme potentiellement dangereuse, » dit Dorais-Joncas. D’autres commandes permettent à l’attaquant de lire des textes ou de faire des captures d’écran.

Les spams envoyés par le bot attirent les victimes vers de fausses promotions pour smartphones. Leur seul but est le hameçonnage d’informations personnelles (informations bancaires par exemple). Un seul bot peut envoyer jusqu’à 1.500 mails par heure. Il est intéressant de savoir que nous avons observé que les cibles de tous ces spams sont des utilisateurs d’Orange S.A., le fournisseur français d’internet.

Lisez, pour plus de détails, « Varenyky : spambot à la française » sur WeLiveSecurity.com. Suivez aussi ESET research sur Twitter.


7.8.19

ESET researchers discover new Android ransomware that tries to spread all around


Android ransomware may be on the decline since 2017 – but recently, ESET researchers discovered a new ransomware family, Android/Filecoder.C. Using victims’ contact lists, it attempts to spread further via SMSes with malicious links.
The new ransomware was seen distributed via porn-related topics on Reddit. The malicious profile used in the ransomware-distributing campaign was reported by ESET but is still active. For a short period of time, the campaign had also run on the “XDA developers” forum, a forum for Android developers; based on ESET’s report, the operators removed the malicious posts.
“The campaign we discovered is small and rather amateurish. Also, the ransomware itself is flawed – especially in terms of the encryption which is poorly implemented. Any encrypted files can be recovered without help from the attackers,” comments Lukáš Štefanko, ESET researcher who led the investigation. “However, if the developers fix the flaws and the distribution becomes more advanced, this new ransomware could become a serious threat.”
The new ransomware is notable for its spreading mechanism. Before it starts encrypting files, it sends a batch of text messages to every address in the victim’s contact list, luring the recipients to click on a malicious link leading to the ransomware installation file. “In theory, this can lead to a flood of infections – more so that the malware has 42 language versions of the malicious message. Fortunately, even non-suspecting users must notice that the messages are poorly translated, and some versions do not seem to make any sense,” comments Lukáš Štefanko.
Besides its non-traditional spreading mechanism, Android/Filecoder.C has a few  anomalies in its encryption. It excludes large archives (over 50 MB) and small images (under 150 kB), and its list of “filetypes to encrypt” contains many entries unrelated to Android while also lacking some of the extensions typical for Android. “Apparently, the list has been copied from the notorious WannaCry ransomware,” observes Štefanko.
There are also other intriguing elements to the unorthodox approach which the developers of this malware have used. Unlike typical Android ransomware, Android/Filecoder.C doesn’t prevent the user from accessing the device by locking the screen. Furthermore, the ransom is not set as a hardcoded value; instead, the amount that the attackers request in exchange for the promise of decrypting the files is created dynamically using the UserID assigned by the ransomware to the particular victim. This process results in a unique ransom amount, falling in the range of 0.01-0.02 BTC.
“The trick with a unique ransom is novel: we haven’t seen it before in any ransomware from the Android ecosystem,” says Štefanko. “It is probably meant to assign payments to victims. This task is typically solved by creating a unique Bitcoin wallet for every encrypted device. In this campaign, we’ve only seen one Bitcoin wallet being used.”
According to Lukáš Štefanko, users with devices protected by ESET Mobile Security are safe from this threat. “They receive a warning about the malicious link; should they ignore the warning and download the app, the security solution will block it.”
This discovery shows that ransomware still poses a threat to Android mobile devices. To stay safe, users should stick to basic security principles:
  • Keep your devices up to date, ideally set them to patch and update automatically so that you stay protected.
  • If possible, stick with Google Play or other reputable app stores. These markets may not be completely free from malicious apps, but you have a fair chance of avoiding them.
  • Prior to installing any app, check its ratings and reviews. Focus on the negative ones as they often come from legitimate users, while positive feedback is often crafted by the attackers.
  • Focus on the permissions requested by the app. If they seem inadequate for the app’s functions, avoid downloading the app.
  • Use a reputable mobile security solution to protect your device.
For more information read We Live Security blog.