Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts
Thursday, June 2, 2016
New Studies of Russian Ransomware: How Much Users Pay and How Much Money They Make
This morning, deep and dark web intelligence firm Flashpoint released the findings from a five month study of an organized Russian ransomware campaign.
The new research reports, titled Inside an Organized Russian Ransomware Campaign and Hacking Healthcare, detail the pay out schemes and how cybercriminals are using Ransomware as a Service (RaaS) to successfully target victims, with the healthcare industry being identified as a priority target.
The reports detail ransomware campaign key metrics, including average salaries for various members of ransomware schemes, ransom amounts per US victim, and average monthly ransom payments as well as some of the latest healthcare-focused attacks and the response in underground forums.
The reports can be found at Ransomware as a Service and Hacking Healthcare.
Monday, November 16, 2015
6 CyberHacks That Will Affect Your Life in 2016
6 CyberHacks That Will Affect Your Life in 2016
As we are quickly marching toward the end of another year, Stephen Newman, CTO of Damballa, discusses the new types of cyber attacks that will likely see in 2016. He points out that these new types of attacks will draw everyone's attention to the lack of privacy and security in our interconnected world.
As we are quickly marching toward the end of another year, Stephen Newman, CTO of Damballa, discusses the new types of cyber attacks that will likely see in 2016. He points out that these new types of attacks will draw everyone's attention to the lack of privacy and security in our interconnected world.
Monday, March 9, 2015
Smart Cities Need Smart Vaccine against Cyber Attacks
A Smart Vaccine approach is needed to protect the Middle East's smart cities, says security expert Dr. Rocky Termanini. It applies, of course, to other regions, too.
Dr. Termanini is the auther of The Cognitive Early Warning Predictive System Using the Smart Vaccine, to be published by CRC Press in November 2015.
Dr. Termanini is the auther of The Cognitive Early Warning Predictive System Using the Smart Vaccine, to be published by CRC Press in November 2015.
Tuesday, February 10, 2015
New Ransomware Strain Encrypts Files from Memory
Tampa Bay, FL (February 10, 2015) -- KnowBe4 CEO Stu
Sjouwerman issued an alert to security professionals today about a newly
discovered piece of ransomware dubbed ”Fessleak” by security firm Invincea. The
ransomware is Russian and delivers its malicious code straight into system
memory and does not drop any files on a disk. That means almost all antivirus
software is unable to catch this. The infection vector is malicious ads on
popular websites that the cybercriminals are able to display by bidding on the
ad space through legit ad networks.
"This particular strain is new and quite harmful as
it takes advantage of file-less infections that can communicate through the TOR
network," said Sjouwerman. "We are going to continue to see more and
more ransomware this year and this is just the latest innovation.”
This strain can check to ensure the host is not running
on a virtual machine to frustrate security researchers and analysts. For
end-users, they might visit a major site on their lunch break like
HuffingtonPost, Photobucket, CBSsports, or Match.com and check out someone's
"Granny opening a new iPhone video", or "These are the Charlie
Hebdo cartoons that terrorists thought were worth killing over" headlines.
Clicking that one link is enough to get confronted with a full screen
announcing all personal or business files, photos and videos have been one-way
encrypted and to get them back you need to pay a ransom in Bitcoin.
The cybercriminals first set up a short-lived burner
domain directing to a landing page where the exploit kit is hosted. Then they
start real-time bidding for ads pointing to the burner domain. Once their bad
ad is displayed on a popular website and users clicked on it, they would be
redirected to the malicious domain which in turn infects their workstation.
The same gang is also using 0-day exploits for Flash
Player, and is apparently able to change their malware on the fly to exploit
the most recent vulnerabilities. Fessleak drops a temp file via Flash and makes
calls to icacls.exe, the file that sets permissions on folders and files. At
this time, there is no detection for the malicious binary, which likely rotates
its hash value to avoid Antivirus detection.
Sjouwerman makes a few recommendations to mitigate this
type of attack:
1) Backup, backup, backup and take a weekly copy of your
backup off-site.
2) Keep your attack surface as small as possible and
religiously patch the OS and third party apps as soon as possible. Visit http://www.Secunia.com site for some
additional help.
3) Run a UTM or a good Proxy, block centrally rather
than machine by machine. If that's not possible, install AdBlocker plugins for
each browser.
4) It is increasingly clear that effective security
awareness training is a must these days. Once a year training for compliance
does not cut it anymore. End-users need to be on their toes with security top
of mind.
Friday, October 31, 2014
Cybersecurity Nightmares
It's Halloween, and it's not just trick-and-treaters that scare us, or TK Keanini. Keanini, Chief Technology Officer at Lancope, has compiled a number of short and horrifying cybersecurity scenarios entitled "Welcome to My Cyber Security Nightmare."
Welcome to My Cybersecurity Nightmare
This past year, we have seen some pretty scary stuff happen in cybersecurity. Being that Halloween is almost here; I thought I would share with you some scenarios that keep me up at night. These are scenarios that we are not ready to battle, and that are well beyond the horrific headlines we read on a daily basis. If you enjoy a good scare, read on.
User Participation in Cyber-Attacks
Most of the resources cybercriminals use to carry out their objectives are acquired through some method that results in compromised computers on the Internet. These resources remain available until the user or organization detects and remediates the incident. But what if the user participated willingly? Instead of bad guys having to compromise hosts, what if they instead cut other people such as corporate insiders in on the profits? Given crypto currency, the TOR network, and a few other factors, this could be a nightmare scenario, as we are not ready for this type of surge in distributed attacks.
The recruitment for this could be something like the ‘work from home’ signs you see around your town. The work could be as easy as downloading and installing a package and could earn the host user as much as $10.00/day. That is $300.00/month for someone to simply leave their computer running and connected. The average citizen is not likely to know what type of activity their computer is involved in on a daily basis.
The end result of this scenario would be a massive number of networked computers available for distributed denial-of-service, cryptographic brute forcing, or remote network sniffing. With the cooperation of the host, the capability list is endless, and because they are making money, the host will be motivated to help the cybercriminals persist. Service providers and law enforcement are not ready for this type of attack. This could lead to botnet armies with size and capabilities we have never seen before.
Expansion of Capability Marketplaces
Another nightmare scenario is for cybercriminals to expand their marketplace networks. Today you look at coordination networks like Uber, Instacart, Care.com, etc. These services are facilitators connecting a consumer who wants something delivered with a network of people who can deliver it.
Now think of applying this pattern to cybercrime. On one end there is a criminal who would like the login credentials of a Global 2000 executive. Via TOR networking, they go to a site where they can place their request, submit their crypto currency, and a skilled global workforce accepts this objective and delivers it within the terms of the agreement. This lowers the coordination cost for cybercrime to near zero and connects the demand with the supply in ways that have never been seen to date.
Because so many people are motivated by money, a service like this could turn citizens into cybercriminals if they believe they cannot get caught and that they can easily make a few bucks on the side.
The last thing I will say about this type of participation and marketplace networks is that they fragment security events into small, seemingly disconnected pieces where one event might not look harmful, but only when seen as a whole can the impact and significance be evaluated.
The Next Level of Cybercrime: Click to Compromise
Consider a SaaS service that helped a person compute their cybercrime – Cybercrime as a Service.
The power of big data analytics and machine learning can compute amazing insight for businesses, and it can do the same for criminals. A criminal could log in to a website and declare their objective, and the service would compute several attack plans that the criminal could choose from. This would work in the same way that a user is presented with multiple routes to reach a destination when getting directions online.
This Cybercrime as a Service would have social networks mapped, personal information on each individual, language analysis that yields a level of trust between individuals, mapping to various accounts (some of which may have been compromised), etc. All of this would be creating a corpus of data that can lead the criminal through a directed graph leading to the objective (exfiltration of a file, ransomware, etc.).
Remember, cybercrime is a business and profitable businesses only get smarter and more effective. These are things that keep me up at night because in our current state, there is nothing that makes these types of attacks hard to execute for cybercriminals, and they could easily turn from nightmare to reality.
Wednesday, March 20, 2013
NATO cyberwar manual: Civilian hackers can be targets
Salon reports that the handbook is first attempt to codify how international law applies to state-sponsored online attacks.
Use kinetic force against cyber aggressors? Yes! Make the cost of playing too dear.
Use kinetic force against cyber aggressors? Yes! Make the cost of playing too dear.
Monday, December 12, 2011
Dallas convicts no longer shred confidential data
This is a really great one, especially in light of the prevalence of cell phones in prisons, which enables inmates to continue to conduct business will in the hoosegow. What's next? Having them process visa applications?
Thursday, October 27, 2011
Boeing sees growth in cybersecurity business despite defense cuts; the right choice?
Given the problems Boeing's having in delivering the new 787 Dreamliner, and the growing threats from goverments and orgainzed crime to information resouces, maybe Boeing's making the right choice.
Other news:
National Security Agency helps banks battle hackers
FBI going to court more often to get personal Internet-usage data
Other news:
National Security Agency helps banks battle hackers
FBI going to court more often to get personal Internet-usage data
Subscribe to:
Posts (Atom)