Authorities Seize Control of RagnarLocker Ransomware Dark Web Site

The dark web site that the RagnarLocker ransomware group used for naming and shaming victims was seized on Thursday as part of a coordinated law enforcement effort.

Active since 2020, RagnarLocker has been involved in numerous attacks, with at least 52 entities across 10 critical infrastructure sectors falling victims to this ransomware family, according to data from the Federal Bureau of Investigation (FBI).

Unlike other ransomware operations, RagnarLocker was not promoted as ransomware-as-a-service, but was operated by a private group that cooperated with other cybercriminals only when needed.

On the infected machines, RagnarLocker would gather and exfiltrate system information, iterate through all drives, terminate services that could interfere with the encryption process, and then encrypt all files of interest, avoiding folders and files that might impede the systems operation.

The same as other ransomware groups, the RagnarLocker cybergang would exfiltrate victims’ data to use it for extortion. In some cases, the group would only steal data for extortion, without deploying file-encrypting ransomware.

The cybergang then listed the alleged victims of its attacks on a Tor-hosted leak site, threatening to release it publicly unless a ransom was paid.

Starting Thursday, a message displayed in English on the RagnarLocker ransomware operation’s Tor-based website informs visitors that “this service has been seized as part of a coordinated international law enforcement action against the RagnarLocker group.”

Advertisement. Scroll to continue reading.

Authorities in a dozen countries were involved in this effort, including law enforcement agencies in France, Germany, Italy, Latvia, the Netherlands, Slovakia, Spain, and the US, coordinated by Europol.

This year, law enforcement operations also led to the shutdown of other nefarious dark web site, including the Hive ransomware portal in January, the Genesis Market cybercrime marketplace in April, and the drugs marketplace Piilopuoti in September.

Related: Deep Dive Into Ragnar Locker Ransomware Targeting Critical Industries

Related: Law Enforcement Blowback Powering Anti-Ransomware Success

Related: Tor-Based Drug Marketplace Piilopuoti Shut Down by Law Enforcement

Related: Feedback Friday: Industry Reactions to Hive Ransomware Takedown

https://www.securityweek.com/authorities-seize-control-of-ragnarlocker-ransomware-dark-web-site/




Fraud Detection Firm Spec Raises $15 Million

Fraud detection and defense startup Spec this week announced that it has raised $15 million in a Series A funding round that brings the total raised by the company to more than $29 million.

The new investment round was led by SignalFire, with additional funding from Legion Capital and Rally Ventures.

Founded in 2020, the San Jose, California-based company focuses on protecting online transactions from fraudulent attacks.

According to Spec, its no-code orchestration platform can prevent modern attacks, including those powered by AI, from blocking, bypassing, or manipulating fraud defenses. It scans user sessions to monitor the activity and respond to attacks in real time.

The solution helps organizations identify and remediate vulnerabilities in their fraud defenses, prevent reverse engineering, improve defenses with actionable insights, and monitor and manage fraud vendor solutions.

Spec’s platform also integrates with popular fraud, ecommerce, and customer experience applications, allowing rapid deployment without having to write additional code.

The new funding will allow Spec to advance its platform, expand its threat labs, and work with partners on specialized fraud prevention solutions.

Advertisement. Scroll to continue reading.

“As we look ahead, our commitment to serving enterprises in retail, ticketing, and marketplaces remains stronger than ever. This funding accelerates our efforts to deliver unparalleled security solutions for these amazing businesses,” Spec co-founder and CEO Nate Kharrl said.

Related: CipherStash Raises $3 Million for Encryption-in-Use Technology

Related: Fraud Prevention Firm Fingerprint Raises $33 Million

Related: Anonybit Raises $3 Million for Biometric Authentication Platform

Related: Generative AI Startup Nexusflow Raises $10.6 Million

https://www.securityweek.com/fraud-detection-firm-spec-raises-15-million/




Operations of Healthcare Solutions Giant Henry Schein Disrupted by Cyberattack

Healthcare solutions giant Henry Schein recently disclosed a cybersecurity incident that disrupted some of its business operations and may have resulted in a data breach.

The company revealed on October 15 that its manufacturing and distribution businesses had been hit by a cyberattack a day earlier.

Henry Schein said it took some of its systems offline to contain the incident, which caused temporary disruption to business operations, but the practice management software used by customers has not been impacted. 

However, at the time of writing, the company’s website is still inaccessible, informing visitors of technical difficulties. 

“The Company has engaged outside cybersecurity and forensic information technology experts to help investigate any data impact and respond to this situation. Henry Schein also has notified relevant law enforcement authorities,” the company said in a brief statement.

The company has not shared any other details on the cyberattack, but its brief description suggests that it may have involved ransomware. SecurityWeek has checked the leak websites of several major ransomware groups, but has found no mention of Henry Schein at the time of writing.

We have reached out to Henry Schein for more information and will update this article if the firm responds. 

Advertisement. Scroll to continue reading.

Headquartered in Melville, New York, Henry Schein provides business, clinical, supply chain and technology solutions to dental and other medical organizations. The company has 23,000 employees and its solutions are used by more than one million customers globally.

Related: 1 Million Impacted by Data Breach at NextGen Healthcare

Related: IBM Discloses Data Breach Impacting Janssen Healthcare Platform

Related: Personal Information of 11 Million Patients Stolen in Data Breach at HCA Healthcare

https://www.securityweek.com/operations-of-healthcare-solutions-giant-henry-schein-disrupted-by-cyberattack/




Finland Charges Psychotherapy Hacker With Extortion

Finland on Wednesday charged a hacker, accused of the theft of tens of thousands of records from psychotherapy patients, with over 21,000 counts of extortion, the national prosecutor announced.

“The suspect is held on remand and has denied being guilty of the offenses,” the National Prosecution Authority said in a statement.

The prosecutor is seeking a seven-year prison sentence for the defendant, Aleksanteri Kivimaki, who was formerly identified as Julius Kivimaki.

In the 2018 breach of the Finnish firm Vastaamo, which oversaw dozens of psychotherapy centers throughout the Nordic nation, the private treatment records of tens of thousands of patients were stolen.

After stealing the records, Kivimaki initially sought to extort over 360,000 euros ($381,000) in bitcoin Vastaamo in exchange for not leaking the records, according to the prosecutor.

When Vastaamo refused to pay, Kivimaki started leaking the records as a means of putting pressure on the company.

According to the prosecution, Kivimaki also sent extortion letters to patients demanding sums ranging from 200 to 500 euros to prevent the disclosure of records of their therapy sessions.

Advertisement. Scroll to continue reading.

Kivimaki was also charged with 9,598 counts of dissemination of information infringing on personal privacy.

Following a European arrest warrant issued by the Finnish police in October 2022, he was arrested in the Paris region on February 3.

Kivimaki has previously been convicted on various charges of cybercrime, fraud, and money laundering, as well as 50,700 data breaches carried out in conjunction with a hacker group in over a hundred countries.

The trial is scheduled to begin on November 13 and is expected to last until February of next year.

https://www.securityweek.com/finland-charges-psychotherapy-hacker-with-extortion/




Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw

Malware hunters in Google’s Threat Analysis Group (TAG) say government-backed hacking groups from different countries are feasting on a well-documented security flaw in the popular WinRAR file archiving utility more than three months after patches were released.

The WinRAR code execution vulnerability, tracked as CVE-2023-38831, was fixed in July after zero-day exploitation was detected but now, three months later, Google says APT groups linked to Russia and China are still using the exploit with success.

“Cybercrime groups began exploiting the vulnerability in early 2023, when the bug was still unknown to defenders. A patch is now available, but many users still seem to be vulnerable,” Google’s Kate Morgan said in a note documenting the APT discoveries. “After a vulnerability has been patched, malicious actors will continue to rely on n-days and use slow patching rates to their advantage.”

Morgan said the flaw, which allows attackers to execute arbitrary code when a user attempts to view a benign file (such as an ordinary PNG file) within a ZIP archive, has been known since at least April 2023 and immediately attracted the interest of threat actors.

“Hours after the blog post [about zero-day exploitation] was released, proof of concepts and exploit generators were uploaded to public GitHub repositories. Shortly after that, TAG began to observe testing activity from both financially motivated and APT actors experimenting with CVE-2023-38831,” Morgan added.

In one case, Google TAG detected the Russia-linked Sandworm delivering decoy PDF documents and malicious ZIP files exploiting the WinRAR bug.  Sandworm, aligned with Russian Armed Forces’ Main Directorate of the General Staff (GRU) Unit, used the exploit to deliver a commodity infostealer that is able to collect and exfiltrate browser credentials and session information from infected machines. 

Morgan documented another incident where APT28, another hacking team linked to Russian GRU, used a free hosting provider to serve CVE-2023-38831 to target users in Ukraine. 

Advertisement. Scroll to continue reading.

Google said it also caught government-backed groups linked to China launching WinRAR exploits in targeted attacks against users in Papua New Guinea.

“The widespread exploitation of the WinRAR bug highlights that exploits for known vulnerabilities can be highly effective, despite a patch being available. Even the most sophisticated attackers will only do what is necessary to accomplish their goals,” Morgan warned.

Software security defects in the WinRAR tool are constantly being targeted by cybercriminals and APT groups.  SecurityWeek has reported on multiple WinRAR exploitation incidents recently, including usage by financially motivated hackers against traders and .gov-backed advanced threat actors.

Related: Traders Targeted by Cybercriminals in Attack Exploiting WinRAR Zero-Day

Related: WinRAR Vulnerability Exploited to Deliver New Malware

Related: Recently Patched WinRAR Flaw Exploited in APT Attacks

Related: Hackers Exploit WinRAR Vulnerability to Deliver Malware

https://www.securityweek.com/three-months-after-patch-gov-backed-actors-exploiting-winrar-flaw/




Darwinium Raises $18 Million for Edge-Based Fraud Prevention Tech

Darwinium, a San Francisco startup in the fraud prevention space, has nabbed $18 million in new capital to build technology to help businesses deal with the deluge of bots, scams and online abuse.

The company, which has roots in Australia, said the $18 million Series A round was led by U.S. Venture Partners (USVP).  Darwinium’s seed-stage investors Blackbird, Airtree Ventures and Accomplice also took new equity positions.

Since its launch in 2021, Darwinium has raised $26 million to work on a digital security and fraud prevention platform running on the perimeter edge.

The company is boasting that its platform combines digital security with fraud prevention to create a single view of customer journeys across the web, mobile apps and APIs and provide fraud analytics with customer journey orchestration tooling.

Darwinium argues that its unique integration point — running on the perimeter edge via Content Delivery Networks (CDNs) — gives businesses a continuous view of user behavior, from pre-authentication, through account creation, login, change-of-details, and payments, all via one deployment. 

“Moving fraud and risk decisions to the perimeter edge is privacy preserving and low latency. It also removes the reliance on ‘point-in-time’ API-based solutions that are vulnerable to exploitation via operational silos and disjointed risk assessments,” the company added.

Darwinium said customers are using its platform to separate human and bot traffic, add downstream context from upstream user behavior, protect customers from account takeover and identity spoofing, identify scams and social engineering behaviors, block content and promo abuse, and detect fraudulent payments.

Advertisement. Scroll to continue reading.

Last November, Darwinium announced a $10 million seed round and said its product had already been adopted by organizations in the banking, ecommerce, gaming, payments, and travel sectors.

The company is founded by Alisdair Faulkner, who previously founded and scored an exit with ThreatMetrix, a fraud detection firm that was acquired for $817 million in 2018.

Related: Darwinium Raises $10 Million for Customer Protection Platform

Related: Descope Targets Customer Identity Market with Massive $53M Seed Round

Related: Investors Place Early $4 Million Bet on Stack Identity

Related: Prove Identity Snags $40M Funding for ID Verification Tech

https://www.securityweek.com/darwinium-raises-18-million-for-edge-based-fraud-prevention-tech/




WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

Security researchers are warning of a critical-severity vulnerability in the Royal Elementor Addons and Templates WordPress plugin that has been exploited as a zero-day for more than a month.

Developed by WP Royal, the plugin helps domain admins build their websites without any coding experience. Royal Elementor has more than 200,000 active installations on the WordPress marketplace.

The exploited bug, tracked as CVE-2023-5360 (CVSS score of 9.8), is described as an insufficient file type validation in the plugin’s upload function, allowing unauthenticated attackers to upload arbitrary files to vulnerable sites, leading to remote code execution.

The flaw impacts all Royal Elementor versions prior to 1.3.79 and, according to WordPress security firm Defiant, has been exploited in malicious attacks since at least August 30.

To date, the security firm has seen more than 46,000 attacks attempting to exploit this vulnerability, with an increase in activity observed on October 3.

Most attacks, Defiant says, came from three different IP addresses and were aimed at deploying specific files on the target sites, to create a malicious administrator account.

According to Automattic’s WPScan team, which identified and reported the vulnerability, the attackers were seen deploying at least one malicious file into the /wpr-addons/forms/ directory.

Advertisement. Scroll to continue reading.

The plugin, Automattic explains, relied on a simple extension validation to ensure that only certain file types could be uploaded, but which allowed unauthenticated users to manipulate the list of allowed extensions.

“Upon investigation we found that wp_unique_filename WordPress function performs file name and extensions sanitization and, when combined with the file_validity function, would enable bad actors to manipulate the input and bypass the checks,” Automattic notes.

Site admins should check the /wpr-addons/forms/ directory for the presence of malicious PHP files, including one file creating a user account named ‘wordpress_administrator’.

Automattic also observed that threat actors have been exploiting the vulnerability to upload malware to the compromised websites.

Administrators and site owners are advised to update to Royal Elementor version 1.3.79, which patches the vulnerability. The patched version has been available since October 6.

Related: Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin

Related: Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites

Related: Vulnerability in WordPress Migration Plugin Exposes Websites to Attacks

https://www.securityweek.com/wordpress-websites-hacked-via-royal-elementor-plugin-zero-day/




Cable Giant Volex Targeted in Cyberattack

UK-based cable manufacturing giant Volex (AIM: VLX) has been targeted in a cyberattack that involved unauthorized access to some of the company’s IT systems and data. 

In a statement issued on Monday, the power and data transmission product manufacturer said all of its sites remain operational and it does not expect any financial impact caused by the incident to be material.

However, it did admit that there has been some “minimal disruption to global production levels”. 

“On becoming aware of the incident, the Group enacted its established IT security protocols and took immediate steps to stop the unauthorised access to its systems and data. Specialist, third party consultants have been engaged to investigate the nature and extent of the incident, and to implement the incident response plan,” Volex said.

Volex has not responded to SecurityWeek’s request for additional information, but based on the company’s brief description of the incident, it may have been targeted in a ransomware attack that was either discovered early or that did not involve the deployment of file-encrypting malware, which can typically cause significant disruption in an organization.

SecurityWeek has checked the leak websites of several major ransomware groups, but found no mention of Volex on any of them. 

Advertisement. Scroll to continue reading.

Volex shares on the Alternative Investment Market (AIM) of the London Stock Exchange dropped slightly after news of the breach broke.

Volex provides power cords, plugs, connectors, electric vehicle charging solutions, consumer cable harnesses, data transfer cables, and data center power cables. The firm has 27 manufacturing locations and a global workforce of more than 11,500 across 24 countries. 

Related: MGM Resorts Says Ransomware Hack Cost $110 Million

Related: Sony Confirms Data Stolen in Two Recent Hacker Attacks

Related: Motel One Discloses Ransomware Attack Impacting Customer Data

Related: Johnson Controls Ransomware Attack Could Impact DHS

https://www.securityweek.com/cable-giant-volex-targeted-in-cyberattack/




Android Devices With Backdoored Firmware Found in US Schools

Tens of thousands of Android devices have been shipped to end-users with backdoored firmware, according to a warning from cybersecurity vendor Human Security.

As part of the global cybercriminal operation called BadBox (PDF), Human Security found a threat actor relied on supply chain compromise to infect the firmware of more than 70,000 Android smartphones, CTV boxes, and tablet devices with the Triada malware.

The infected devices come from at least one Chinese manufacturer but, before they are delivered to resellers, physical retail stores, and e-commerce warehouses, a backdoor was injected into their firmware.

“Products known to contain the backdoor have been found on public school networks throughout the United States,” Human says.

Discovered in 2016, Triada is a modular trojan residing in a device’s RAM, relying on the Zygote process to hook all applications on Android, actively using root privileges to substitute system files. Over time, the malware went through various iterations and was found pre-installed on low-cost Android devices on at least two occasions.

As part of the BadBox operation that Human Security discovered, the infected low-cost Android devices allow threat actors to carry out various ad-fraud schemes, including one named PeachPit, which at its peak relied on 121,000 Android and 159,000 iOS devices infected with malware, and on 39 Android, iOS, and CTV-centric apps designed to connect to a fake supply-side platform (SSP).

One of the modules delivered to the infected devices from the command-and-control (C&C) server allows the creation of WebViews that are fully hidden from the user, but which “are used to request, render, and click on ads, spoofing the ad requests to look like they’re coming from certain apps, referred by certain websites, and rendered” on specific devices.

Advertisement. Scroll to continue reading.

BadBox, Human Security notes, also includes a residential proxy module that allows the threat actors to sell access to the victim’s network. Furthermore, they can create WhatsApp messaging accounts and Gmail accounts they can then use for other malicious activities.

“Finally, because of the backdoor’s connection to C2 servers on BadBox-infected smartphones, tablets, and CTV boxes, new apps or code can be remotely installed by the threat actors without the device owner’s permission. The threat actors behind BadBox could develop entirely new schemes and deploy them on BadBox-infected devices without any interaction from the devices’ owners,” Human notes.

The cybersecurity firm says that it has managed to disrupt the PeachPit ad fraud scheme and that the BadBox operators have taken down their C&C servers, likely to adapt and circumvent the deployed defensive measures.

Human also warns that BadBox-infected devices cannot be cleaned by the end-users, since the backdoor resides in the firmware partition and that almost all infected devices are lower-price-point, recommending that users choose familiar brands when purchasing new products.

Related: Xenomorph Android Banking Trojan Targeting Users in US, Canada

Related: Predator Spyware Hitting iOS, Android Devices via Zero-Days

Related: Banking Trojan Delivered via Google Play Targets Users in US, Europe

https://www.securityweek.com/android-devices-with-backdoored-firmware-found-in-us-schools/




Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations

The US, Ukraine, and Israel remain the most frequent targets of cyberespionage and cybercrime attacks out of a total of 120 attacked countries, Microsoft says in a new report.

The observed attacks, the tech giant says, were fueled by nation-state spying and influence operations, and more than 40% of the observed attacks targeted critical infrastructure organizations. At times, NATO member states were at the receiving end of half of the observed cyberattacks.

“While headline-grabbing attacks from the past year were often focused on destruction or financial gain with ransomware, data shows the predominant motivation has swung back to a desire to steal information, covertly monitor communication, or to manipulate what people read,” Microsoft notes.

According to the company’s latest Digital Defense Report (PDF – direct download), between July 2022 and June 2023, Russian spy agencies have intensified their attacks in support of the war in Ukraine, while Iranian threat actors have been amplifying manipulative campaigns and targeting sensitive networks for espionage.

Russia and China too have been increasing the scope of their influence operations, the former to intimidate global Ukrainian communities, and the latter to spread covert anti-US propaganda, directly targeting global Chinese-speaking and other communities.

According to the tech giant’s report, state-sponsored threat actors are increasingly employing propaganda to undermine democratic institutions and manipulate national and global opinion.

China has expanded state-sponsored cyberespionage campaigns fueling its Belt and Road Initiative or targeting US military, key facilities, and critical infrastructure, while North Korean hackers were seen targeting a submarine technology company, while continuing to engage in cryptocurrency theft.

Advertisement. Scroll to continue reading.

“While the US, Ukraine, and Israel continue to be most heavily attacked, the last year has seen an increase in the global scope of attacks. This is particularly the case in the Global South, especially Latin America and sub-Saharan Africa. Iran increased its operations in the Middle East. Organizations involved in policymaking and execution were among the most targeted, in line with the shift in focus to espionage,” Microsoft says.

According to the tech giant’s report, state-sponsored threat actors are increasingly employing propaganda to undermine democratic institutions and manipulate national and global opinion.

Microsoft also observed that threat actors are using AI to improve influence operations, but notes that the technology is crucial for defense and for automating and augmenting detection, analysis, response, and prediction.

Since September 2022, Microsoft says, there has been a 200% increase in human-operated ransomware attacks, targeting organizations with customized ransom demands. Since November 2022, the instances of data exfiltration following compromise have doubled, Microsoft’s report shows.

The tech giant also notes that more than 80% of all observed compromises originated from unmanaged or bring-your-own devices and that ransomware operators are exploiting flaws in less common software, to avoid prediction.

The report also shows that the number of password-based and multi-factor authentication (MFA) fatigue attacks has increased. Over the past year, Microsoft observed roughly 6,000 MFA fatigue attempts per day and, in 2023, an average of 4,000 password attacks per second.

Related: ICS Computers in Western Countries See Increasing Attacks: Report

Related: Healthcare Organizations Hit by Cyberattacks Last Year Reported Big Impact, Costs

Related: Mandiant 2023 M-Trends Report Provides Factual Analysis of Emerging Threat Trends

https://www.securityweek.com/microsoft-releases-new-report-on-cybercrime-state-sponsored-cyber-operations/