602-461-7219

Phoenix Technology Solutions
  • Home
  • Is This You?
  • 10 Things We Do Better
  • Services
    • Managed Services
    • Backup and Disaster Recovery
    • IT Consulting
    • VoIP/Phone Solutions
    • Email / Spam Protection
    • Hosted Solutions
    • Virtualization
  • Contact Us
  • Menu Menu
  • Link to Facebook
  • Link to X
  • Link to LinkedIn
  • Link to Rss this site

Disneyland Malware Team: It’s a Puny World After All

November 16, 2022/0 Comments/in Blog/by Phoenix Technology

A financial cybercrime group calling itself the Disneyland Team has been making liberal use of visually confusing phishing domains that spoof popular bank brands using Punycode, an Internet standard that allows web browsers to render domain names with non-Latin alphabets like Cyrillic.

The Disneyland Team’s Web interface, which allows them to interact with malware victims in real time to phish their login credentials using phony bank websites.

The Disneyland Team uses common misspellings for top bank brands in its domains. For example, one domain the gang has used since March 2022 is ushank[.]com — which was created to phish U.S. Bank customers.

But this group also usually makes use of Punycode to make their phony bank domains look more legit. The U.S. financial services firm Ameriprise uses the domain ameriprise.com; the Disneyland Team’s domain for Ameriprise customers is https://www.xn--meripris-mx0doj[.]com [brackets added to defang the domain], which displays in the browser URL bar as ạmeriprisẹ[.]com.

Look carefully, and you’ll notice small dots beneath the “a” and the second “e”. You could be forgiven if you mistook one or both of those dots for a spec of dust on your computer screen or mobile device.

This candid view inside the Disneyland Team comes from Alex Holden, founder of the Milwaukee-based cybersecurity consulting firm Hold Security. Holden’s analysts gained access to a Web-based control panel the crime group has been using to keep track of victim credentials (see screenshot above). The panel reveals the gang has been operating dozens of Punycode-based phishing domains for the better part of 2022.

Have a look at the Punycode in this Disneyland Team phishing domain: https://login2.xn--mirtesnbd-276drj[.]com, which shows up in the browser URL bar as login2.ẹmirạtesnbd[.]com, a domain targeting users of Emirates NBD Bank in Dubai.

Here’s another domain registered this year by the Disneyland Team: https://xn--clientchwb-zxd5678f[.]com, which spoofs the login page of financial advisor Charles Schwab with the landing page of cliẹntșchwab[.]com. Again, notice the dots under the letters “e” and “s”.  Another Punycode domain of theirs sends would-be victims to cliẹrtschwạb[.]com, which combines a brand misspelling with Punycode.

We see the same dynamic with the Disneyland Team Punycode domain https://singlepoint.xn--bamk-pxb5435b[.]com, which translates to singlepoint.ụșbamk[.]com — again phishing U.S. Bank customers.

What’s going on here? Holden says the Disneyland Team is Russian-speaking — if not also based in Russia —  but it is not a phishing gang per se. Rather, this group uses the phony bank domains in conjunction with malicious software that is already secretly installed on a victim’s computer.

Holden said the Disneyland Team domains were made to help the group steal money from victims infected with a powerful strain of Microsoft Windows-based banking malware known as Gozi 2.0/Ursnif. Gozi specializes in collecting credentials, and is mainly used for attacks on client-side online banking to facilitate fraudulent bank transfers. Gozi also allows the attackers to connect to a bank’s website using the victim’s computer.

In years past, crooks like these would use custom-made “web injects” to manipulate what Gozi victims see in their Web browser when they visit their bank’s site. These web injects allowed malware to rewrite the bank’s HTML code on the fly, and copy and/or intercept any data users would enter into a web-based form, such as a username and password.

Most Web browser makers, however, have spent years adding security protections to block such nefarious activity. As a result, the Disneyland Team simply tries to make their domains look as much like the real thing as possible, and then funnel victims toward interacting with those imposter sites.

“The reason that it is infeasible for them to use in-browser injects include browser and OS protection measures, and difficulties manipulating dynamic pages for banks that require multi-factor authentication,” Holden said.

In reality, the fake bank website overlaid by the Disneyland Team’s malware relays the victim’s browser activity through to the real bank website, while allowing the attackers to forward any secondary login requests from the bank, such as secret questions or multi-factor authentication challenges.

The Disneyland Team included instructions for its users, noting that when the victim enters their login credentials, he sees a 10-second spinning wheel, and then the message, “Awaiting back office approval for your request. Please don’t close this window.”

A fake PNC website overlay or “web inject” displaying a message intended to temporarily prevent the user from accessing their account.

The “SKIP” button in the screenshot above sends the user to the real bank login page, “in case the account is not interesting to us,” the manual explains. “Also, this redirect works if none of our operators are working at the time.”

The “TAKE” button in the Disneyland Team control panel allows users or affiliates to claim ownership over a specific infected machine or bot, which then excludes other users from interacting with that victim.

In the event that it somehow takes a long time to get the victim (bot) connected to the Disneyland Team control panel, or if it is necessary to delay a transaction, users can push a button that prompts the following message to appear on the victim’s screen:

“Your case ID number is 875472. An online banking support representative will get in touch shortly. Please provide your case ID number, and DO NOT close this page.”

The Disneyland user manual explains that the panel can be used to force the victim to log in again if they transmit invalid credentials. It also has other options for stalling victims whilst their accounts are drained. Another fake prompt the panel can produce shows the victim a message saying, “We are currently working on updating our security system. You should be able to log in once the countdown timer expires.”

The user manual says this option blocks the user from accessing their account for two hours. “It is possible to block for an hour with this button, in this case they get less frustrated, within the hours ddos will kill their network.”

Cybercrime groups will sometimes launch distributed denial-of-service (DDoS) attacks on the servers of the companies they’re trying to rob — which is usually intended to distract victims from their fleecing, although Holden said it’s unclear if the Disneyland Team employs this tactic as well.

For many years, KrebsOnSecurity tracked the day-to-day activities of a similar malware crew that used web injects and bots to steal tens of millions of dollars from small- to mid-sized businesses across the United States.

At the end of each story, I would close with a recommendation that anyone concerned about malware snarfing their banking information should strongly consider doing their online banking from a dedicated, security-hardened system which is only used for that purpose. Of course, the dedicated system approach works only if you always use that dedicated system for managing your account online.

Those stories also observed that since the vast majority of the malicious software used in cyberheists is designed to run only on Microsoft Windows computers, it made sense to pick a non-Windows computer for that dedicated banking system, such as a Mac or even a version of Linux. I still stand by this advice.

In case anyone is interested, here (PDF) is a list of all phishing domains currently and previously used by the Disneyland Team.

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-16 19:57:482022-11-16 19:58:00Disneyland Malware Team: It’s a Puny World After All

Top Zeus Botnet Suspect “Tank” Arrested in Geneva

November 15, 2022/0 Comments/in Blog/by Phoenix Technology

Vyacheslav “Tank” Penchukov, the accused 40-year-old Ukrainian leader of a prolific cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses in the United States and Europe, has been arrested in Switzerland, according to multiple sources.

Wanted Ukrainian cybercrime suspect Vyacheslav “Tank” Penchukov (right) was arrested in Geneva, Switzerland. Tank was the day-to-day manager of a cybercriminal group that stole tens of millions of dollars from small to mid-sized businesses.

Penchukov was named in a 2014 indictment by the U.S. Department of Justice as a top figure in the JabberZeus Crew, a small but potent cybercriminal collective from Ukraine and Russia that attacked victim companies with a powerful, custom-made version of the Zeus banking trojan.

The U.S. Federal Bureau of Investigation (FBI) declined to comment for this story. But according to multiple sources, Penchukov was arrested in Geneva, Switzerland roughly three weeks ago as he was traveling to meet up with his wife there.

Penchukov is from Donetsk, a traditionally Russia-leaning region in Eastern Ukraine that was recently annexed by Russia. In his hometown, Penchukov was a well-known deejay (“DJ Slava Rich“) who enjoyed being seen riding around in his high-end BMWs and Porsches. More recently, Penchukov has been investing quite a bit in local businesses.

The JabberZeus crew’s name is derived from the malware they used, which was configured to send them a Jabber instant message each time a new victim entered a one-time password code into a phishing page mimicking their bank. The JabberZeus gang targeted mostly small to mid-sized businesses, and they were an early pioneer of so-called “man-in-the-browser” attacks, malware that can silently siphon any data that victims submit via a web-based form.

Once inside a victim company’s bank accounts, the crooks would modify the firm’s payroll to add dozens of “money mules,” people recruited through work-at-home schemes to handle bank transfers. The mules in turn would forward any stolen payroll deposits — minus their commissions — via wire transfer overseas.

Tank, a.k.a. “DJ Slava Rich,” seen here performing as a DJ in Ukraine in an undated photo from social media.

The JabberZeus malware was custom-made for the crime group by the alleged author of the Zeus trojan — Evgeniy Mikhailovich Bogachev, a top Russian cybercriminal with a $3 million bounty on his head from the FBI. Bogachev is accused of running the Gameover Zeus botnet, a massive crime machine of 500,000 to 1 million infected PCs that was used for large DDoS attacks and for spreading Cryptolocker — a peer-to-peer ransomware threat that was years ahead of its time.

Investigators knew Bogachev and JabberZeus were linked because for many years they were reading the private Jabber chats between and among members of the JabberZeus crew, and Bogachev’s monitored aliases were in semi-regular contact with the group about updates to the malware.

Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, noted in his blog from 2014 that Tank told co-conspirators in a JabberZeus chat on July 22, 2009 that his daughter, Miloslava, had been born and gave her birth weight.

“A search of Ukrainian birth records only showed one girl named Miloslava with that birth weight born on that day,” Warner wrote. This was enough to positively identify Tank as Penchukov, Warner said.

Ultimately, Penchukov’s political connections helped him evade prosecution by Ukrainian cybercrime investigators for many years. The late son of former Ukrainian President Victor Yanukovych (Victor Yanukovych Jr.) would serve as godfather to Tank’s daughter Miloslava. Through his connections to the Yanukovych family, Tank was able to establish contact with key insiders in top tiers of the Ukrainian government, including law enforcement.

Sources briefed on the investigation into Penchukov said that in 2010 — at a time when the Security Service of Ukraine (SBU) was preparing to serve search warrants on Tank and his crew — Tank received a tip that the SBU was coming to raid his home. That warning gave Tank ample time to destroy important evidence against the group, and to avoid being home when the raids happened. Those sources also said Tank used his contacts to have the investigation into his crew moved to a different unit that was headed by his corrupt SBU contact.

Writing for Technology Review, Patrick Howell O’Neil recounted how SBU agents in 2010 were trailing Tank around the city, watching closely as he moved between nightclubs and his apartment.

“In early October, the Ukrainian surveillance team said they’d lost him,” he wrote. “The Americans were unhappy, and a little surprised. But they were also resigned to what they saw as the realities of working in Ukraine. The country had a notorious corruption problem. The running joke was that it was easy to find the SBU’s anticorruption unit—just look for the parking lot full of BMWs.”

AUTHOR’S NOTE/BACKGROUND

I first encountered Tank and the JabberZeus crew roughly 14 years ago as a reporter for The Washington Post, after a trusted source confided that he’d secretly gained access to the group’s private Jabber conversations.

From reading those discussions each day, it became clear Tank was nominally in charge of the Ukrainian crew, and that he spent much of his time overseeing the activities of the money mule recruiters — which were an integral part of their victim cashout scheme.

It was soon discovered that the phony corporate websites the money mule recruiters used to manage new hires had a security weakness that allowed anyone who signed up at the portal to view messages for every other user. A scraping tool was built to harvest these money mule recruitment messages, and at the height of the JabberZeus gang’s activity in 2010 that scraper was monitoring messages on close to a dozen different money mule recruitment sites, each managing hundreds of “employees.”

Each mule was given busy work or menial tasks for a few days or weeks prior to being asked to handle money transfers. I believe this was an effort to weed out unreliable money mules. After all, those who showed up late for work tended to cost the crooks a lot of money, as the victim’s bank would usually try to reverse any transfers that hadn’t already been withdrawn by the mules.

When it came time to transfer stolen funds, the recruiters would send a message through the fake company website saying something like: “Good morning [mule name here]. Our client — XYZ Corp. — is sending you some money today. Please visit your bank now and withdraw this payment in cash, and then wire the funds in equal payments — minus your commission — to these three individuals in Eastern Europe.”

Only, in every case the company mentioned as the “client” was in fact a small business whose payroll accounts they’d already hacked into.

So, each day for several years my morning routine went as follows: Make a pot of coffee; shuffle over to the computer and view the messages Tank and his co-conspirators had sent to their money mules over the previous 12-24 hours; look up the victim company names in Google; pick up the phone to warn each that they were in the process of being robbed by the Russian Cyber Mob.

My spiel on all of these calls was more or less the same: “You probably have no idea who I am, but here’s all my contact info and what I do. Your payroll accounts have been hacked, and you’re about to lose a great deal of money. You should contact your bank immediately and have them put a hold on any pending transfers before it’s too late. Feel free to call me back afterwards if you want more information about how I know all this, but for now please just call or visit your bank.”

In many instances, my call would come in just minutes or hours before an unauthorized payroll batch was processed by the victim company’s bank, and some of those notifications prevented what otherwise would have been enormous losses — often several times the amount of the organization’s normal weekly payroll. At some point I stopped counting how many tens of thousands of dollars those calls saved victims, but over several years it was probably in the millions.

Just as often, the victim company would suspect that I was somehow involved in the robbery, and soon after alerting them I would receive a call from an FBI agent or from a police officer in the victim’s hometown. Those were always interesting conversations.

Collectively, these notifications to victims led to dozens of stories over several years about small businesses battling their financial institutions to recover their losses. I never wrote about a single victim that wasn’t okay with my calling attention to their plight and to the sophistication of the threat facing other companies.

This incessant meddling on my part very much aggravated Tank, who on more than one occasion expressed mystification as to how I knew so much about their operations and victims. Here’s a snippet from one of their Jabber chats in 2009, after I’d written a story for The Washington Post about their efforts to steal $415,000 from the coffers of Bullitt County, Kentucky. In the chat below, “lucky12345” is the Zeus author Bogachev:

tank: Are you there?
tank: This is what they damn wrote about me.
tank: http://voices.washingtonpost.com/securityfix/2009/07/an_odyssey_of_fraud_part_ii.html#more
tank: I’ll take a quick look at history
tank: Originator: BULLITT COUNTY FISCAL Company: Bullitt County Fiscal Court
tank: Well, you got [it] from that cash-in.
lucky12345: From 200K?
tank: Well, they are not the right amounts and the cash out from that account was shitty.
tank: Levak was written there.
tank: Because now the entire USA knows about Zeus.
tank: ????
lucky12345: It’s fucked.

On Dec. 13, 2009, one of Tank’s top money mule recruiters — a crook who used the pseudonym “Jim Rogers” — told his boss something I hadn’t shared beyond a few trusted confidants at that point: That The Washington Post had eliminated my job in the process of merging the newspaper’s Web site (where I worked at the time) with the dead tree edition.

jim_rogers: There is a rumor that our favorite (Brian) didn’t get his contract extension at Washington Post. We are giddily awaiting confirmation ???? Good news expected exactly by the New Year! Besides us no one reads his column ????

tank: Mr. Fucking Brian Fucking Kerbs!

Another member of the JabberZeus crew — Ukrainian-born Maksim “Aqua” Yakubets — also is currently wanted by the FBI, which is offering a $5 million reward for information leading to his arrest and conviction.

Alleged “Evil Corp” bigwig Maksim “Aqua” Yakubets. Image: FBI

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-15 19:48:202022-11-15 19:48:41Top Zeus Botnet Suspect “Tank” Arrested in Geneva

Cybersecurity Sharing | An Infosec User’s Guide to Getting Started on Mastodon

November 14, 2022/0 Comments/in Blog/by Phoenix Technology

Twitter, it seems fair to say, is going through some turbulent times, and whatever else people might say about the microblogging social platform, there’s no doubt that it’s a major source of information exchange in the cybersecurity world. From infosec news to threat actor IoCs, open source PoCs, conference announcements, and OSINT intelligence – not to mention plenty of entertainment and pet pics – Twitter has long been the social media platform of choice for the cybersecurity world.

The last two weeks, however, have seen massive interest in a rival platform, Mastodon. Many in infosec have said they are moving to Mastodon exclusively, others are using  Mastodon as well as Twitter, while thousands of others wait and wonder what this fragmentation might look like in the weeks and months ahead, unsure of how to get started with this alternative social media platform or whether it will work for them.

In this post, we provide an essential guide to getting up and running with Mastodon, discuss how it differs from Twitter, and how to navigate some of its more challenging aspects. We’ll explain how to find and hook up with the rest of the infosec community, including some of our favorite cybersecurity Twitter stars.

What is Mastodon?

Although most people have only just become aware of it, Mastodon is a social media sharing platform, much like Twitter, that has been around since 2016. Starting out as a Patreon project, it was launched in part to help combat some of the problems facing Twitter users, in particular privacy and harassment issues.

The central idea behind Mastodon is that smaller communities can better self-regulate than larger ones, and Mastodon itself is a collection or “federation” of multiple small communities, each on its own server, or ‘instance’.

There is no central body or organization – individuals own the servers, and users can choose and move between servers as they wish. Some servers may block feeds from other servers (e.g., porn sites, extremist views), but most will subscribe to the “federated” feed. This ‘federation’ of servers means users have two distinct timelines: a local one from users on the same instance and a federated one from users across (what Mastodon calls) ‘the fediverse’.

Users who don’t like the feed they’re getting are free to move to another instance. It’s also possible to join multiple instances with the same user name and email address, a ‘feature’ that has both pros and cons that we’ll discuss below.

How to Join Mastodon

With that in mind, the first thing new users need to do when joining Mastodon is to choose an ‘instance’ to join. Start at the joinmastodon page. Alternatively, if you know the address of the instance you want to join, you can go directly to its home page. For cybersecurity, ioc.exchange and infosec.exchange appear to be the most popular.

Aside from that, it’s the usual sign up and verify routine.

After creating an account, visit the Settings page to configure various preferences, set up 2FA for account security and enable tweetdeck-like panels for viewing multiple columns.

Differences Between Mastodon and Twitter

There’s a familiar Twitter-like feel to Mastodon, but there’s some important differences to be aware of, too.

First, there is no identity verification, meaning anyone can impersonate anyone else. This is compounded by the fact that user names are only unique to an instance, so there could be as many accounts with the same username as there are instances in the entire fediverse. That means it’s both easy to impersonate someone else and difficult to prevent someone impersonating you or a business. “Squatting” names is practically impossible, since anybody could start up their own instance and add it to the fediverse.

Just as with Twitter, users can “like” each other’s posts, but on Mastodon, liking a post does not result in boosting the post so that it is seen by more users. On Mastodon, the ‘boost’ feature serves that purpose and is more akin to Twitter’s “retweet”.

Some other useful features are that each post can be restricted to Mentioned people only, followers only, visible for all but opted-out of discovery features, or public.

Further options include an optional ‘content warning’ and posting only to the local instance.

Those are all plusses, but beware a couple of privacy concerns pointed out by Mike Masnick on Mastodon and re-tweeted by Marcus Hutchins on Twitter: DMs are posts that are set to only be visible to the people messaged. If you mention someone’s full handle in a DM, it adds them to the conversation, just like tagging someone in a tweet does. DMs are also visible to server owners and admins, so don’t assume any kind of privacy here (the same is true of Twitter, of course).

On Mastodon, mentioning someone in a DM adds them to the conversation the same way mentioning them in a thread would. That has got to have led to some awkward experiences ???? pic.twitter.com/nLJVFzFdLe

— malwaretech@infosec.exchange (@MalwareTechBlog) November 7, 2022

Finding Your Twitter Users on Mastodon

For most new users of Mastodon, the tricky part is curating that feed so that you’re getting the content that’s most relevant to you. Joining the right instance helps a lot – remember that the ‘local’ feeds is from those on the same instance, so choosing an instance where a large number of people have the same interests is key. Aside from that, the next most important step is to populate your lists of follows.

For Twitter users that follow a large number of other Twitter accounts, it might seem daunting trying to replicate that on a completely different social media platform. Fortunately, there’s a tool to help with that. Here’s how to use it.

Navigate to fedfinder.glitch.me, and click the “Authorize” button in the “Find fediverse handles of Twitter contacts” box. After authorizing access to your Twitter account, in the next page, click the ‘Scan followings’ and ‘Scan followers’ buttons and wait while the lists are populated.

fedifinder mastodon how to find your twitter users

From this point there are two choices. Option one is to scroll down the list and manually choose which accounts to follow by clicking the button for each account.

fedifinder mastodon how to find your twitter users

Option 2 is the more efficient for anything but a few accounts:  scroll to the bottom of the list and export all the accounts as a .csv file.

To import the list in Mastodon, go to the Settings page and choose ‘Import’ in the sidebar. Click ‘Choose File’ under “Data” and then Upload the .csv file from your local drive.

Top Twitter Cybersecurity Accounts on Mastodon

Another good way to find cybersecurity and infosec accounts on Mastodon is to look at the followers of some of those that you imported from Twitter or those of some of the most popular cybersecurity-related accounts that have already jumped from Twitter.

Unsurprisingly, you’ll find that many of your favorite Infosec Tweeters and re-tweeters are already on Mastodon. Those that have made the jump include many from our list of 22 top Twitter accounts.

Twitter Mastodon
@campuscodi | Catalin Cimpanu mastodon.social/@campuscodi
@gcluley | Graham Cluley mastodon.green/@gcluley
@GossiTheDog | Kevin Beaumont nfosec.exchange/@gossithedog
@hacks4pancakes | Lesley Carhart infosec.exchange/@hacks4pancakes
@hostilespectrum | JD Work infosec.exchange/@hacks4pancakes
@JohnHultquist | John Hultquist infosec.exchange/@Johnhultquist
@juanandres_gs | J. A. Guerrero-Saade infosec.exchange/@jags
@k8em0 | Katie Moussouris infosec.exchange/@k8em0
@KimZetter | Kim Zetter infosec.exchange/@kimzetter
@likethecoins | Katie Nickels infosec.exchange/@likethecoins
@MalwareTechBlog | Marcus Hutchins infosec.exchange/@malwaretech
@malwareunicorn infosec.exchange/@malwareunicorn
@philofishal | Phil Stokes infosec.exchange/@philofishal
@RidT | Thomas Rid infosec.exchange/@ridt
@theJoshMeister | Josh Long infosec.exchange/@theJoshMeister
@TomHegel | Tom Hegel infosec.exchange/@hegel
@mRr3b00t | Daniel Card infosec.exchange/@UK_Daniel_Card
@milenkowski | Aleksandar Milenkowski infosec.exchange/@milenkowski
@DAlperovitch | Dmitri Alperovitch mas.to/@dmitri
@SwiftOnSecurity | SwiftOnSecurity infosec.exchange/@SwiftOnSecurity
@ryanaraine | Ryan Naraine infosec.exchange/@ryanaraine

Conclusion

Whether Mastodon serves to replace or only supplement Twitter, there’s certainly advantages to be had in the platform’s ad-free, decentralized structure, as well as some challenges for both new users and servers. The sudden and extra load over the last few weeks has caused at least one instance to announce it’s shutting its doors, but therein also lies the beauty of the open-source “fediverse” – anyone can set up another server and join the platform, and users can easily migrate their data from one server to another, or occupy multiple servers simultaneously.

Twitter’s recent problems led users to look for an alternative, and Mastodon looks to have answered that call. Whether Twitter will get its house in order and tempt those users back remains to be seen; in the meantime, there’s lots of infosec content to enjoy and explore on Mastodon.

https://phxtechsol.com/wp-content/uploads/2022/11/Cybersecurity-Sharing-An-Infosec-Users-Guide-to-Getting-Started-on-Mastodon-3.jpg 628 1200 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-14 19:55:262022-11-14 19:55:40Cybersecurity Sharing | An Infosec User’s Guide to Getting Started on Mastodon

The Good, the Bad and the Ugly in Cybersecurity – Week 46

November 11, 2022/0 Comments/in Blog/by Phoenix Technology

The Good

A two-year FBI investigation into LockBit ransomware has led to charges this week against a dual Russian-Canadian citizen for allegedly conducting ransomware attacks on U.S. and other organizations around the world.

Mikhail Vasiliev, 33, was arrested in Ontario, Canada on Wednesday on charges of conspiring to damage protected computers and transmitting ransom demands in connection with doing so. He is now awaiting extradition to the U.S.

Documents filed in the case state that since the LockBit RaaS (ransomware-as-a-service) first appeared in 2020, it has been used in over 1000 attacks and garnered its operators tens of millions of dollars in confirmed ransom payments. However, Deputy AG Lisa Monaco had a message for those involved: “Let this be yet another warning to ransomware actors…we will use every available tool to disrupt, deter and punish cyber criminals.”

LockBit 3 ransomware leaks site
 

It’s also not the first time Canadian police and the FBI have cooperated to arrest individuals believed to be involved in ransomware: Back in 2021, Canadian national Sébastien Vachon-Desjardins was arrested in Canada and subsequently sentenced to 20 years in a U.S. prison for his role in Netwalker ransomware attacks.

The Bad

Despite wins like those above, it’s clear that the profits from ransomware and data extortion as well as the ease of conducting such attacks continue to incentivise threat actors. This week, the Health Sector Cybersecurity Coordination Center (HC3) warned that Venus ransomware is targeting U.S. healthcare entities via publicly exposed Remote Desktop Services.

HC3 says that Venus ransomware is targeting Windows devices that companies have failed to protect with a firewall or other defenses, allowing attackers to gain initial access via the Remote Desktop Service. Typically, threat actors discover vulnerable services through internet search services such as Shodan or purchase access from Initial Access Brokers.

Reports suggest that Venus ransomware is likely being operated by several independent cybercrime groups. HC3 says that the malware has been observed reaching out to IP addresses in a wide variety of countries, including Denmark, France, Great Britain, Ireland, Japan, the Netherlands, Russia and the United States.

At present, there are no data leak sites associated with Venus intrusions, and the operators appear to be relying solely on file locking to extort money from victims. Ransom demands are said to start at around $20,000. Victims are reminded that paying a ransom by no means ensures either that encrypted data will be unlocked or that the organization will not suffer further harm.

The Ugly

In cybersecurity, trust is always a weak point that attackers will seek to abuse, and this week’s Most Odious award goes to the threat actors behind the latest attempts to infect users of open source projects hosted on PyPI and GitHub.

Researchers this week spotted a malicious package on PyPI called “ApiColor” that reached out to a remote URL to download and execute code hidden in a .png file. The ApiColor package installed a steganography module and retrieved and executed a further second-stage malware payload.

The threat actors had set up multiple accounts on GitHub with code repositories that included the malicious PyPI package in their dependencies, hoping to infect developers or organizations that used the open source GitHub repositories. The PyPI package has since been taken down, but malware linked to some of the fake users accounts remains on GitHub at the time of writing.

Supply chain attacks on PyPI and Rust’s crate.io are not unknown, and seeding malicious code via GitHub repositories to infect developers and ultimately downstream users has also been seen before (e.g., in XCSSET malware). Steganography is also a common tactic for hiding malware.

However, what makes this attack of particular concern is precisely that the vectors and TTPs are neither novel nor sophisticated, and yet the attackers invested a considerable amount of time and effort setting up an elaborate infrastructure in the knowledge that trust in external code dependencies is still a blind spot for many organizations. The warning shots have been fired, and security teams need to be sure that they are on top of the supply chain risk across their software stack.

https://phxtechsol.com/wp-content/uploads/2022/11/lockbit_3_update_7.jpg 629 1071 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-11 19:23:312022-11-11 19:23:36The Good, the Bad and the Ugly in Cybersecurity – Week 46

Lawsuit Seeks Food Benefits Stolen By Skimmers

November 10, 2022/0 Comments/in Blog/by Phoenix Technology

A nonprofit organization is suing the state of Massachusetts on behalf of thousands of low-income families who were collectively robbed of more than a $1 million in food assistance benefits by card skimming devices secretly installed at cash machines and grocery store checkout lanes across the state. Federal law bars states from replacing these benefits using federal funds, and a recent rash of skimming incidents nationwide has disproportionately affected those receiving food assistance via state-issued prepaid debit cards.

The Massachusetts SNAP benefits card looks more like a library card than a payment card.

On Nov. 4, The Massachusetts Law Reform Institute (MLRI) filed a class action lawsuit on behalf of low-income families whose Supplemental Nutrition and Assistance Program (SNAP) benefits were stolen from their accounts. The SNAP program serves over a million people in Massachusetts, and 41 million people nationally.

“Over the past few months, thieves have stolen over a million SNAP dollars from thousands of Massachusetts families – putting their nutrition and economic stability at risk,” the MLRI said in a statement on the lawsuit. “The criminals attach a skimming device on a POS (point of sale) terminal to capture the household’s account information and PIN. The criminals then use that information to make a fake card and steal the SNAP benefits.”

In announcing the lawsuit, the MRLI linked to a story KrebsOnSecurity published last month that examined how skimming thieves increasingly are targeting SNAP payment card holders nationwide. The story looked at how the vast majority of SNAP benefit cards issued by the states do not include the latest chip technology that makes it more difficult and expensive for thieves to clone them.

The story also highlighted how SNAP cardholders usually have little recourse to recover any stolen funds — even in unlikely cases where the victim has gathered mountains of proof to show state and federal officials that the fraudulent withdrawals were not theirs.

Deborah Harris is a staff attorney at the MLRI. Harris said the goal of the lawsuit is to force Massachusetts to reimburse SNAP skimming victims using state funds, and to convince The U.S. Department of Agriculture (USDA) — which funds the program that states draw from — to change its policies and allow states to replace stolen benefits with federal funds.

“Ultimately we think it’s the USDA that needs to step up and tell states they have a duty to restore the stolen benefits, and that USDA will cover the cost at least until there is better security in place, such as chip cards,” Harris told KrebsOnSecurity.

“The losses we’re talking about are relatively small in the scheme of total SNAP expenditures which are billions,” she said. “But if you are a family that can’t pay for food because you suddenly don’t have money in your account, it’s devastating for the family.”

The USDA has not said it will help states restore the stolen funds. But on Oct. 31, 2022, the agency released guidance (PDF) whose primary instructions were included in an appendix titled, Card Security Options Available to Households. Notably, the USDA did not mention the idea of shifting to chip-based SNAP benefits cards.

The recently issued USDA guidance.

“The guidance generally continues to make households responsible for preventing the theft of their benefits as well as for suffering the loss when benefits are stolen through no fault of the household,” Harris said. “Many of the recommendations are not practical for households who don’t have a smartphone to receive text messages and aren’t able to change their PIN after each transaction and keep track of the new PIN.”

Harris said three of the four recommendations are not currently available in Massachusetts, and they are very likely not currently available in other states. For example, she said, Massachusetts households do not have the option of freezing or locking their cards between transactions. Nor do they receive alerts about transactions. And they most certainly don’t have any way to block out-of-state transactions.

“Perhaps these are options that [card] processors and states could provide, but they are not available now as far as we know,” Harris said. “Most likely they would take time to implement.”

The Center for Law and Social Policy (CLASP) recently published Five Ways State Agencies Can Support EBT Users at Risk of Skimming. CLASP says while it is true states can’t use federal funds to replace benefits unless the loss was due to a “system error,” states could use their own funds.

“Doing so will ensure families don’t have to go without food, gas money, or their rent for the month,” CLASP wrote.

That would help address the symptoms of card skimming, but not a root cause. Hardly anyone is suggesting the obvious, which is to equip SNAP benefit cards with the same security technology afforded to practically everyone else participating in the U.S. banking system.

There are several reasons most state-issued SNAP benefit cards do not include chips. For starters, nobody says they have to. Also, it’s a fair bit more expensive to produce chip cards versus plain old magnetic stripe cards, and many state assistance programs are chronically under-funded. Finally, there is no vocal (or at least well-heeled) constituency advocating for change.

A copy of the class action complaint filed by the MLRI is available here.

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-10 18:58:342022-11-10 18:58:39Lawsuit Seeks Food Benefits Stolen By Skimmers

MITRE Managed Services Evaluation | 4 Key Takeaways for MDR & DFIR Buyers

November 9, 2022/0 Comments/in Blog/by Phoenix Technology

As the cyber threat landscape grows increasingly treacherous and sophisticated, more teams are looking to augment their often-limited internal cybersecurity resources with the expertise and hands-on assistance offered by managed detection and response (MDR) services and managed security service providers (MSSPs). Gartner estimates that by 2025, 50% of organizations using endpoint detection and response (EDR) technology will enlist the help of a managed security service partner.

About the MITRE Engenuity ATT&CK® Evaluation of Managed Security Services

In response to the growing needs of today’s cybersecurity teams and buyers, MITRE Engenuity has just published its debut ATT&CK Evaluation of Managed Security Services. MITRE Engenuity has quickly evolved to become the industry standard for third party evaluation of cybersecurity solutions. The independent evaluations provide rigorous analysis based on the ATT&CK® framework and knowledge base with the intent to help organizations combat today’s sophisticated cyber threats and improve their threat detection capabilities.

SentinelOne has participated in more comprehensive MITRE evaluations than any other cybersecurity leader, being the only XDR vendor to have participated in three years of ATT&CK Enterprise Evaluations, the inaugural Deception evaluation, and the inaugural Managed Services evaluation. Learn more about SentinelOne’s leading performance in MITRE Engenuity’s Enterprise ATT&CK and Deception evaluations here.

MITRE summarizes its newest Managed Services evaluation below:

ATT&CK Evaluations for Managed Services will assess vendor participant capabilities in their ability to analyze and describe adversary behavior. Adversary activity emulated by the MITRE Engenuity red team, and correlating context provided by the participants will be mapped to the MITRE ATT&CK knowledge base.

As part of the evaluation process, participants like SentinelOne were tasked with understanding adversary activity without prior knowledge of the emulated adversary, and provide their analysis as if MITRE Engenuity was a standard MDR customer.

In this blog post, we’ll outline the key takeaways from our Vigilance MDR team’s participation in the inaugural MITRE Engenuity ATT&CK Evaluation for Managed Services. These takeaways are especially relevant for those considering or actively evaluating MDR and digital forensics & incident response (DFIR) services.


 

Takeaway 1: The Right Data Leads to the Right Decisions

While identifying the emulated adversary in this scenario seems like table stakes, proper adversary attribution unlocks actionability.

Based on the activity detected on this user endpoint, forensic artifacts collected, and the tactics, techniques, and procedures (TTPs) observed throughout the campaign, the SentinelOne Vigilance team was able to correctly attribute the attack to Iranian threat actor group APT 34, also known as OilRig.

Beyond just identifying the emulated adversary, the Vigilance team leveraged first party and open threat intelligence to provide additional insight into OilRig. The team’s reporting included a summary of the adversary and the group’s evolution over time, commonly exploited tools by the adversary, and all of their known associated TTPs.

As an MDR & DFIR buyer, it is important to consider whether the information you receive from your service partner is meaningful and actionable. While comprehensive reporting is a must, time and resource-constrained analysts benefit from analysis that is pertinent, timely, and distinguishes between insight and overwhelming detail.

In addition to the remediation guidance offered in-platform, Vigilance reporting focuses on what customers need to know to evaluate risk, assess incident impact, and mitigate threats for the immediate and long term.

Takeaway 2: Detection Is Half the Battle, Protection Is the Endgame

For the purposes of the evaluation, participants were tasked with detecting and understanding adversary activity through the entire attack, without intervening to prevent or remediate the threat. Over a 10-step campaign, our Vigilance team was able to track the adversary from end to end as they infiltrated the simulated environment through a phishing attack with a malicious attachment, performed reconnaissance on the host and environment, moved laterally to a critical server, and exfiltrated corporate data.

It is crucial to note, however, that a real-life application of detection and response technology and MDR services should be aimed at preventing and mitigating such attacks as quickly as possible—before the adversary can perform recon, move laterally, or steal data.

In a live scenario of this incident, the SentinelOne Singularity platform and Vigilance services would have stopped the attack from the very first detection. If set to “Protect” mode rather than “Detect-Only”, the Sentinel Agent would be equipped to autonomously kill the entire chain in an instant, without analyst intervention, rather than allowing the attack to execute over the course of several days. This would have prevented any further movement or downstream business impacts associated with this campaign.

Takeaway 3: Real-Time Response Maximizes Cyber Resilience

Time is of the essence in a real-world attack scenario. By a similar principle as our last takeaway, organizations should aim to eradicate malicious actors from their environment as soon as they’re detected, and have the confidence in their MDR partner to do just that.

Though the ATT&CK evaluation did not include a service level agreement (SLA) as part of its criteria, this should be a significant consideration for those evaluating MDR and DFIR services. The true efficacy of an MDR team often comes down to their ability to detect, contain, and mitigate a threat as quickly and effectively as possible, all with the goal of minimizing the impact of a cyber incident.

At SentinelOne, our Vigilance analysts are able to respond to events at often unmatched speeds. This is due in part to the robust autonomous capabilities of the Sentinel Agent, which can kill and quarantine threats at the endpoint level before a human ever intervenes. Additionally, Vigilance analysts take action on alerts that come with real-time, machine-generated context produced by SentinelOne’s patented Storyline™ technology. This allows an analyst to view and understand the entire progression of an attack in one pane of glass, instantly. On average, Vigilance minimizes attacker dwell time to just 20 minutes.

For many other MDR and MSSP-delivered services, the process of connecting the dots, building context, validating true vs. false positives, and containing threats is often a heavily manual effort, which may lead to longer overall response times.

Takeaway 4: There is More to MDR — DFIR Is the Difference

Although the 24×7 security monitoring offered by MDR services provides organizations with a reliable safety blanket, the reality of today’s digital world is that no organization is 100% impenetrable to a cyber incident. This is why more and more teams look to augment their security programs with digital forensics and incident response, or DFIR, capabilities.

The evaluation factored in security teams’ growing desire for deeper analysis and forensic investigation, and how this level of insight could enhance an end client’s overall understanding of attacks targeting their organization. In this spirit, the Vigilance team not only reported on “what” the adversary was doing in the simulated environment, but also the “how” and “why” — this included malware and data exfiltration technique analysis, as well as reverse engineering of malware samples.

These capabilities are at the crux of SentinelOne’s Vigilance Respond Pro offering. Through Vigilance Respond Pro, we are able to deliver our customers a more frictionless MDR and DFIR experience, drawing from the expertise of a unified, designated team with intimate knowledge of the customer environment.

When a DFIR team already has a pulse on what’s happening in the customer environment, is able to leverage their existing tools, and directly interfaces with their day-to-day MDR team, it significantly accelerates overall investigation and response. MDR and DFIR buyers should consider this approach in contrast to enlisting the help of two disparate, siloed teams under one vendor, or two separate firms for MDR and DFIR altogether.

Looking Ahead: Next Steps for MDR and DFIR Buyers

From the MITRE Engenuity ATT&CK Evaluation for Managed Services emerged some key considerations for those evaluating MDR and DFIR services. However, it is important for teams to consider their cybersecurity partners holistically, from the breadth, depth, and reliability of their technology to the expertise and level of service delivered by their people.

We encourage buyers to continue to lean on third party evaluations such as MITRE Engenuity to assess the best fit for their organizations, including their track record of performance across various domains such as Enterprise EDR & XDR, Identity & Deception, and Managed Services.

Dive deeper into SentinelOne’s leading performance over three years of MITRE Engenuity ATT&CK evaluations here. To join the ranks of other customers who have gained peace of mind and made security progress with SentinelOne Vigilance MDR and DFIR, learn more about our Vigilance Respond Pro.

Webinar | MITRE Engenuity ATT&CK: A Guide to Evaluating MDR Success
Tuesday, November 15 at 10:00 am (PST) / 1 pm (EST)

Register Now

https://phxtechsol.com/wp-content/uploads/2022/11/MITRE-Managed-Services-Evaluation-4-Key-Takeaways-for-MDR-DFIR-Buyers-2-1.jpg 628 1200 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-09 19:03:432022-11-09 19:03:45MITRE Managed Services Evaluation | 4 Key Takeaways for MDR & DFIR Buyers

Patch Tuesday, November 2022 Election Edition

November 9, 2022/0 Comments/in Blog/by Phoenix Technology

Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.

Probably the scariest of the zero-day flaws is CVE-2022-41128, a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the weakness. Microsoft credits Google with reporting the vulnerability, which earned a CVSS score of 8.8.

CVE-2022-41073 is a zero-day flaw in the Windows Print Spooler, a Windows component that Microsoft has patched mightily over the past year. Kevin Breen, director of cyber threat research at Immersive Labs, noted that the print spooler has been a popular target for vulnerabilities in the last 12 months, with this marking the 9th patch.

The third zero-day Microsoft patched this month is CVE-2022-41125, which is an “elevation of privilege” vulnerability in the Windows Cryptography API: Next Generation (CNG) Key Isolation Service, a service for isolating private keys. Satnam Narang, senior staff research engineer at Tenable, said exploitation of this vulnerability could grant an attacker SYSTEM privileges.

The fourth zero-day, CVE-2022-41091, was previously disclosed and widely reported on in October. It is a Security Feature Bypass of “Windows Mark of the Web” – a mechanism meant to flag files that have come from an untrusted source.

The other two zero-day bugs Microsoft patched this month were for vulnerabilities being exploited in Exchange Server. News that these two Exchange flaws were being exploited in the wild surfaced in late September 2022, and many were surprised when Microsoft let October’s Patch Tuesday sail by without issuing official patches for them (the company instead issued mitigation instructions that it was forced to revise multiple times). Today’s patch batch addresses both issues.

Greg Wiseman, product manager at Rapid7, said the Exchange flaw CVE-2022-41040 is a “critical” elevation of privilege vulnerability, and CVE-2022-41082 is considered Important, allowing Remote Code Execution (RCE) when PowerShell is accessible to the attacker.

“Both vulnerabilities have been exploited in the wild,” Wiseman said. “Four other CVEs affecting Exchange Server have also been addressed this month. Three are rated as Important, and CVE-2022-41080 is another privilege escalation vulnerability considered Critical. Customers are advised to update their Exchange Server systems immediately, regardless of whether any previously recommended mitigation steps have been applied. The mitigation rules are no longer recommended once systems have been patched.”

Adobe usually issues security updates for its products on Patch Tuesday, but it did not this month. For a closer look at the patches released by Microsoft today and indexed by severity and other metrics, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com usually has the lowdown on any patches that may be causing problems for Windows users.

As always, please consider backing up your system or at least your important documents and data before applying system updates. And if you run into any problems with these updates, please drop a note about it here in the comments.

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-09 18:49:202022-11-09 18:49:23Patch Tuesday, November 2022 Election Edition

The Good, the Bad and the Ugly in Cybersecurity – Week 45

November 4, 2022/0 Comments/in Blog/by Phoenix Technology

The Good

Software supply chain attacks aren’t just creeping into the threat landscape anymore – they have been fully on the rise over recent years. After multiple high-profile attacks, including those on SolarWinds and Kaseya, nation states and organizations alike have all worked to share lessons learned and raise their awareness on supply chain attacks.

This week, the NSA, CISA, and the Office of the Director of National Intelligence (ODNI) released a new set of guidelines for securing software supply chain operations. The guidelines were created in coordination with public-private cross-sector, Enduring Security Framework (ESF), to provide suppliers with best practices for planning, prevention, and response processes.

While the document lays out comprehensive instructions to help suppliers define criteria for security checks and respond to vulnerabilities, it more importantly articulates the notion of establishing shared responsibility.

“Prevention is often seen as the responsibility of the software developer, as they are required to securely develop and deliver code, verify third party components, and harden the build environment. But the supplier also holds a critical responsibility in ensuring the security and integrity of our software,” the NSA noted in their press release.

Software supply chain attacks have remained at the forefront of discussion by U.S. officials with a new federal strategy to adopt a zero-trust model announced in January of this year followed in May by NIST Special Publication 800-191 addressing supply chain risk management. The ESF is set to release another set of guidelines, focusing next on customers in the software supply chain lifecycle. This week’s release is preceded by the first in the series, a guideline created to support developers specifically.

The Bad

Popular file-hosting service, Dropbox, disclosed this week that they suffered a breach after a phishing campaign targeted employees. In their blog post, the California-based company explained that attackers accessed 130 of their code repositories in GitHub, but the breach did not include unauthorized access to user accounts, content, passwords, or payment information. Code for its core apps and infrastructure were also not contained in the compromised repositories.

This phishing campaign on Dropbox shares its roots with a campaign that targeted GitHub just a few months ago. In both cases, the threat actor impersonated CircleCI, a continuous integration software, to harvest user credentials and MFA codes. Attackers were able to breach Dropbox’s defenses by using legitimate-looking phishing emails that directed employees to enter their credentials and hardware authentication key to pass a one-time password (OTP) to a fake CircleCI site.

Dropbox revealed that the code accessed by the threat actor contained some credentials, mainly API keys used by the company’s developers, and also “a few thousand names and email addresses” belonging to employees, sales leads, third-party vendors, as well as current and past customers.

Though the company has underscored that no customer data was stolen, the need for large companies to harden their authentication protocols is clear. In this case, over 700 million registered users rely on Dropbox for folder sharing, cloud storage, file backup, task management, and document signing services.

Identity-based protection has long needed more attention with even the U.S. government mandating this year that all federal agencies are to implement both zero-trust architecture and phishing-resistant MFA. Dropbox’s blog confirmed that the company has accelerated an upgrade to their authentication tools and will soon use biometric factors or hardware tokens across its environment.

The Ugly

The RomCom RAT has come out to play again, and this time it’s using rogue versions of SolarWinds Network Performance Monitor (NPM), KeePass password manager, and PDF Reader Pro. RomCom also has been known to use trojanized variants of Advanced IP Scanner and pdfFiller.

Researchers found RomCom actors leveraging customer trust in well-known software brands to create typo-squat lookalike download sites, effectively disguising their malware as legitimate products. This is done by scraping the HTML code from the company’s legitimate site, registering a new, similar domain, and deploying targeted phishing emails or social media posts to lure in specific users.

The spoofed websites host and deploy the RomCom RAT (remote access trojan), which is capable of taking screenshots and collecting sensitive information, before exporting them back to the threat actor’s server.

RomCom seems to be expanding on this tactic now that fake Veeam Backup Recovery installers have been identified, too.

We’re observing that ROMCOM RAT is now being packaged as an installer for Veeam Backup and Recovery software. This is in addition to the KeePass Password Manager and SolarWinds Orion installers identified by BlackBerry yesterday. pic.twitter.com/CHF1B9gB2M

— Unit 42 (@Unit42_Intel) November 3, 2022

Ukrainian military institutions have been the primary targets of this recent campaign though secondary targets included some English-speaking countries. Researchers commented that “given the geography of the targets and the current geopolitical situation, it’s unlikely that the RomCom RAT threat actor is cybercrime-motivated.”

Campaigns like these are part of the reason why the lines separating cybercriminals and targeted attack threat actors are blurring. The more targeted attack actors use traditional means of tooling, the harder attribution is.

For now, there are speculations that RomCom actors are potentially linked to Cuba Ransomware and Industrial Spy, but concrete evidence has yet to be found. The FBI continues to encourage organizations to bolster their defenses against spoofing, social engineering scams, and business email compromise and to report any suspected attempts to the Internet Crime Complaint Center.

https://phxtechsol.com/wp-content/uploads/2022/11/GBU-Wk-45_chain.jpg 1339 1999 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-04 18:15:442022-11-04 18:15:50The Good, the Bad and the Ugly in Cybersecurity – Week 45

LinkedIn Adds Verified Emails, Profile Creation Dates

November 4, 2022/0 Comments/in Blog/by Phoenix Technology

Responding to a recent surge in AI-generated bot accounts, LinkedIn is rolling out new features that it hopes will help users make more informed decisions about with whom they choose to connect. Many LinkedIn profiles now display a creation date, and the company is expanding its domain validation offering, which allows users to publicly confirm that they can reply to emails at the domain of their stated current employer.

LinkedIn’s new “About This Profile” section — which is visible by clicking the “More” button at the top of a profile — includes the year the account was created, the last time the profile information was updated, and an indication of how and whether an account has been verified.

LinkedIn also said it is adding a warning to some LinkedIn messages that include high-risk content, or that try to entice the user into taking the conversation to another platform (like WeChat).

“We may warn you about messages that ask you to take the conversation to another platform because that can be a sign of a scam,” the company said in a blog post. “These warnings will also give you the choice to report the content without letting the sender know.”

In late September 2022, KrebsOnSecurity warned about the proliferation of fake LinkedIn profiles for Chief Information Security Officer (CISO) roles at some of the world’s largest corporations. A follow-up story on Oct. 5 showed how the phony profile problem has affected virtually all executive roles at corporations, and how these fake profiles are creating an identity crisis for the businesses networking site and the companies that rely on it to hire and screen prospective employees.

Reporting here last month also tracked a massive drop in profiles claiming to work at several major technology companies, as LinkedIn apparently took action against hundreds of thousands of inauthentic accounts that falsely claimed roles at these companies.

For example, on October 10, 2022, there were 576,562 LinkedIn accounts that listed their current employer as Apple Inc. The next day, half of those profiles no longer existed. At around the same time, the number of LinkedIn profiles claiming current roles at Amazon fell from roughly 1.25 million to 838,601 in just one day, a 33 percent drop.

For whatever reason, the majority of the phony LinkedIn profiles reviewed by this author were young women with profile photos that appear to have been generated by artificial intelligence (AI) tools.

“We’re seeing rapid advances in AI-based synthetic image generation technology and we’ve created a deep learning model to better catch profiles made with this technology,” LinkedIn’s Oscar Rodriguez wrote. “AI-based image generators can create an unlimited number of unique, high-quality profile photos that do not correspond to real people.”

It remains unclear who or what is behind the recent proliferation of fake executive profiles on LinkedIn, but likely they are from a combination of scams. Cybersecurity firm Mandiant (recently acquired by Google) told Bloomberg that hackers working for the North Korean government have been copying resumes and profiles from leading job listing platforms LinkedIn and Indeed, as part of an elaborate scheme to land jobs at cryptocurrency firms.

Identity thieves have been known to masquerade on LinkedIn as job recruiters, collecting personal and financial information from people who fall for employment scams.

Also, fake profiles also may be tied to so-called “pig butchering” scams, wherein people are lured by flirtatious strangers online into investing in cryptocurrency trading platforms that eventually seize any funds when victims try to cash out.

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-04 17:58:432022-11-04 17:58:47LinkedIn Adds Verified Emails, Profile Creation Dates

Hacker Charged With Extorting Online Psychotherapy Service

November 3, 2022/0 Comments/in Blog/by Phoenix Technology

A 25-year-old Finnish man has been charged with extorting a once popular and now-bankrupt online psychotherapy company and its patients. Finnish authorities rarely name suspects in an investigation, but they were willing to make an exception for Julius “Zeekill” Kivimaki, a notorious hacker who — at the tender age of 17 — had been convicted of more than 50,000 cybercrimes, including data breaches, payment fraud, operating botnets, and calling in bomb threats.

In late October 2022, Kivimaki was charged (and arrested in absentia, according to the Finns) with attempting to extort money from the Vastaamo Psychotherapy Center.  On October 21, 2020, Vastaamo became the target of blackmail when a tormentor identified as “ransom_man” demanded payment of 40 bitcoins (~450,000 euros at the time) in return for a promise not to publish highly sensitive therapy session notes Vastaamo had exposed online.

In a series of posts over the ensuing days on a Finnish-language dark net discussion board, ransom_man said Vastaamo appeared unwilling to negotiate a payment, and that he would start publishing 100 patient profiles every 24 hours “to provide further incentive for the company to continue communicating with us.”

“We’re not asking for much, approximately 450,000 euros which is less than 10 euros per patient and only a small fraction of the around 20 million yearly revenues of this company,” ransom_man wrote.

When Vastaamo declined to pay, ransom_man shifted to extorting individual patients. According to Finnish police, some 22,000 victims reported extortion attempts targeting them personally, targeted emails that threatened to publish their therapy notes online unless paid a 500 euro ransom.

The extortion message targeted Vastaamo patients.

On Oct. 23, 2020, ransom_man uploaded to the dark web a large compressed file that included all of the stolen Vastaamo patient records. But investigators found the file also contained an entire copy of ransom_man’s home folder, a likely mistake that exposed a number of clues that they say point to Kivimaki.

Ransom_man quickly deleted the large file (accompanied by a “whoops” notation), but not before it had been downloaded a number of times. The entire archive has since been made into a searchable website on the Dark Web.

Among those who grabbed a copy of the database was Antti Kurittu, a team lead at Nixu Corporation and a former criminal investigator. In 2013, Kurittu worked on investigation involving Kivimaki’s use of the Zbot botnet, among other activities Kivimaki engaged in as a member of the hacker group Hack the Planet.

“It was a huge opsec [operational security] fail, because they had a lot of stuff in there — including the user’s private SSH folder, and a lot of known hosts that we could take a very good look at,” Kurittu told KrebsOnSecurity, declining to discuss specifics of the evidence investigators seized. “There were also other projects and databases.”

Kurittu said he and others he and others who were familiar with illegal activities that were attributed to Kivimäki couldn’t shake suspicion

he and others who were familiar with illegal activites that were attributed to Kivimäki couldn’t shake suspicion that the infamous cybercriminal was also behind the Vastaamo extortion.

“I couldn’t find anything that would link that data directly to one individual, but there were enough indicators in there that put the name in my head and I couldn’t shake it,” Kurittu said. “When they named him as the prime suspect I was not surprised.”

A handful of individually extorted victims paid a ransom, but when news broke that the entire Vastaamo database had been leaked online, the extortion threats no longer held their sting. However, someone would soon set up a site on the dark web where anyone could search this sensitive data.

Kivimaki stopped using his middle name Julius in favor of his given first name Aleksanteri when he moved abroad several years ago. A Twitter account by that name was verified by Kivimaki’s attorney as his, and through that account he denied being involved in the Vastaamo extortion.

“I believe [the Finnish authorities] brought this to the public in order to influence the decision-making of my old case from my teenage years, which was just processed in the Court of Appeal, both cases are investigated by the same persons,” Kivimaki tweeted on Oct. 28.

Kivimaki is appealing a 2020 district court decision sentencing him to “one year of conditional imprisonment for two counts of fraud committed as a young person, and one of gross fraud, interference with telecommunications as a young person, aggravated data breach as a young person and incitement to fraud as a young person,” according to the Finnish tabloid Ilta-Sanomat.

“Now in the Court of Appeal, the prosecutor is demanding a harsher punishment for the man, i.e. unconditional imprisonment,” reads the Ilta-Sanomat story. “The prosecutor notes in his complaint that the young man has been committing cybercrimes from Espoo since he was 15 years old, and the actions have had to be painstakingly investigated through international legal aid.”

As described in this Wired story last year, Vastaamo filled an urgent demand for psychological counseling, and it won accolades from Finnish health authorities and others for its services.

“Vastaamo was a private company, but it seemed to operate in the same spirit of tech-enabled ease and accessibility: You booked a therapist with a few clicks, wait times were tolerable, and Finland’s Social Insurance Institution reimbursed a big chunk of the session fee (provided you had a diagnosed mental disorder),” William Ralston wrote for Wired. “The company was run by Ville Tapio, a 39-year-old coder and entrepreneur with sharp eyebrows, slicked-back brown hair, and a heavy jawline. He’d cofounded the company with his parents. They pitched ­Vastaamo as a humble family-run enterprise committed to improving the mental health of all Finns.”

But for all the good it brought, the healthcare records management system that Vastaamo used relied on little more than a MySQL database that was left dangerously exposed to the web for 16 months, guarded by nothing more than an administrator account with a blank password.

The Finnish daily Iltalehti said Tapio was relieved of his duties as CEO of Vastaamo in October 2020, and that in September, prosecutors brought charges against Tapio for a data protection offense in connection with Vastaamo’s information leak.

“According to Vastaamo, the data breach in Vastaamo’s customer databases took place in November 2018,” Iltalehti reported last month. “According to Vastaamo, Tapio concealed information about the data breach for more than a year and a half.”

https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg 0 0 Phoenix Technology https://phxtechsol.com/wp-content/uploads/2017/02/PTS-Horiz-logo-1-1200-300x53.jpg Phoenix Technology2022-11-03 17:49:152022-11-03 17:49:49Hacker Charged With Extorting Online Psychotherapy Service
Page 2 of 3123

Archive

  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019

Categories

  • Blog
  • Uncategorized

Facebook

Contact Info

2415 E Camelback Rd
Suite 700, PMB 7019
Phoenix, AZ 85016

602-461-7219

Recent Posts

  • How SentinelOne Delivers Results, Not Noise | MITRE Managed Services Engenuity ATT&CK® Evaluations
  • PinnacleOne ExecBrief | Deep Tech In The Crosshairs
  • Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested
© Copyright 2025 - Phoenix Technology Solutions LLC
  • Link to Facebook
  • Link to X
  • Link to LinkedIn
  • Link to Rss this site
  • Privacy Policy
  • Terms And Conditions
  • Disclaimer
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

OKLearn more

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Google Analytics Cookies

These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.

If you do not want that we track your visit to our site you can disable tracking in your browser here:

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Other cookies

The following cookies are also needed - You can choose if you want to allow them:

Accept settingsHide notification only