11.2.21

 


Operation NightScout: Supply-Chainattack targets online gaming in Asia

ESET Researchers uncover a supply-chain attack used in cyberespionage

operation targeting on-line gaming communities in Asia

 By Ignacio Sanmillan

 Following the publication of our research, BigNox have contacted us to say that their initial denial of the compromise was a misunderstanding on their part and that they have since taken these steps to improve security for their users:

·                           use only HTTPS to deliver software updates in order to minimize the risks of domain                        hijacking and Man-in-the-Middle (MitM) attacks

·       implement file integrity verification using MD5 hashing and file signature checks

·       adopt additional measures, notably encryption of sensitive data, to avoid exposing users’ personal information

BigNox have also stated that they have pushed the latest files to the update server for NoxPlayer and that, upon startup, NoxPlayer will now run a check of the application files previously installed on the users’ machines.

ESET assumes no responsibility for the accuracy of the information provided by BigNox.

During 2020, ESET research reported various supply-chain attacks, such as the case of WIZVERA VeraPort, used by government and banking websites in South Korea, Operation StealthyTrident compromising the Able Desktop chat software used by several Mongolian government agencies, and Operation SignSight, compromising the distribution of signing software distributed by the Vietnamese government.

In January 2021, we discovered a new supply-chain attack compromising the update mechanism of NoxPlayer, an Android emulator for PCs and Macs, and part of BigNox’s product range with over 150 million users worldwide.

This software is generally used by gamers in order to play mobile games from their PCs, making this incident somewhat unusual.

Three different malware families were spotted being distributed from tailored malicious updates to selected victims, with no sign of leveraging any financial gain, but rather surveillance-related capabilities.

We spotted similarities in loaders we have been monitoring in the past with some of the ones used in this operation, such as instances we discovered in a Myanmar presidential office website supply-chain compromise on 2018, and in early 2020 in an intrusion into a Hong Kong university.

About BigNox

BigNox is a company based in Hong Kong, which provides various products, primarily an Android emulator for PCs and Macs called NoxPlayer. The company’s official website claims that it has over 150 million users in more than 150 countries speaking 20 different languages. However, it’s important to note that the BigNox follower base is predominantly in Asian countries.

BigNox also wrote an extensive blogpost in 2019 on the use of VPNs in conjunction with NoxPlayer, showing the company’s concern for their users’ privacy.

We have contacted BigNox about the intrusion, and they denied being affected. We have also offered our support to help them past the disclosure in case they decide to conduct an internal investigation.

Am I compromised?

·       Who is affected: NoxPlayer users.

 

Complete article on

https://www.welivesecurity.com/2021/02/01/operation-nightscout-supply-chain-attack-online-gaming-asia/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

 Hacker attempts to poison Florida city’s water supply

While the incursion was thwarted in time, cyberattacks targeting critical infrastructure are a major cause for concern

 Amer Owaida

Last Friday, an unknown attacker accessed the computer systems of a water treatment facility in Oldsmar, Florida, and attempted to poison the city’s water supply by manipulating the chemical levels of sodium hydroxide.

This substance, commonly referred to as lye or caustic soda, is used across various industries and can be found in liquid drain cleaners, detergents and is also used to control water acidity. However, if ingested, it can cause spontaneous vomiting, chest and abdominal pain, difficulty swallowing with drooling, and corrosive injuries.

Speaking at a press conference about the attack, Pinellas County Sheriff Bob Gualtieri said that at about 8:00 AM on Friday a plant operator noticed that someone remotely accessed the system he was monitoring. Since the system is often accessed using specialized software by authorized personnel to troubleshoot problems remotely and for monitoring purposes, the operator didn’t give it much thought. The plant serves approximately 15,000 residents.

However, at approximately 1:30 PM local time the operator noticed that the system was being accessed again. This time the perpetrator accessed various functions that control the water being treated including part of the software that controls the levels of sodium hydroxide in the water. They then proceeded to change the levels from 100 parts per million to 11,100 parts per million, after which they exited the system.

“The plant operator immediately reduced the level back to the appropriate amount of 100 parts. Because the operator noticed the increase and lowered it right away, at no time was there a significant adverse effect on the water being treated. Importantly the public was never in danger,” said the sheriff.

While the name of the program used to access the system wasn’t specified, according to Reuters reporter Chris Bing, the hackers were able to infiltrate the systems through TeamViewer, widely used software for remote support and access.

Oldsmar mayor Eric Seidel said that the good news is that the monitoring protocols they have in place work. “Even had they not caught them, there’s redundancies in the system that would have caught the change in the pH level,” he added.

The Pinellas County Sheriff’s office is investigating the attack together with the Federal Bureau of Investigation (FBI) and the United States Secret Service. So far, no suspects have been identified and it’s unclear whether the attack originated from the US or abroad; however, they are following up on leads.

The breach of the water treatment plant has raised concerns about possible further attacks; all government authorities in the Tampa Bay area with critical infrastructure components were requested to actively review their computer security protocols.

31.1.21

 

Trois patches Apple contre des menaces zéro‑day exploitées

La société émet des mises à jour d'urgence pour corriger les bogues affectant des appareils allant des iPhones aux montres Apple.

 


Amer Owaida

Apple a mis à jour ses systèmes d’exploitation iOS et iPadOS pour corriger trois failles de sécurité de type zéro-day qui sont activement exploitées dans la nature. Le trio de failles concerne différentes versions d’iPhones et d’iPads et la dernière génération d’iPod touch.

« Apple a connaissance d’un rapport selon lequel ce problème aurait été activement exploité », précise l’alerte de sécurité d’Apple, qui décrit chaque faille de sécurité qui est résolue avec la sortie de la version 14.4 d’iOS et d’iPadOS.

La liste des appareils concernés comprend les iPhone 6 et plus, les iPad Air 2 et plus, les iPad mini 4 et plus et la 7e génération d’iPod touch. Le titan de la technologie basé à Cupertino a également publié des mises à jour de sécurité pour l’une des vulnérabilités sur une série de ses autres offres, y compris Apple Watch (watchOS 7.3) et Apple TVs (tvOS 14.4).

Comme d’habitude, on ne sait rien des auteurs et des cibles de ces attaques zéro-day, qui exploitent les failles du noyau du système d’exploitation et du moteur de navigation WebKit.

La première faille, identifiée CVE-2021-1782 et située dans le noyau du système d’exploitation, est un bogue de condition de course qui pourrait conduire à une escalade des privilèges, qui pourrait être exploitée par un attaquant utilisant une application malveillante. En clair, cela signifie qu’un attaquant pourrait utiliser l’application pour obtenir des privilèges supplémentaires dans le système d’exploitation de l’appareil, ce qui lui permettrait de faire toutes sortes de dégâts.

Pendant ce temps, les deux autres failles de sécurité, indexées comme CVE-2021-1871 et CVE-2021-1870, résident dans le composant WebKit, le moteur de navigation web open-source d’Apple utilisé par le navigateur Safari, Mail, et diverses autres applications iOS et iPadOS. Selon la description du bogue, il provient d’un « problème de logique » qui pourrait être exploité par un attaquant distant et lui permettre d’exécuter du code arbitraire. Selon Vulmon, le duo de failles pourrait être exploité « en persuadant une victime de visiter un site web spécialement conçu ».

Au-delà des trois zéros jours, qui ont tous été mis au jour par des chercheurs anonymes, Apple a également publié des correctifs de sécurité pour les failles affectant ses produits Xcode et iCloud pour Windows.

L’équipe d’intervention d’urgence informatique de Hong Kong (HKCERT) a émis une alerte classant les vulnérabilités comme « à risque extrêmement élevé » et invitant les utilisateurs des appareils Apple concernés à appliquer les mises à jour immédiatement. Si vous n’avez pas activé les mises à jour automatiques, vous pouvez mettre à jour vos appareils manuellement en allant dans le menu Paramètres, puis en appuyant sur Général et en allant dans la section Mise à jour du logiciel.

Apple a précédemment détruit trois autres vulnérabilités zéro-days qui étaient activement exploités dans la nature en novembre de l’année dernière.

 

21.1.21

 

FBI warns of voice phishing attacks stealing corporate credentials

Criminals coax employees into handing over their access credentials and use the login data to burrow deep into corporate networks

Amer Owaida

The United States’ Federal Bureau of Investigation (FBI) has issued a warning about campaigns where threat actors target employees worldwide with voice phishing (also known as vishing) attacks in order to steal their network credentials and elevate user privileges.

The warning can in part be attributed to the fact that the COVID-19 pandemic has forced many companies to shift to telework, which may not allow for comprehensive monitoring of network access points and privilege escalation.

The Bureau highlighted a campaign that goes back to December 2019 and involved attackers targeting employees at large businesses in the US and elsewhere through Voice over IP (VoIP) platforms as well as a company chatroom in order to coax credentials into corporate networks.

“During the phone calls, employees were tricked into logging into a phishing webpage in order to capture the employee’s username and password,” reads the FBI’s description of one attack vector, which often involves spoofed caller ID numbers that conceal the criminal’s location and identity.

Before long, the threat actors found that they could burrow deeper into the networks than they’d initially believed and that they even had the ability to elevate permissions on the compromised accounts.

In these scenarios, attackers can wreak all manner of havoc on a company’s systems such as implanting malware, sifting through the company’s data to search for proprietary data, or gaining access to account credentials of executives with the aim of conducting Business Email Compromise (BEC) fraud. Needless to say, any of this could cost any company dearly.

Meanwhile, in another case, cybercriminals first contacted an employee via the company’s chatroom and duped the person into logging into a fraudulent Virtual Private Network (VPN) page. Using the captured account credentials, they then accessed the company’s network, where they searched for an employee with the ability to change usernames and emails.

The cybercriminals were successful in identifying their target via a cloud-based payroll service and went on to phish the victim’s credentials using the chatroom tactic as well.

RELATED READING: Strengthening the different layers of IT networks

The federal law enforcement agency also shared advice on how companies could mitigate the risks of such attacks. This includes implementing multi-factor authentication, actively scanning and monitoring for unauthorized access, network segmentation, and periodic reviews of employee network access.

In August 2020, the FBI together with the Cybersecurity and Infrastructure Security Agency (CISA) issued a similar advisory warning about a surge in vishing attacks targeting staff at multiple companies. During these attacks, the threat actors also used similar tactics including fraudulent VPN pages to obtain account credentials.

14.1.21

Operation Spalax: Targeted malware attacks in Colombia

ESET researchers uncover attacks targeting Colombian government institutions and private companies, especially from the energy and metallurgical industries

In 2020 ESET saw several attacks targeting Colombian entities exclusively. These attacks are still ongoing at the time of writing and are focused on both government institutions and private companies. For the latter, the most targeted sectors are energy and metallurgical. The attackers rely on the use of remote access trojans, most likely to spy on their victims. They have a large network infrastructure for command and control: ESET observed at least 24 different IP addresses in use in the second half of 2020.

These are probably compromised devices that act as proxies for their C&C servers. This, combined with the use of dynamic DNS services, means that their infrastructure never stays still. We have seen at least 70 domain names active in this timeframe and they register new ones on a regular basis.

The attackers

The attacks we saw in 2020 share some TTPs with previous reports about groups targeting Colombia, but also differ in many ways, thus making attribution difficult.

One of those reports was published in February 2019, by QiAnXin researchers. The operations described in that blogpost are connected to an APT group active since at least April 2018. We have found some similarities between those attacks and the ones that we describe in this article:

·       We saw a malicious sample included in IoCs of QiAnXin’s report and a sample from the new campaign in the same government organization. These files have fewer than a dozen sightings eeach.

·       SSome of the phishing emails from the current campaign were sent from IP addresses cCorresponding to a range that belongs to Powerhouse Management, a VPN service. The same IP aaddress range was used for emails sent in the earlier campaign.

·       The phishing emails have similar topics and pretend to come from some of the same entities – for example, the Office of the Attorney General (Fiscalia General de la Nacion) or the National Directorate of Taxes and Customs (DIAN).

·       Some of the C&C servers in Operation Spalax use linkpc.net and publicvm.com subdomains, along with IP addresses that belong to Powerhouse Management. This also happened in the earlier campaign.

However, there are differences in the attachments used for phishing emails, the remote access trojans (RATs) used and in most of the operator’s C&C infrastructure.

There is also this report from Trend Micro, from July 2019. There are similarities between the phishing emails and parts of the network infrastructure in that campaign and the one we describe here. The attacks described in that article were connected to cybercrime, not espionage. While we have not seen any payload delivered by the attackers other than RATs, some of the targets in the current campaign (such as a lottery agency) don’t make much sense for spying activities.

These threat actors show perfect usage of the Spanish language in the emails they send, they only target Colombian entities, and they use premade malware and don’t develop any themselves.

Attack overview

Targets are approached with emails that lead to the download of malicious files. In most cases, these emails have a PDF document attached, which contains a link that the user must click to download the malware. The downloaded files are regular RAR archives that have an executable file inside. These archives are hosted in legitimate file hosting services such as OneDrive or MediaFire. The target has to manually extract the file and execute it for the malware to run.

We’ve found a variety of packers used for these executables, but their purpose is always to have a remote access trojan running on the victimized computer, usually by decrypting the payload and injecting it into legitimate processes. An overview of a typical attack is shown in Figure 1. We have seen the attackers use three different RATs: Remcos, njRAT and AsyncRAT.

Read the full article on https://www.welivesecurity.com/2021/01/12/operation-spalax-targeted-malware-attacks-colombia/

 


4.1.21





7 ways malware can get into your device

You know that malware is bad, but are you also aware of the various common ways in which it can infiltrate your devices?

Malware has been one of the most common threats that netizens face daily. However, although you have heard about the various types of malware you can encounter, chances are you don’t know how these malicious programs are able to infest your devices.

While knowing what types of threats exist is the first step towards protecting yourself and your devices, the next and arguably more important step is to know how threat actors try to sneak these malicious pieces of code into your computers, smartphones, and tablets. To help you combat these threats, we look at some of the most common methods and tactics used to tricking netizens into downloading malware and compromising their data and security.

Phishing and malspam emails

Usually the main objective of phishing emails is to wheedle sensitive information out of you such as your access credentials to various services, your card verification code (last three digits on the backside of your payment card), PIN code, or other personally identifiable information (PII). But by masquerading as mail from a trusted institution, they may contain attachments or links that will lead to your device getting infested with malware.

Therefore, it’s always prudent to not just skim over your emails but read them thoroughly. More often than not you’ll notice dead giveaways that you’re dealing with a scam. Telltale signs usually include spelling mistakes, evoking a sense of urgency, requesting personal information, or the email originating from a suspicious domain.

Fraudulent websites

To trick victims into downloading malicious apps, cybercriminals like to spoof websites of famous brands or organizations. The scammers create fraudulent webpages impersonating the real deal, with the domain name resembling the domain of the organization being spoofed as closely as possible, with some subtle differences here and there, such as adding a letter or symbol or even a whole word. The websites will be malware-laced and will try to dupe the target into clicking on links that will download malware into their devices.

To avoid getting your device infested with malware by visiting one of these websites, always search for the official domain by typing it into a search engine or by typing it manually into the address bar. It bears repeating that a proper security solution will also protect you from most threats and will also block you from accessing known malicious websites.

USB flash drives

External storage devices are a popular form of storing and transferring files; however, they do carry a number of risks. For example, threat actors like to use the “lost” flash-drive social engineering strategy, to dupe unwitting good Samaritans into plugging a compromised thumb drive into their computers. Once an afflicted drive is plugged in and opened your device can get infested with a keylogger or ransomware.

Alternatively, if you aren’t careful about how you handle your flash drive, your computer may get infested by cross-contamination. To mitigate the chances of contaminating your PC you should use a reputable and up-to-date endpoint security solution that will scan any external media plugged into your device and warn you if it contains anything suspicious.

P2P sharing and torrents

While over the years peer-to-peer sharing and torrents have gained a reputation for being a place to illegally download software, games, and media, they have been used by developers as an easy way to disseminate their open-source software or musicians to spread their songs. However, they are also infamous for being abused by black hats who inject the shared files with malicious code. Most recently, ESET researchers uncovered cybercriminals misusing the BitTorrent protocol and Tor network to spread KryptoCibule, a multitasking multicurrency cryptostealer.

To minimize the risk of being compromised, you should use a reputable Virtual Private Network (VPN) to encrypt your traffic and keep it safe from prying eyes. You should also use an up-to-date security solution that can protect you from most threats including viruses or malware that may be a part of the files you’re trying to torrent.

Compromised software

Although it may not happen often, software being directly compromised by threat actors isn’t a rare occurrence. One prominent example of an application’s security being compromised was the case of CCleaner. In these attacks, the black hats inject the malware directly into the application, which is then used to spread the malware when unsuspecting users download the app.

Since CCleaner is a trusted application, it wouldn’t have occurred to a user to overly scrutinize it. However, you should be careful when downloading any type of software – even the one you trust. You also can’t go wrong by using a reputable security solution and don’t forget to patch and update your apps regularly, security patches usually deal with any vulnerabilities or loopholes found in the affected apps.

Adware

Some websites are riddled with various ads that pop up whenever you click on any section of the webpage or can even appear immediately whenever you access certain websites. While the aim of these ads is generally to generate revenue for these sites, sometimes they are laced with various types of malware and by clicking on these ads or adware, you may involuntarily download it onto your device. Some ads even use scare tactics telling users that their devices have been compromised and only the solution offered in the ad can clean up the compromise; however, that is almost never the case.

A sizeable amount of the adware can be avoided by using trusted ad-blocking extensions on your browser, which will, as the name suggests, block ads from appearing on the website you’re visiting. Another thing you can do is avoid suspicious websites that use such advertisements altogether.

Fake apps

The last item on this list deals with fake mobile applications. These apps usually masquerade as the real thing and try to dupe users onto downloading them into the victims’ devices, thereby compromising the devices. They can take on the guise of anything, posing as fitness-tracking tools, cryptocurrency apps, or even COVID-19 tracing apps. However, in reality, instead of receiving the advertised services, the devices will get infested with various flavors of malware such as ransomware, spyware, or keyloggers.

To avoid downloading any malicious apps onto your devices, you should stick with applications offered by trusted developers with a verifiable track record and reviews. Also keeping your devices patched and up-to-date can help you stay protected from various threats that would try to exploit the vulnerabilities that may be present in older versions of apps and operating systems.

Conclusion

While the list of strategies used by cybercriminals to target unsuspecting citizens is long and it may get longer (black hats keep coming up with new malicious tactics, after all), there are ways you can keep your data secure and your devices protected. These threats can be countered by adhering to cybersecurity best practices, which include using reputable security solutions and keeping your systems patched and up to date. 

23.12.20

 


ESET beloond met AV-Test Top Product-awards voor beste Windows-antivirussoftware

ESET, een wereldleider op het gebied van cyberbeveiliging, werd beloond met Top Product Awards van AV-TEST in de nieuwste review- en certificeringsrapporten voor de categorieën ondernemingen (business) en consumenten (home consumer). ESET Endpoint Security 7.3 en ESET Internet Security 13.2, beveiligingsproducten voor Windows, behaalden, tijdens tests die in augustus en oktober 2020 werden uitgevoerd in de professionele en consumentensectie, de Top Product-awards met perfecte scores voor Bescherming en Bruikbaarheid.

AV-TEST, een toonaangevende onafhankelijke testorganisatie, gebruikt een van 's werelds grootste collecties malware om een ​​echte omgeving te creëren voor zeer nauwkeurige interne tests en realistische testcases.

De tests evalueerden de beste Windows-antivirussoftware voor zowel thuis- als zakelijke gebruikers, waarbij alle leveranciers in drie hoofdcategorieën beoordeeld worden: Bescherming, Prestaties en Bruikbaarheid. In zowel de consumenten- als bedrijfsevaluaties scoorden de oplossingen van ESET een perfecte 6 in de categorie Bescherming, die metingen uitvoert in zake malware zoals virussen, wormen en Trojaanse paarden. Een perfecte 6 werd ook behaald in de categorie Bruikbaarheid, die de impact meet van de beveiligingssoftware op de bruikbaarheid van de computer. Beide oplossingen scoorden ook bijna perfecte scores van 5,5 in de categorie Prestaties, die bij dagelijks gebruik de impact van het product op de computersnelheid meet.

Naast deze uitstekende resultaten ontving ESET afgelopen zomer zijn 100ste AV-Test-certificaat. Deze onderscheiding viel samen met de tiende verjaardag van het eerste AV-Test-certificaat door ESET behaald in juni 2010.

Roman Kováč, Chief Research Officer bij ESET, merkt op: “Het is bijzonder aanmoedigend om niet alleen geprezen te worden voor onze beveiligingsoplossingen voor consumenten en professionals, maar ook om erkend te worden voor tien jaar consistente en uitstekende resultaten bij tests door derden. Bij ESET zijn we erg trots op ons werk om technologie veiliger te maken. Deze erkenning door AV-Test bewijst opnieuw dat onze oplossingen in realistische scenario's werken. Bedrijven en thuisgebruikers kunnen erop vertrouwen dat ze bij ESET in veilige handen zijn. Na een jaar als geen ander is het nog nooit zo belangrijk geweest dat gevoelige informatie en gegevens beschermd worden met geavanceerde beveiligingssoftware, zowel op het werk als thuis."

Verneem meer over de thuis- en zakelijke oplossingen van ESET voor Windows op https://www.eset.com/be-nl/