19.9.19

Le premier espiongiciel d’un nouveau genre se faufile dans Google Play



ESET analyse le premier espiongiciel connu qui est construit sur l’outil d’espionnage open-source AhMyth et qui est apparu sur Google Play – deux fois.

Lukas Stefanko

Les chercheurs d’ESET ont découvert le premier espiongiciel (spyware) connu qui est construit sur les fondations du malware open-source AhMyth et a contourné le processus de validation des applications de Google.

L’application malveillante, appelée Radio Balouch aka RB Music, est en fait une application radio entièrement fonctionnelle pour les amateurs de musique balouchi, sauf qu’elle est livrée avec une très mauvaise surprise pour les utilisateurs – une fonctionnalité pour voler les données personnelles de ces derniers. L’application s’est glissée deux fois dans l’app store officiel d’Android, mais a été rapidement supprimée par Google à chaque fois après que nous avons alerté l’entreprise à ce sujet.

AhMyth, l’outil d’accès à distance open-source auquel l’application Radio Balouch a emprunté sa fonctionnalité malveillante, a été rendu public fin 2017. Depuis, nous avons été témoins de diverses applications malveillantes basées sur cette application, mais l’application Radio Balouch est la toute première à apparaître sur la boutique officielle des applications Android.

La solution de sécurité mobile d’ESET protège les utilisateurs d’AhMyth et de ses dérivés depuis janvier 2017 – avant même qu’AhMyth ne devienne publique. Comme la fonctionnalité malveillante d’AhMyth n’est pas cachée, protégée ou obscurcie, il est trivial d’identifier l’application Radio Balouch – et d’autres dérivés – comme étant malveillante, et de les classer comme appartenant à la famille AhMyth.

Outre Google Play, le logiciel malveillant, détecté par ESET sous le nom Android/Spy.Agent.AOX, était aussi disponible sur d’autres boutiques d’applications. De plus, un site Web dédié en assurait pour la diffusion, via Instagram et YouTube. Nous avons signalé la nature malveillante de la campagne aux fournisseurs de services respectifs, mais nous n’avons reçu aucune réponse.

Radio Balouch est une application de streaming radio entièrement fonctionnelle pour la musique spécifique à la région Balouchi (pour des raisons de cohérence, nous suivons l’orthographe utilisée dans la campagne; les transcriptions les plus courantes en anglais sont « Balochi » ou « Baluchi »). Cependant, l’application espionne ses victimes en arrière-plan.

Nous avons découvert deux fois différentes versions de l’application malveillante Radio Balouch sur Google Play. Dans chaque cas, l’application comptait plus de 100 installations. Nous avons signalé la première apparition de cette application sur la boutique officielle Android à l’équipe de sécurité de Google le 2 juillet 2019; elle a été retirée dans les 24 heures.

L’application malveillante Radio Balouch est réapparue sur Google Play le 13 juillet 2019. Comme auparavant, ESET a immédiatement avisé Google, qui l’a rapidement supprimée.


Universities warned to brace for cyberattacks



The UK’s cybersecurity agency also outlines precautions that academia should take to mitigate risks


The United Kingdom’s National Cyber Security Centre (NCSC) has issued a stark warning to universities across the country, urging them to be on their guards against cyberattacks.

The main risk is, in fact, two-fold. Firstly, it comes from ne’er-do-wells seeking financial gain via what are often untargeted attacks. When the attacks are targeted, however, they “have the potential for greater financial impact”, notes the cybersecurity agency.

“Cybercrime will probably present the most evident and disruptive difficulties for universities,” reads the threat assessment.

At the same time, however, the report sounds the alarm on a more silent threat, one that is “likely to cause greater long-term damage” – state-sponsored attacks and espionage. These incursions seek strategic gain and are aimed at intellectual property theft from institutions that house valuable research data and other assets, which is largely why they fall in the crosshairs of cyberattackers.

To defend against incursions, the universities are being urged to ensure they have a range of basic measures in place. This includes security-conscious policies and strict authentication and access controls, as well as making sure that university networks are designed with security considerations in mind. Still, the very first line of defense, as noted by the report, is “good security awareness among staff and students”.

Techniques may be evolving but, courtesy of their high success rate, attacks involving social engineering remain a staple. Indeed, a team of ethical hackers recently conducted simulated attacks at more than 50 universities in the UK and, in each case, got their hands on high-value data within two hours. As we also wrote back then, key to the 100-percent success rate was spear-phishing, a targeted form of phishing that involves sending a bespoke email to a well-researched prospective victim.

Here is our list of measures that educational institutions are well advised to take in order to defend against cyberattacks.


8.9.19



Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default

Firefox new Enhanced Tracking Protection (ETP) feature launched to all users of the browser to offer better privacy and protection from cryptojacking.

Protecting user’s privacy is a long-time preoccupation in IT security, and corporations are also taking action. We saw another example this week with Firefox Version 69.0. Since Tuesday September 3, third-party tracking cookies and cryptominers are now blocked by default for all Firefox users – on desktop as well as Android.

The feature, called Enhanced Tracking Protection (ETP), rolls out stronger privacy protections. The Mozilla Blog explains the specificity of this feature:

·         The default standard setting for this feature now blocks third-party tracking cookies and cryptominers.
·         The optional strict setting blocks fingerprinters as well as the items blocked in the standard setting.

While the announcement is important, we should note that this feature is not exactly new from Mozilla. It was already enable for new users since last June. However, it is now available for all users of the open-source Web browser.
Marissa Wood, Vice President of Product at Mozilla, explains: “Currently, over 20% of Firefox users have Enhanced Tracking Protection on. With today’s release, we expect to provide protection for 100% of ours users by default. “

The new feature targets third-party cookies, which are usually begetting by advertising networks. First-party cookies are not affected by this feature.
The second target of this feature is cryptojacking. In brief, cryptojacking is in brief the usage of a computer or device’ to mine cryptocurrency without the user’s knowledge. Cybercriminals instigate attacks in order to hijack digital currencies, or use compromise computer resources to mine cryptocurrencies unwittingly to the legitimate users of those devices. According to a recent survey, a third of British corporations have been hit this serious threat.

If you want to go further in protecting your privacy online, you might want to read these articles as well:





ESET door Gartner genoemd als enige ‘Challenger’ in zijn Magic Quadrant 2019, voor Endpoint Protection Platforms, voor het tweede jaar op rij

ESET, wereldleider in cybersecurity, werd genoemd als enige Challenger in de 2019 Gartner Magic Quadrant for Endpoint Protection Platforms*, voor het tweede jaar op rij. ESET werd geëvalueerd op basis van zijn uitvoeringscapaciteiten en de  volledigheid van zijn visie.

“Voor ons was een enorme prestatie om vorig jaar in de Gartner Magic Quadrant als enige uitdager te worden genoemd. Deze herkenning voor een tweede keer mogen ontvangen, bewijst onze vastberadenheid om voortdurend de beste endpoint bescherming, detectie en reactie aan de bedrijven te bieden,” verduidelijkte Ignacio Sbampato, chief business officer bij ESET. “ We zijn trots op onze aanpak dat gebaseerd is op vooruitstrevend onderzoek en visie om oplossingen te ontwikkelen die organisaties beschermen op een consistente en uitgebreide wijze. We zijn ervan overtuigd dat onze rangschikking te danken is aan onze voortdurende groei als een globale speler op het gebied informatiebeveiliging.

Sbampato vervolgt: “Sinds vorig jaar  heeft ESET zijn aanbod voor bedrijven versterkt met ESET Enterprise Inspector, een oplossing voor Endpoint Detection en Response, alsook ESET Dynamic Threat Defense, een cloud-gebaseerde  sandbox, die een complete Endpoint Protection Platform aanbiedt aan zijn bedrijfsklanten wereldwijd. Dit maakt deel uit van ESET’s strategie om zijn aanwezigheid in het bedrijfssegment uit te breiden.”

Van zijn positionering als Challenger  voor het tweede jaar op rij, denkt ESET dat het te danken is aan zijn capaciteiten om een gebruiksvriendelijk, uitgebreid en consistent eindpuntbeschermingsproduct te bieden en weerspiegelt zijn groeiend marktaandeel in alle segmenten die voor het bedrijf cruciaal zijn. Dit gaat van de bedrijven tot  de consument en de KMO’s. ESET is trots op de hoge graad van detectie en de kleine voetafdruk van zijn producten. Het bedrijf is ervan overtuigd dat de kwaliteit van zijn klantenservice zijn positie in Gartner’s Magic Quadrant zijn toewijding aan de best mogelijke service voor al zijn klanten benadrukt.

Volgens de IT-woordenschat van Gartner **, “Gartner’s Magic Quadrants bieden visuele snapshots, diepgaande analyses en bruikbaar advies die inzicht geven in de richting, maturiteit en spelers van een markt. Magic Quadrants vergelijken vendors op basis van de standaardcriteria en methodologie van Gartner. Elk rapport heeft een Magic Quadrant grafiek die een markt beschrijft met behulp van een tweedimensionale matrix waarin leveranciers geëvalueerd worden op basis van hun volledigheid van visie en capaciteit om die uit te voeren. "

Ontvang nu uw gratis exemplaar van het Gartner-rapport en bekijk de positionering van ESET in het Magic Quadrant op: https://www.eset.com/int/business/gartner-epp-mq-2019/ .

*Bron: Gartner, “Magic Quadrant for Endpoint Protection Platforms,” Peter Firstbrook, Dionisio Zumerle, Prateek Bhajanka, Lawrence Pingree, Paul Webber, 20 August 2019.
** Bron: Gartner IT Glossary, “Magic Quadrant,” 22 August 2019. https://www.gartner.com/it-glossary/magic-quadrant

Waarschuwing van  Gartner 
Gartner endosseert geen enkele leverancier, product of dienst die in zijn onderzoekpublicaties vermeld staan en geeft ook technologiegebruikers geen raad om uitsluitend de vendors te selecteren die de hoogste ratings of andere vermeldingen kregen. De publicaties van Gartner geven de opinie weer van Gartner’s onderzoeksteams  en moeten niet beschouwd worden  als feitelijke verklaringen. Gartner verwerpt alle waarborgen, expliciet en impliciet, wat zijn onderzoek betreft met inbegrip van waarborgen van verkoopbaarheid of geschiktheid voor een bepaald doel.

Voor het gratis e-book over gegevensbescherming, bezoek  https://www.eset.com/be-nl/zakelijk/data-protection-ebook/

28.8.19


 Cyberbullying: What schools and teachers can do

How schools and educators can address and help prevent abusive behavior on the Internet
These days, the internet is woven into people’s everyday lives, and children’s lives are no exception. For all its benefits, the technological evolution has also brought, or magnified, some problems, and cyberbullying is one of the most pervasive threats that youth face online. In fact, when a kid starts to be bullied at school, the harassment usually continues on social networks, messaging apps, and elsewhere on the internet. Educational institutions may think that the issues of the digital world lie outside the scope of schooling or that they don’t warrant scrutiny. However, online abuse and harassment often have a bigger impact on the victims than in-person bullying – and yet they may be ignored until it’s too late.

Importantly, on the internet everything can become more powerful. A social media post can reach hundreds or even thousands of people in a matter of minutes and before you know it, all those people may be talking and expressing opinions about the post or image. The impact of abusive content on the victim is magnified when there’s an increase in the number of people seeing, liking, sharing, and/or commenting on the post. Indeed, if the content has gone viral, it’s impossible to stop or delete it, even if the aggressors come to regret their actions.
On a related note, the sense of decreased inhibition afforded by screens and social networks due to the sense of anonymity may make many kids feel empowered enough to say and do things in the digital world that they would never do in the physical world.
Against this backdrop and as way to encourage a proactive approach in tackling cyberbullying and other types of online harassment, here are four principles that every school and teacher can apply in order to deal with this problem:

1. Educate students to be good digital citizens


Since the digital world is part of our real lives, the rules that apply on the internet should be the same as those we are already familiar with in the physical world. When teaching kids about respect and social conventions, it’s important to include the realm of the internet and ensure that they are also taught how to behave and communicate through digital media.
Subjects like civic education and citizenship should go beyond traditional boundaries to touch also on ethics, morality and respect in the digital world. Team exercises and activities are another powerful way to get groups to work together as one. The purpose of such activities is to get all the members of the class to work together toward a common goal, using all their individual strengths and valuing each person’s abilities to complete a task.

2. Prioritize awareness-raising over banning

Awareness is very powerful, not least because it changes social perceptions. Rather than creating panic over the use of technology or spreading misunderstandings, awareness allows a positive atmosphere to emerge.
Many schools choose to ban the use of technology, which can actually backfire in that pupils and students will use their phones on the sly. Young people identify with technology and adapt it to fit into their daily lives. That’s why it’s important to show students how they can use technology for the common good, such as to share knowledge or to support one another. Furthermore, by bringing technology into the classroom, teachers can focus on its ethical use.

3. Collective solidarity in reporting cyberbullying

A report by the Safe2Tell initiative found that, in 81% of cases of bullying at school, some group of students would have known about an attack, but would have decided not to report it. In most of these cases, the silence is mainly due to the fear of becoming the next victim or of facing punishment by adults. In these cases, children need to know that the problem is not technology, but rather people using it for the wrong ends. Promoting free-flowing dialogue and providing a space for listening also contributes to children knowing who to turn to if faced with abusive behavior.
On the other hand, online abuse can, and should, be reported on the platforms themselves. All social networks have the option to report posts, comments and even profiles that harm or harass someone. This is the only way to eliminate abusive content on social networks, because after a series of reports are received, the post or profile is deleted. These reports are completely anonymous, so there is no need to fear retaliation.

4. Dialogue: the basis for all support

Students need to know who they can reach out to before a problem arises. And in this area, trust is the key to open a dialogue. A recent survey (in Spanish) found that 25% of children and teenagers believe their elders know less than they do about technology. This perception makes them feel that their online problems are played down and not understood. What happens on the internet is viewed by children as very serious. Their digital identities are essentially the same for them as their real-world identities. For that reason, if a student approaches a teacher or other responsible adult with an online problem, the teacher needs to take it as seriously as a similar real-world issue and seek out the resources to deal with it.

It’s important to remember that while youngsters know a lot about how technology is used and how it works, adults have more real-life experience. With this in mind, exploring topics like technological risks, safety on the internet and appropriate online behavior are vital to encouraging dialogue. And it’s essential to break the silence around bullying and cyberbullying, by talking about instances of cyberabuse and their solutions. In doing so, teachers need to be clear and empathetic and to communicate openly with their students.

In conclusion, if we view digital communication as part of each person’s own little world, we can apply these thoughts expressed by Eleanor Roosevelt:
Where, after all, do universal human rights begin? In small places, close to home – so close and so small that they cannot be seen on any maps of the world. Yet they are the world of the individual person; the neighborhood he lives in; the school or college he attends; the factory, farm, or office where he works. Such are the places where every man, woman, and child seeks equal justice, equal opportunity, equal dignity without discrimination. Unless these rights have meaning there, they have little meaning anywhere. Without concerted citizen action to uphold them close to home, we shall look in vain for progress in the larger world.



27.8.19



InterSystems API Manager bewaakt API-verkeer tussen gedistribueerde softwareomgevingen

 InterSystems, wereldwijd toonaangevend in software voor de zorgsector en generieke informatietechnologie voor het bedrijfsleven en de overheid, introduceert InterSystems API Manager, als nieuwe functionaliteit voor InterSystems IRIS Data Platform™ 2019.2. Gebruikers daarvan zijn nu in staat om binnen hun IT-infrastructuur het berichtenverkeer tussen web gebaseerde API’s (Application Programming Interface) te monitoren en te sturen.

Het aantal toepassingen van API-koppelingen neemt exponentieel toe nu organisaties in alle geledingen kiezen voor internet gebaseerde applicaties, gelaagd volgens een ’service oriented’ architectuur (webservices). Het beheer over de diverse software omgevingen krijgt een meer gedistribueerd karakter. Om daar grip op te houden is het essentieel het API-verkeer goed te bewaken en waar nodig bij te sturen. InterSystems API Manager voorziet in het gemakkelijk routeren van al het API-verkeer via een centrale toegang (gateway) waardoor de aanvragen bij data uitwisseling tussen applicaties terechtkomen bij de juiste nodes (servers, databases, clients, apps. enz.).  

Systeemontwikkelaars die InterSystems API Manager gebruiken zijn ook in staat om:
  • Al het API-verkeer te monitoren vanaf een centrale locatie om van daaruit knelpunten te signaleren en te verhelpen;
  • API-verkeer gecontroleerd door te laten door per applicatie de toegestane omvang te configureren; IP-adressen op een witte, dan wel zwarte lijst te plaatsen en eindpunten in onderhoudsinspecties mee te nemen;
  • Op interactieve wijze API-documentatie te bieden aan in- en externe ontwikkelaars via een speciale, aanpasbaar ontwikkelaarsportaal;
  • API’s veilig op te bergen op een centrale plaats.
“Om te kunnen voldoen aan verwachtingen rond de digitale transformatie, gebruiken en implementeren ontwikkelaars razendsnel nieuwe API’s. Ze moeten om succesvol te zijn daarom kunnen beschikken over een intuïtief te gebruiken beheerinstrument”, zegt Scott Gnau, de binnen de InterSystems-organisatie verantwoordelijke manager voor Data Platforms. ”Wij zijn zeer verheugd onze klanten van het IRIS data platform te kunnen voorzien van de mogelijkheid van API-beheer voor het naadloos integreren en snel uitrollen van oplossingen voor data uitwisseling op bedrijfsniveau en sectorniveau of in het geval van zorgtoepassingen op regionaal dan wel landelijk niveau.”

InterSystems API Manager laat zich gemakkelijk configureren aan de hand van een web gebaseerde ’user interface’ of via API-calls en vormt daardoor een zeer bruikbaar instrument voor het op afstand uitrollen van applicaties. InterSystems API Manager komt in de vorm van een container en is dus veilig in een bestaande omgeving te introduceren. Ontwikkelaars kunnen ook een InterSystems API Manager cluster configureren, waarin meervoudige nodes zijn opgenomen en de doorvoercapaciteit is te verhogen zonder extra doorlooptijd. 

Meer informatie is te vinden op www.intersystemsbenelux.com

20.8.19


Ransomware wave hits 23 towns in Texas
The attack, which has victimized mostly smaller local governments, is thought to have been unleashed by a single threat actor
As many as 23 government organizations across Texas are reeling from an apparently “coordinated ransomware attack”, an alert by the Texas Department of Information Resources (DIR) reveals.
The incident occurred last Friday and for the most part affected smaller local governments, reads the alert’s update. The attack appears to have been unleashed by “one single threat actor”, said the agency, before adding that state‑owned systems and networks were spared. The scope of the damage isn’t immediately clear, however, as the DIR stopped short of disclosing much in the way of additional details about the incident.
As a result, there’s no word on which specific entities were hit or which ransomware strain took root in their computer systems. Nor did the DIR say how the simultaneous attack on almost two dozen entities transpired. Other unknowns include the attack’s perpetrator(s), the amount of the demanded ransom, whether paying up has been weighed as an option, and, indeed, how the recovery efforts are progressing.
(Separately, the city of Borger has disclosed that it is one of the victims, whereas the National Public Radio has quoted a DIR spokesman as saying that none of the affected municipalities has paid up.)
“Investigations into the origin of this attack are ongoing; however, response and recovery are the priority at this time,” reads the alert’s uppate.
Response teams from multiple Texan authorities as well as from federal agencies such as the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) are all working on bringing the affected systems back online. The situation prompted Texas Governor Greg Abbott to order a level 2 “escalated response”, which is one step below the highest level of alert – a level 1 “emergency.”
As shown by a recent report by threat intelligence provider Recorded Future, ransomware attacks on state and local governments in the US have been growing at a fast clip. AtlantaBaltimore and two Floridian cities, for example, have all seen their municipal systems crippled by various ransomware strains. Whereas the first two chose to claw back their systems, Riviera Beach and Lake City decided to pay the ransoms up front, highlighting the tough choices that ransomware victims face.
Just weeks ago, the US Conference of Mayors, which represents more than 1,400 mayors from cities around the country, vowed not to cave in to cyber-extortionists in case their systems are hit by ransomware.
For precautions that organizations in general can take to defend against this type of threat, please refer to Ransomware: Expert advice on how to keep safe and secure. Enterprises, although not only them, may be particularly interested in our comprehensive white paper, Ransomware: An enterprise perspective.