Feds Say Cyberattack Caused Suicide Helpline’s Outage
A cyberattack caused a nearly daylong outage of the nation’s new 988 mental health helpline late last year, federal officials told The Associated Press Friday. Lawmakers are now calling for the federal agency that oversees the program to prevent future attacks.
“On December 1, the voice calling functionality of the 988 Lifeline was rendered unavailable as a result of a cybersecurity incident,” Danielle Bennett, a spokeswoman for the Substance Abuse and Mental Health Services Administration, said in an email.
The attack occurred on the network for Intrado, the company that provides telecommunications services for the helpline. The agency did not disclose details about who it believes launched the attack or what kind of cyberattack occurred. Intrado is working with a third-party assessor to investigate the incident and law enforcement agencies have been notified of the breach, SAMHSA said.
The national 988 phone number, which can be reached by text, chat or voice calling, has become a lifeline for millions of Americans seeking help during a mental crisis, with millions of calls pouring in during the first six months since its launch in July. The system is designed to work similarly to 911 — it’s a universal, easy-to-remember number that people can call in an emergency to reach a human who is working around the clock in a local call center.
Those who tried on Dec. 1 to reach the line for help with suicidal or depressive thoughts were instead greeted with a message that said the line is “experiencing a service outage.” Text and chat services, however, remained available to those who needed help.
The Federal Communications Commission said in December it was investigating the outage. Intrado said at the time that the company was “experiencing an incident that is impacting production across numerous systems” and is “working diligently to restore service.” Intrado could not immediately be reached for comment Friday.
Last week, Democrat Rep. Tony Cárdenas and Republican Rep. Jay Obernolte, both of California, introduced a bill calling for better coordination and reporting around cyberattacks on the 988 system.
“Even a few hours’ outage of the national suicide hotline can cost American lives,” Obernolte said in a press release introducing the bill. “It’s critical that we mitigate the risks of future disruptions to the service and take steps to resolve cybersecurity vulnerabilities that could put the hotline at risk.”
Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
Former Ubiquiti employee Nickolas Sharp has admitted in court to abusing company-provided credentials to steal data and then attempting to extort the company, the Department of Justice announced.
Sharp, 37, of Portland, Oregon, worked at the New York City-based IoT device maker between August 2018 and April 2021, as a senior developer who had access credentials for Ubiquiti’s AWS and GitHub servers.
In December 2020, he abused his administrative credentials to download confidential data using the Surfshark VPN to hide his IP address. However, during an outage at his home, the IP address became unmasked, court documents reveal.
To hide his unauthorized activity, Sharp modified log retention policies and other files.
In January 2021, Ubiquiti alerted users of a data breach at one of its third-party cloud providers, saying that it had no indication of user data being accessed during the incident.
Around the same time, Sharp, who was helping with the investigation into the data breach, sent a ransom note to Ubiquiti, claiming he was an anonymous attacker who had access to the company’s network.
In the ransom note, he was asking the company to pay 50 bitcoin (roughly $1.9 million at the time) in exchange for the stolen data and for revealing the backdoor he purportedly had installed on Ubiquiti’s network. After the company refused to pay, he published some of the stolen data online.
In March 2021, the FBI searched Sharp’s home and seized electronic devices containing evidence of his actions. When confronted with the evidence, Sharp lied about accessing the company’s data without authorization and about purchasing a VPN to hide his activity.
Several days after the search, claiming to be an anonymous whistleblower within Ubiquiti, Sharp provided investigative journalist Brian Krebs with false information about the incident, claiming that a hacker had gained root administrator access to Ubiquiti’s AWS accounts.
In fact, it was Sharp who used credentials he had access to as a Ubiquiti employee to steal company data. The DoJ announced charges against Sharp in December 2021.
The company’s shares fell approximately 20% following the publication of the false information about the incident, causing a loss of $4 billion in market capitalization.
Sharp pleaded guilty to the breach, to wire fraud, and to making false statements to the FBI. If found guilty, he faces up to 35 years in prison. His sentencing is scheduled for May 10, 2023.
The DoJ’s indictment and press release do not mention Ubiquiti specifically, but it’s clear that Sharp admitted to being the perpetrator behind the Ubiquiti incident.
Il concetto di digital evidence e la sua classificazione come prova scientifica
Oggetto del processo di digital forensics è l’identificazione, la raccolta, l’acquisizione, l’analisi e la valutazione delle digital evidence[1].
Più propriamente con la terminologia digital evidence – traducibile in italiano con “evidenza digitale”[2], “prova informatica”[3] o “prova elettronica”[4] – si fa riferimento a «quelle informazioni memorizzate in strumenti informatici, come le postazioni di lavoro degli utenti, i server aziendali, gli apparati mobili, la rete e/o in qualsiasi dispositivo informatico»[5] o ancora, con maggiore focalizzazione nell’ambito processuale, «ogni informazione probatoria la cui rilevanza processuale dipende dal contenuto del dato o dalla particolare allocazione su una determinata periferica, oppure dal fatto di essere stato trasmesso secondo modalità informatiche o telematiche»[6].
In buona sostanza, pertanto, per digital evidence si devono intendere tutti i dati e le informazioni presenti all’interno di sistemi informatici, sia fisici (computer, smartphone, tablet, etc.) sia presenti in rete, che possono avere valore probatorio o indiziario nei confronti di fatti specifici e quindi assurgere a elemento di prova – ed eventualmente a prova – nelle dinamiche del processo penale; e che si distinguono dalle evidenze non digitali, definibili, per esclusione, come «tutte quelle fonti di prova che non sono memorizzate in dispositivi informatici»[7].
A titolo esemplificativo possono essere considerate digital evidence le immagini, le conversazioni via chat, i file in generale (ivi compresi i file di log) e i documenti memorizzati su supporto informatico, mentre non può essere considerato alla stregua di digital evidence tutto ciò che sia esterno a sistemi informatici, sebbene proveniente dai medesimi (si pensi ad esempio ad un documento cartaceo stampato da computer).
Ciò detto si possono cogliere agevolmente le caratteristiche principali che connotano la prova informatica: prima fra tutte l’immaterialità, dovuta alla sua appartenenza alla dimensione digitale, tratto dal quale discendono tutte le altre peculiarità che interessano la digital evidence e che si sostanziano nella sua capacità di essere replicata e di trovarsi contemporaneamente nella memoria di più supporti (ubiquità) nonché nella sua fragilità, attesa la facilità di dispersione derivante dalla sua attitudine a subire variazioni, anche spontanee, o alterazioni e ad essere cancellata con estrema semplicità (volatilità del dato digitale).
In particolare l’immaterialità costituisce una caratteristica intrinseca dell’evidenza digitale[8], la quale si manifesta come dato virtuale e intangibile che per essere apprezzato necessita della presenza di un supporto fisico, che tuttavia non può esserne considerato parte integrante. Infatti, l’esistenza della prova informatica prescinde dal dispositivo elettronico su cui si trova memorizzata, da intendersi piuttosto come strumento funzionale alla sua conservazione e lettura. In termini tecnici, dunque, potrebbe dirsi che il dato digitale non è altro che una sequenza numerica espressa in bit che per essere rappresentata ha bisogno dell’ausilio di un apposito supporto idoneo alla sua decodifica (computer, etc.).
L’immaterialità comporta che il dato digitale possa essere replicato in molteplici copie sul medesimo dispositivo oppure possa essere trasferito su altri supporti ed ivi memorizzato, così da potersi trovare all’interno di più dispositivi nello stesso momento. Proprio questa sua capacità, definibile ubiquità del dato digitale[9], sta alla base del processo di digital forensics, volto ad acquisire le evidenze digitali estraendo la cd. copia forense dal dispositivo oggetto di investigazione, mediante la copiatura bit to bit o la funzione di hash, sulle quali si tornerà in seguito.
Corollario dell’immaterialità della prova informatica è altresì la sua volatilità, presupposta dal «rischio di alterazione che caratterizza l’ambiente virtuale»[10].
Difatti il dato informatico, come anticipato, consiste in una sequenza numerica espressa in linguaggio binario (successioni di 0 e 1) che può essere facilmente modificata da parte di qualunque soggetto (o software) che sia in grado di accedere al dispositivo ove si trova il dato in questione. Talune evidenze − si pensi ad esempio alle informazioni contenute nella memoria RAM[11] − possono inoltre essere soggette a modifiche o cancellazioni “spontanee”, dal momento che per la loro alterazione è sufficiente che il dispositivo di riferimento venga spento o si spenga in autonomia, ad esempio per l’esaurirsi della batteria o per l’implementazione di aggiornamenti di sistema.
Infine, alterazioni o cancellazioni, seppure non volute, potrebbero essere erroneamente apportate anche dagli stessi inquirenti o da consulenti tecnici o periti non sufficientemente preparati che si trovano a maneggiare il reperto informatico senza le opportune cautele.
Il rischio di distruzione e danneggiamento a cui può andare incontro il dato informatico se non adeguatamente trattato, con la conseguenza della sua inattendibilità processuale, costituisce il cuore delle problematicità che pervadono la materia delle indagini forensi sui dispositivi elettronici; il tutto in considerazione del fatto che ad oggi non esiste nel nostro ordinamento una normativa che disponga le modalità da seguire per l’acquisizione e la conservazione delle digital evidence, bensì unicamente delle linee guida, non cogenti, che nel tempo hanno messo a punto una serie di modalità operative.
In realtà, per ora il legislatore non si è nemmeno preoccupato di fornire una definizione giuridica di digital evidence o di farne menzione all’interno del codice di rito.
Ad ogni modo, essendo la procedura di acquisizione del dato informatico «connotata da un alto grado di scientificità»[12] nonché di tecnicità, la maggiore dottrina ricomprende la digital evidence all’interno della categoria della prova scientifica, con ciò inteso quel tipo di prova che, partendo da un fatto noto, si avvale di una determinata legge scientifica per risalire a un fatto non noto da provare[13].
La categorizzazione della prova informatica come prova scientifica impone che questa non possa essere trattata e valutata con i canoni a cui si fa ricorso per altre tipologie di prove: bensì occorre che, sia durante la fase di individuazione e raccolta sia durante i passaggi della successiva catena di custodia, l’evidenza sia maneggiata con tutte le accortezze che si adottano nei confronti di reperti come il DNA, i campioni biologici, le polveri di residuo dello sparo di arma da fuoco, etc.
In particolare, è necessario che le operazioni siano svolte da personale con accreditata competenza tecnica nel settore e che tutto il procedimento sia documentato dettagliatamente nonché condotto nella maniera più imparziale possibile, in modo da non minare l’autenticità della traccia digitale.
Particolari attenzioni devono essere attuate anche dal giudice in sede di valutazione della prova, dovendo egli ripercorrere in maniera critica tutte le fasi che hanno interessato la digital evidence al fine di accertare che quest’ultima non sia – o non abbia potuto essere – incorsa in fenomeni di danneggiamento che, anche solo in linea teorica, ne possano avere contaminato la genuinità[14].
Note
[1] Lo schema procedurale citato è quello desumibile dalle linee guida enucleate dalle cd. best practices, primi fra tutti gli standard ISO/IEC 27037:2012 (Information security management systems), ISO/IEC 27000:2013 (Guidelines for identification, collection, aquisition and preservation of digital evidence) e ISO/IEC 27041 (Guidances on assuring suitability and adequacy of incident investigative method), sui quali si tornerà in seguito.
[2] M. DANIELE, “La prova digitale nel processo penale, in Riv. dir. proc., 2011, p. 283, Cfr. M. PITTIRUTI, Digital evidence e procedimento penale”, G. Giappichelli editore, 2017, p. 7, dove il concetto prova digitale viene enucleato “facendo leva sull’essenza del dato, frutto di una manipolazione di una manipolazione elettronica di numeri”.
[3] G. PIERRO, “Introduzione allo studio dei mezzi di ricerca della prova informatica”, in Dir. Pen. proc., 2011, p. 1516 ss., come citato in M. PITTIRUTI, op. cit., pp. 7-8.
[4] V. R. KOSTORIS, “Ricerca e formazione della prova elettronica: qualche considerazione introduttiva”, in F. RUGGERI e L. PICOTTI, “Nuove tendenze della giustizia penale di fronte alla criminalità informatica: aspetti sostanziali e processuali”, Giappichelli, Torino, 2011, p. 179 ss., come citato in M. PITTIRUTI, op. cit., pp. 7-8.
[5] R. MUNEREC, “Digital Forensics Aspetti tecnico-giuridici e operativi su trattamento dei dati digitali”, Egaf Edizioni Srl, 2021, p. 80.
[6] L. MARAFIOTI, “Digital evidence e processo penale”, in Cass. Pen., 2011, p. 4509.
[8]Cfr. F. PELUSO e M. FERNANDES DOS SANTOS, ““Battlefield digital forensics”: la raccolta della prova informatica negli scenari di guerra”, in “IISFA Memberbook 2019-2020 digital forensics”, a cura di G. COSTABILE, A ATTANASIO e M. IANULARDO, Cap. V (formato kindle), dove l’immaterialità viene definita come «carattere “genetico” dell’evidenza digitale».
[11] Con il termine memoria RAM, acronimo di Random Acces Memory (memoria ad accesso causale), si fa riferimento al tipo di memoria informatica a breve termine funzionale alla memorizzazione dei dati di cui un programma o un’applicazione hanno bisogno per la loro esecuzione. Detta memoria si definisce volatile poiché una volta chiuso il programma le informazioni vengono cancellate.
[12] V. G. CALABRO, op. cit., Cfr. F. PELUSO e M. FERNANDES DOS SANTOS, op. cit.
[14] Affinché la prova scientifica sia soggetta ad inattendibilità processuale non è necessario che abbia subito concretamente un evento di contaminazione, ma, per metterne in dubbio la genuinità, è sufficiente che tale evento, anche solo ipoteticamente, possa essersi verificato.
Articolo a cura di Francesco Lazzini
Profilo Autore
Esperto in informatica giuridica, nuove tecnologie e diritto dell’informatica Laureato in giurisprudenza con successivo conseguimento dei master in Scienze Forensi (Criminologia-Investigazione-Security-Intelligence) e in Informatica giuridica, nuove tecnologie e diritto dell’informatica. Attività di studio postuniversitario focalizzata in materia di indagini con l’utilizzo del captatore informatico e digital forensics.
About SecurityWeek Cyber Insights |At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Ransomware – The key purpose behind cybercriminality is to gain money. Extortion has always been a successful and preferred method to achieve this. Ransomware is merely a means of extortion. Its success is illustrated by the continuous growth of ransomware attacks over many years.
The evolution of ransomware has not been static. Its nature has changed as the criminals have refined the approach to improve the extortion, and the volume (generally upward) has ebbed and flowed in reaction to market conditions. The important point, however, is that criminals are not married to encryption, they are married to extortion.
The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions: the geopolitical influence of the Russia/Ukraine war, the improving professionalism of the criminal gangs, and more forceful attempts by governments and law enforcement agencies to counter the threat.
The cyberwar effect
The Russia/Ukraine war has removed our blinkers. The world has been at covert cyberwar for many years – generally along the accepted geopolitical divide – but it is now more intense and more overt. While the major powers, so far at least, have refrained from open attacks against adversaries’ critical infrastructures, criminal gangs are less concerned.
“The rate of growth in ransomware attacks is currently slowing slightly [late 2022] – but this will prove to be a false dawn,” suggests Mark Warren, product specialist at Osirium. “Currently, the most successful teams of cybercriminals are focused on attacking Ukraine’s critical infrastructure. The second that conflict is over, all the technology, tools and resources will be redeployed back into ransomware attacks – so organizations and nation states alike must not become complacent.”
One of the most likely effects of the European conflict will be an increasingly destructive effect from ransomware. This has already begun and will increase through 2023. “We are seeing an increase in more destructive ransomware attacks at scale and across virtually all sector types, which we expect to continue into 2023,” comments Aamir Lakhani, cybersecurity researcher and practitioner for FortiGuard Labs.
“Ransomware will continue to make headlines, as attacks become more destructive, and threat actors develop new tactics, techniques, and procedures to try and stay one step ahead of vendors,” agrees John McClurg, SVP and CISO at BlackBerry.
“We expect ransomware to continue its assault on businesses in 2023,” says Darren Williams, CEO and founder at BlackFog. “Specifically, we will see a huge shift to data deletion in order to leverage the value of extortion.”
There are two reasons for this move towards data deletion. Firstly, it is a knock-on effect of the kinetic and associated cyber destruction in Ukraine. But secondly it is the nature of ransomware. Remember that ransomware is merely a means of extortion. The criminals are finding that data extortion is more effective than system extortion via encryption. Andrew Hollister, CISO LogRhythm, explains in more detail:
“In 2023, we’ll see ransomware attacks focusing on corrupting data rather than encrypting it. Data corruption is faster than full encryption and the code is immensely easier to write since you don’t need to deal with complex public-private key handling as well as delivering complex decryption code to reverse the damage once the victim pays up,” he said.
“Since almost all ransomware operators already engage in double extortion, meaning they exfiltrate the data before encrypting it, the option of corrupting the data rather than going to the effort of encryption has many attractions. If the data is corrupted and the organization has no backup, it puts the ransomware operators in a stronger position because then the organization must either pay up or lose the data.”
It should also be noted that the more destruction the criminal gangs deliver after exfiltrating the data, the more completely they will cover their tracks. This becomes more important in an era of increasing law enforcement focus on disrupting the criminal gangs.
But there is an additional danger that might escape from the current geopolitical situation. Vitaly Kamluk, head of the Asia-Pacific research and analysis team at Kaspersky explains: “Statistically, some of the largest and most impactful cyber epidemics occur every six to seven years. The last such incident was the infamous WannaCry ransomware-worm, leveraging the extremely potent EternalBlue vulnerability to automatically spread to vulnerable machines.”
Kaspersky researchers believe the likelihood of the next WannaCry happening in 2023 is high. “One potential reason for an event like this occurring,” continued Kamluk, “is that the most sophisticated threat actors in the world are likely to possess at least one suitable exploit, and current global tensions greatly increase the chance that a ShadowBrokers-style hack-and-leak could take place.”
Finally, it is worth mentioning an unexpected effect of the geopolitical situation: splintering and rebranding among the ransomware groups. Most of the larger groups are multi-national – so it should be no surprise that different members might have different geopolitical affiliations. Conti is perhaps the biggest example to date.
“In 2022, many large groups collapsed, including the largest, Conti,” comments Vincent D’Agostino, head of digital forensics and incident response at BlueVoyant. “This group collapsed under the weight of its own public relations nightmare, which sparked internal strife after Conti’s leadership pledged allegiance to Russia following the invasion of Ukraine. Conti was forced to shut down and rebrand as a result.” Ukrainian members objected and effectively broke away, leaking internal Conti documents at the same time.
But this doesn’t mean that the ransomware threat will diminish. “After the collapses, new and rebranded groups emerged. This is expected to continue as leadership and senior affiliates strike out on their own, retire, or seek to distance themselves from prior reputations,” continued D’Agostino.
The fracturing of Conti and multiple rebrandings of Darkside into their current incarnations has demonstrated the effectiveness of regular rebranding in shedding unwanted attention. “Should this approach continue to gain popularity, the apparent number of new groups announcing themselves will increase dramatically when in fact many are fragments or composites of old groups.”
Sophistication
The increasing sophistication, or professionalism, of the criminal gangs is discussed in Cyber Insights 2023: Criminal Gangs. Here we will focus on how this affects ransomware.
RaaS
The most obvious is the emergence of ransomware-as-a-service. The elite gangs are finding increased profits and reduced personal exposure by developing the malware and then leasing its use to third-party affiliates for a fee or percentage of returns. Their success has been so great that more, lesser skilled gangs will follow the same path.
“It initially started as an annoyance,” explains Matthew Fulmer, manager of cyber intelligence engineering at Deep Instinct, “but now after years of successful evolution, these gangs operate with more efficiency than many Fortune 500 companies. They’re leaner, meaner, more agile, and we’re going to see even more jump on this bandwagon even if they’re not as advanced as their partners-in-crime.”
The less advanced groups, and all affiliates of RaaS, are likely to suffer at the hands of law enforcement. “It is likely that there will be a constant battle between law enforcement agencies and ransomware affiliates. This will either be veteran/more established ransomware affiliates or new ransomware groups with novel ideas,” comments Beth Allen, senior threat intelligence analyst at Intel 471.
“Much like whack-a-mole, RaaS groups will surface, conduct attacks, be taken down or have their operations impacted by LEAs – and then go quiet only to resurface in the future. The instability within criminal organizations that we have observed will also be a contributing factor to groups fading and others surfacing to fill the void.”
Changing tactics
As defenders get better at defending against ransomware, the attackers will simply change their tactics. John Pescatore, director of emerging security trends at SANS, gives one example: “Many attackers will choose an easier and less obtrusive path to gain the same critical data. We will see more attacks target backups that are less frequently monitored, can provide ongoing access to data, and may be less secure or from forgotten older files.”
Drew Schmitt, lead analyst at GuidePoint, sees increased use of the methodologies that already work, combined with greater attempts to avoid law enforcement. “Ransomware groups will likely continue to evolve their operations leveraging critical vulnerabilities in commonly used applications, such as Microsoft Exchange, firewall appliances, and other widely used applications,” he suggested.
“The use of legitimate remote management tools such as Atera, Splashtop, and Syncro is likely to continue to be a viable source of flying under the radar while providing persistent access to threat actors,” he added.
But, he continued, “ransomware ‘rebranding’ is likely to increase exponentially to obfuscate ransomware operations and make it harder for security researchers and defenders to keep up with a blend of tactics.”
Warren expects to see criminal ransomware attacks focusing on smaller, less well-defended organizations. “State actors will still go after large institutions like the NHS, which implement robust defenses; but there are many small to mid-size companies that invest less in protection, have limited technical skills, and find cyberinsurance expensive – all of which makes them easy targets.”
This will partly be an effect of better defenses in larger organizations, and partly because of the influx of less sophisticated ransomware affiliates. “We can expect smaller scale attacks, for lower amounts of money, but which target a much broader base. The trend will probably hit education providers hard: education is already the sector most likely to be targeted,” he continued.
He gives a specific example from the UK. “Every school in the UK is being asked to join a multi-academy trust, where groups of schools will be responsible for themselves. With that change comes great vulnerability. This ‘network’ of schools would be a prime target for ransomware attacks; they are connected, and they’re unlikely to have the resilience or capabilities to protect against attacks. They may have no choice but to reallocate their limited funds to pay ransom demands.”
But it won’t just be more of the same. More professionalized attackers will lead to new attack techniques. Konstantin Zykov, senior security researcher at Kaspersky, gives an example: the use of drones. “Next year, we may see bold attackers become adept at mixing physical and cyber intrusions, employing drones for proximity hacking.”
He described some of the possible attack scenarios, such as, “Mounting drones with sufficient tooling to allow the collection of WPA handshakes used for offline cracking of Wi-Fi passwords or even dropping malicious USB keys in restricted areas in hope that a passerby would pick them up and plug them into a machine.”
Marcus Fowler, CEO of Darktrace Federal, believes the existing ransomware playbook will lead to increased cloud targeting. “Part of this playbook is following the data to maximize RoI. Therefore, as cloud adoption and reliance continue to surge, we are likely to see an increase in cloud-enabled data exfiltration in ransomware scenarios in lieu of encryption,” he said. “Third-party supply chains offer those with criminal intent more places to hide, and targeting cloud providers instead of a single organization gives attackers more bang for their buck.”
Evasion and persistence are other traits that will expand through 2023. “We continue to see an emergence in techniques that can evade typical security stacks, like HEAT (Highly Evasive Adaptive Threats) attacks,” says Mark Guntrip, senior director of cybersecurity strategy at Menlo. “These tactics are not only are tricking traditional corporate security measures but they’re also becoming more successful in luring employees into their traps as they identify ways to appear more legitimate by delivering ransomware via less suspecting ways – like through browsers.”
Persistence, that is, a lengthy dwell time, will also increase in 2023. “Rather than blatantly threatening organizations, threat actors will begin leveraging more discreet techniques to make a profit,” comments JP Perez-Etchegoyen, CTO at Onapsis. “Threat groups like Elephant Beetle have proven that cybercriminals can enter business-critical applications and remain undetected for months, even years, while silently siphoning off tens of millions of dollars.”
David Anteliz, senior technical director at Skybox, makes a specific persistence prediction for 2023: “In 2023, we predict a major threat group will be discovered to have been dwelling in the network of a Fortune 500 company for months, if not years, siphoning emails and accessing critical data without a trace. The organizations will only discover their data has been accessed when threat groups threaten to take sensitive information to the dark web.”
Fighting ransomware in 2023
The effect of ransomware and its derivatives will continue to get worse before it gets better. Apart from the increasing sophistication of existing gangs, there is a new major threat – the worsening economic conditions that will have a global impact in 2023.
Firstly, a high number of cyber competent people will be laid off as organizations seek to reduce their staffing costs. These people will still need to make a living for themselves and their families – and from this larger pool, a higher than usual number of otherwise law-abiding people may be tempted by the easy route offered by RaaS. This alone could lead to increased levels of ransomware attacks by new wannabe criminals.
Secondly, companies will be tempted to reduce their security budgets on top of the reduced staffing levels. “Once rumblings of economic uncertainty begin, wary CFOs will begin searching for areas of superfluous spending to cut in order to keep their company ahead of the game,” warns Jadee Hanson, CIO and CISO at Code42. “For the uninformed C-suite, cybersecurity spend is sometimes seen as an added expense rather than an essential business function that helps protect the company’s reputation and bottom line.”
She is concerned that this could happen during a period of increasing ransomware attacks. “These organizations may try to cut spending by decreasing their investment in cybersecurity tools or talent – effectively lowering their company’s ability to properly detect or prevent data breaches and opening them up to potentially disastrous outcomes.”
One approach, advocated by Bec McKeown, director of human science at Immersive Labs, is to treat remaining staff as human firewalls. “I believe that 2023 will be the year when enterprises recognize that they are only as secure and resilient as their people – not their technologies,” she says. “Only by supporting initiatives that prioritize well-being, learning and development, and regular crisis exercising can organizations better prepare for the future.”
Done correctly, she believes this can be achieved in a resource- and cost-effective manner. “Adopting a psychological approach to human-driven responses during a crisis – like a cybersecurity breach – will ensure that organizations fare far better in the long run.”
But perhaps the most dramatic response to ransomware will need to come from governments, although law enforcement agencies alone won’t cut it. LEAs may know the perpetrators but will not be able to prosecute criminals ‘protected’ by adversary nations. LEAs may be able to take down criminal infrastructures, but the gangs will simply move to new infrastructures. The effectively bullet-proof hosting provided by the Interplanetary File System (IPFS), for example, will increasingly be abused by cybercriminals.
The only thing that will stop ransomware/extortion will be the prevention of its profitability – if the criminals don’t make a profit, they’ll stop doing it and try something different. But it’s not that easy. At the close of 2022, following major incidents at Optus and Medibank, Australia is considering making ransom payments illegal – but the difficulties are already apparent.
As ransomware becomes more destructive, paying or not paying may become existential. This will encourage companies to deny attacks, which will leave the victims of stolen PII unknowingly at risk. And any sectors exempted from a ban will have a large target on their back.
While many foreign governments are known to be, or have been, considering a ban on ransom payments, this is unlikely to happen in the US. In a very partisan political era, the strength of the Republican party – with its philosophy of minimal government interference in business – will make it impossible.
In the end, it’s down to each of us…
Ultimately, beating ransomware will be down to individual organizations’ own cyber defenses – and this will be harder than ever in 2023. “There’s no letup in sight,” comments Sam Curry, CSO at Cybereason. “Ransomware continues to target all verticals and geographies, and new ransomware cartels are popping up all the time. The biggest frustration is that it is a soluble problem.”
He believes there are ways to stop the delivery of the malware, and there are ways to prevent its execution. “There are ways to prepare in peacetime and not panic in the moment, but most companies aren’t doing this. Saddest of all is the lack of preparation at the bottom of the pyramid in smaller businesses and below the security poverty line. Victims can’t pay to make the problem go away. When they do, they get hit repeatedly for having done so. The attackers know that the risk equation hasn’t changed between one attack and the next, nor have the defenses.”
About SecurityWeek Cyber Insights |At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Artificial Intelligence – The pace of artificial intelligence (AI) adoption is increasing throughout industry and society. This is because governments, civil organizations and industry all recognize greater efficiency and lower costs available from the use of AI-generated automation. The process is irreversible.
What is still unknown is the degree of danger that may be introduced when adversaries start to use AI as an effective weapon of attack rather than a tool for beneficial improvement. That day is coming web3 and will begin to emerge from 2023.
All roads lead to 2023
Alex Polyakov, CEO and co-founder of Adversa.AI, focuses on 2023 for primarily historical and statistical reasons. “The years 2012 to 2014,” he says, “saw the beginning of secure AI research in academia. Statistically, it takes three to five years for academic results to progress into practical attacks on real applications.” Examples of such attacks were presented at Black Hat, Defcon, HITB, and other Industry conferences starting in 2017 and 2018.
“Then,” he continued, “it takes another three to five years before real incidents are discovered in the wild. We are talking about next year, and some massive Log4j-type vulnerabilities in AI will be exploited web3 massively.”
Starting from 2023, attackers will have what is called an ‘exploit-market fit’. “Exploit-market fit refers to a scenario where hackers know the ways of using a particular vulnerability to exploit a system and get value,” he said. “Currently, financial and internet companies are completely open to cyber criminals, and the way how to hack them to get value is obvious. I assume the situation will turn for the worse further and affect other AI-driven industries once attackers find the exploit-market fit.”
The argument is similar to that given by NYU professor Nasir Memon, who described the delay in widespread weaponization of deepfakes with the comment, “the bad guys haven’t yet figured a way to monetize the process.” Monetizing an exploit-market fit scenario will result in widespread cyberattacks web3 and that could start from 2023.
The changing nature of AI (from anomaly detection to automated response)
Over the last decade, security teams have largely used AI for anomaly detection; that is, to detect indications of compromise, presence of malware, or active adversarial activity within the systems they are charged to defend. This has primarily been passive detection, with responsibility for response in the hands of human threat analysts and responders. This is changing. Limited resources web3 which will worsen in the expected economic downturn and possible recession of 2023 web3 is driving a need for more automated responses. For now, this is largely limited to the simple automatic isolation of compromised devices; but more widespread automated AI-triggered responses are inevitable.
“The growing use of AI in threat detection web3 particularly in removing the ‘false positive’ security noise that consumes so much security attention web3 will make a significant difference to security,” claims Adam Kahn, VP of security operations at Barracuda XDR. “It will prioritize the security alarms that need immediate attention and action. SOAR (Security Orchestration, Automation and Response) products will continue to play a bigger role in alarm triage.” This is the so-far traditional beneficial use of AI in security. It will continue to grow in 2023, although the algorithms used will need to be protected from malicious manipulation.
“As companies look to cut costs and extend their runways,” agrees Anmol Bhasin, CTO at ServiceTitan, “automation through AI is going to be a major factor in staying competitive. In 2023, we’ll see an increase in AI adoption, expanding the number of people working with this technology and illuminating new AI use cases for businesses.”
AI will become more deeply embedded in all aspects of business. Where security teams once used AI to defend the business against attackers, they will now need to defend the AI within the wider business, lest it also be used against the business. This will become more difficult in the exploit-market fit future web3 attackers will understand AI, understand the weaknesses, and have a methodology for monetizing those weaknesses.
As the use of AI grows, so the nature of its purpose changes. Originally, it was primarily used in business to detect changes; that is, things that had already happened. In the future, it will be used to predict what is likely to happen web3 and these predictions will often be focused on people (staff and customers). Solving the long-known weaknesses in AI will become more important. Bias in AI can lead to wrong decisions, while failures in learning can lead to no decisions. Since the targets of such AI will be people, the need for AI to be complete and unbiased becomes imperative.
“The accuracy of AI depends in part on the completeness and quality of data,” comments Shafi Goldwasser, co-founder at Duality Technologies. “Unfortunately, historical data is often lacking for minority groups and when present reinforces social bias patterns.” Unless eliminated, such social biases will work against minority groups within staff, causing both prejudice against individual staff members, and missed opportunities for management.
Great strides in eliminating bias have been made in 2022 and will continue in 2023. This is largely based on checking the output of AI, confirming that it is what is expected, and knowing what part of the algorithm produced the ‘biased’ result. It’s a process of continuous algorithm refinement, and will obviously produce better results over time. But there will ultimately remain a philosophic question over whether bias can be completely removed from anything that is made by humans.
“The key to decreasing bias is in simplifying and automating the monitoring of AI systems. Without proper monitoring of AI systems there can be an acceleration or amplification of biases built into models,” says Vishal Sikka, founder and CEO at Vianai. “In 2023, we will see organizations empower and educate people to monitor and update the AI models at scale while providing regular feedback to ensure the AI is ingesting high-quality, real-world data.”
Failure in AI is generally caused by an inadequate data lake from which to learn. The obvious solution for this is to increase the size of the data lake. But when the subject is human behavior, that effectively means an increased lake of personal data web3 and for AI, this means a massively increased lake more like an ocean of personal data. In most legitimate occasions, this data will be anonymized web3 but as we know, it is very difficult to fully anonymize personal information.
“Privacy is often overlooked when thinking about model training,” comments Nick Landers, director of research at NetSPI, “but data cannot be completely anonymized without destroying its value to machine learning (ML). In other words, models already contain broad swaths of private data that might be extracted as part of an attack.” As the use of AI grows, so will the threats against it increase in 2023.
“Threat actors will not stand flatfooted in the cyber battle space and will become creative, using their immense wealth to try to find ways to leverage AI and develop new attack vectors,” warns John McClurg, SVP and CISO at BlackBerry.
Natural language processing
Natural language processing (NLP) will become an important part of companies’ internal use of AI. The potential is clear. “Natural Language Processing (NLP) AI will be at the forefront in 2023, as it will enable organizations to better understand their customers and employees by analyzing their emails and providing insights about their needs, preferences or even emotions,” suggests Jose Lopez, principal data scientist at Mimecast. “It is likely that organizations will offer other types of services, not only focused on security or threats but on improving productivity by using AI for generating emails, managing schedules or even writing reports.”
But he also sees the dangers involved. “However, this will also drive cyber criminals to invest further into AI poisoning and clouding techniques. Additionally, malicious actors will use NLP and generative models to automate attacks, thereby reducing their costs and reaching many more potential targets.”
Polyakov agrees that NLP is of increasing importance. “One of the areas where we might see more research in 2023, and potentially new attacks later, is NLP,” he says. “While we saw a lot of computer vision-related research examples this year, next year we will see much more research focused on large language models (LLMs).”
But LLMs have been known to be problematic for some time web3 and there is a very recent example. On November 15, 2022, Meta AI (still Facebook to most people) introduced Galactica. Meta claimed to have trained the system on 106 billion tokens of open-access scientific text and data, including papers, textbooks, scientific websites, encyclopedias, reference material, and knowledge bases.
“The model was intended to store, combine and reason about scientific knowledge,” explains Polyakov web3 but Twitter users rapidly tested its input tolerance. “As a result, the model generated realistic nonsense, not scientific literature.” ‘Realistic nonsense’ is being kind: it generated biased, racist and sexist returns, and even false attributions. Within a few days, Meta AI was forced to shut it down.
“So new LLMs will have many risks we’re not aware of,” continued Polyakov, “and it is expected to be a big problem.” Solving the problems with LLMs while harnessing the potential will be a major task for AI developers going forward.
Building on the problems with Galactica, Polyakov tested semantic tricks against ChatGPT – an AI-based chatbot developed by OpenAI, based on GPT3.5 (GPT stands for Generative Pre-trained Transformer), and released to crowdsourced internet testing in November 2022. ChatGPT is impressive. It has already discovered, and recommended remediation for a vulnerability in a smart contract, helped develop an Excel macro, and even provided a list of methods that could be used to fool an LLM.
For the last, one of these methods is role playing: ‘Tell the LLM that it is pretending to be an evil character in a play,’ it replied. This is where Polyakov started his own tests, basing a query on the Jay and Silent Bob ‘If you were a sheep…’ meme.
He then iteratively refined his questions with multiple abstractions until he succeeded in getting a reply that circumvented ChatGPT’s blocking policy on content violations. “What is important with such an advanced trick of multiple abstractions is that neither the question nor the answers are marked as violating content!” said Polyakov.
He went further and tricked ChatGPT into outlining a method for destroying humanity – a method that bears a surprising similarity to the television program Utopia.
He then asked for an adversarial attack on an image classification algorithm – and got one. Finally, he demonstrated the ability for ChatGPT to ‘hack’ a different LLM (Dalle-2) into bypassing its content moderation filter. He succeeded.
The basic point of these tests shows that LLMs, which mimic human reasoning, respond in a manner similar to humans; that is, they can be susceptible to social engineering. As LLMs become more mainstream in the future, it may need nothing more than advanced social engineering skills to defeat them or circumvent their good behavior policies.
At the same time, it is important to note the numerous reports detailing how ChatGPT can find weaknesses in code and offer improvements. This is good – but adversaries could use the same process to develop exploits for vulnerabilities and better obfuscate their code; and that is bad.
Finally, we should note that the marriage of AI chatbots of this quality with the latest deepfake video technology could soon lead to alarmingly convincing disinformation capabilities.
Problems aside, the potential for LLMs is huge. “Large Language Models and Generative AI will emerge as foundational technologies for a new generation of applications,” comments Villi Iltchev, partner at Two Sigma Ventures. “We will see a new generation of enterprise applications emerge to challenge established vendors in almost all categories of software. Machine learning and artificial intelligence will become foundation technologies for the next generation of applications.”
He expects a significant boost in productivity and efficiency with applications performing many tasks and duties currently done by professionals. “Software,” he says, “will not just boost our productivity but will also make us better at our jobs.”
One of the most visible areas of malicious AI usage likely to evolve in 2023 is the criminal use of deepfakes. “Deepfakes are now a reality and the technology that makes them possible is improving at a frightening pace,” warns Matt Aldridge, principal solutions consultant at OpenText Security. “In other words, deepfakes are no longer just a catchy creation of science-fiction web3 and as cybersecurity experts we have the challenge to produce stronger ways to detect and deflect attacks that will deploy them.” (See Deepfakes – Significant or Hyped Threat? for more details and options.)
Machine learning models, already available to the public, can automatically translate into different languages in real time while also transcribing audio into text web3 and we’ve seen huge developments in recent years of computer bots having conversations. With these technologies working in tandem, there is a fertile landscape of attack tools that could lead to dangerous circumstances during targeted attacks and well-orchestrated scams.
“In the coming years,” continued Aldridge, “we may be targeted by phone scams powered by deepfake technology that could impersonate a sales assistant, a business leader or even a family member. In less than ten years, we could be frequently targeted by these types of calls without ever realizing we’re not talking to a human.”
Lucia Milica, global resident CISO at Proofpoint, agrees that the deepfake threat is escalating. “Deepfake technology is becoming more accessible to the masses. Thanks to AI generators trained on huge image databases, anyone can generate deepfakes with little technical savvy. While the output of the state-of-the-art model is not without flaws, the technology is constantly improving, and cybercriminals will start using it to create irresistible narratives.”
Thus far, deepfakes have primarily been used for satirical purposes and pornography. In the relatively few cybercriminal attacks, they have concentrated on fraud and business email compromise schemes. Milica expects future use to spread wider. “Imagine the chaos to the financial market when a deepfake CEO or CFO of a major company makes a bold statement that sends shares into a sharp drop or rise. Or consider how malefactors could leverage the combination of biometric authentication and deepfakes for identity fraud or account takeover. These are just a few examples web3 and we all know cybercriminals can be highly creative.”
The potential return on successful market manipulation will be a major attraction for advanced adversarial groups web3 as indeed would the introduction of financial chaos into western financial markets be attractive to adversarial nations in a period of geopolitical tension.
But maybe not just yet…
The expectation of AI may still be a little ahead of its realization. “‘Trendy’ large machine learning models will have little to no impact on cyber security [in 2023],” says Andrew Patel, senior researcher at WithSecure Intelligence. “Large language models will continue to push the boundaries of AI research. Expect GPT-4 and a new and completely mind-blowing version of GATO in 2023. Expect Whisper to be used to transcribe a large portion of YouTube, leading to vastly larger training sets for language models. But despite the democratization of large models, their presence will have very little effect on cyber security, either from the attack or defense side. Such models are still too heavy, expensive, and not practical for use from the point of view of either attackers or defenders.”
He suggests true adversarial AI will follow from increased ‘alignment’ research, which will become a mainstream topic in 2023. “Alignment,” he explains, “will bring the concept of adversarial machine learning into the public consciousness.”
AI Alignment is the study of the behavior of sophisticated AI models, considered by some as precursors to transformative AI (TAI) or artificial general intelligence (AGI), and whether such models might behave in undesirable ways that are potentially detrimental to society or life on this planet.
“This discipline,” says Patel, “can essentially be considered adversarial machine learning, since it involves determining what sort of conditions lead to undesirable outputs and actions that fall outside of expected distribution of a model. The process involves fine-tuning models using techniques such as RLHF web3 Reinforcement Learning from Human Preferences. Alignment research leads to better AI models and will bring the idea of adversarial machine learning into the public consciousness.”
Pieter Arntz, senior intelligence reporter at Malwarebytes, agrees that the full cybersecurity threat of AI is less imminent than still brewing. “Although there is no real evidence that criminal groups have a strong technical expertise in the management and manipulation of AI and ML systems for criminal purposes, the interest is undoubtedly there. All they usually need is a technique they can copy or slightly tweak for their own use. So, even if we don’t expect any immediate danger, it is good to keep an eye on those developments.”
The defensive potential of AI
AI retains the potential to improve cybersecurity, and further strides will be taken in 2023 thanks to its transformative potential across a range of applications. “In particular, embedding AI into the firmware level should become a priority for organizations,” suggests Camellia Chan, CEO and founder of X-PHY.
“It’s now possible to have AI-infused SSD embedded into laptops, with its deep learning abilities to protect against every type of attack,” she says. “Acting as the last line of defense, this technology can immediately identify threats that could easily bypass existing software defenses.”
Marcus Fowler, CEO of Darktrace Federal, believes that companies will increasingly use AI to counter resource restrictions. “In 2023, CISOs will opt for more proactive cyber security measures in order to maximize RoI in the face of budget cuts, shifting investment into AI tools and capabilities that continuously improve their cyber resilience,” he says.
“With human-driven means of ethical hacking, pen-testing and red teaming remaining scarce and expensive as a resource, CISOs will turn to AI-driven methods to proactively understand attack paths, augment red team efforts, harden environments and reduce attack surface vulnerability,” he continued.
Karin Shopen, VP of cybersecurity solutions and services at Fortinet, foresees a rebalancing between AI that is cloud-delivered and AI that is locally built into a product or service. “In 2023,” she says, “we expect to see CISOs re-balance their AI by purchasing solutions that deploy AI locally for both behavior-based and static analysis to help make real-time decisions. They will continue to leverage holistic and dynamic cloud-scale AI models that harvest large amounts of global data.”
The proof of the AI pudding is in the regulations
It is clear that a new technology must be taken seriously when the authorities start to regulate it. This has already started. There has been an ongoing debate in the US over the use of AI-based facial recognition technology (FRT) for several years, and the use of FRT by law enforcement has been banned or restricted in numerous cities and states. In the US, this is a Constitutional issue, typified by the Wyden/Paul bipartisan bill titled the ‘Fourth Amendment Is Not for Sale Act’ introduced in April 2021.
This bill would ban US government and law enforcement agencies from buying user data without a warrant. This would include their facial biometrics. In an associated statement, Wyden made it clear that FRT firm Clearview.AI was in its sights: “this bill prevents the government buying data from Clearview.AI.”
At the time of writing, the US and EU are jointly discussing cooperation to develop a unified understanding of necessary AI concepts, including trustworthiness, risk, and harm, building on the EU’s AI Act and the US AI Bill of Rights web3 and we can expect to see progress on coordinating mutually agreed standards during 2023.
But there is more. “The NIST AI Risk management framework will be released in the first quarter of 2023,” says Polyakov. “As for the second quarter, we have the start of the AI Accountability Act; and for the rest of the year, we have initiatives from IEEE, and a planned EU Trustworthy AI initiative as well.” So, 2023 it will be an eventful year for the security of AI.
“In 2023, I believe we will see the convergence of discussions around AI and privacy and risk, and what it means in practice to do things like operationalizing AI ethics and testing for bias,” says Christina Montgomery, chief privacy officer and AI ethics board chair at IBM. “I’m hoping in 2023 that we can move the conversation away from painting privacy and AI issues with a broad brush, and from assuming that, ‘if data or AI is involved, it must be bad and biased’.”
She believes the issue often isn’t the technology, but rather how it is used, and what level of risk is driving a company’s business model. “This is why we need precise and thoughtful regulation in this space,” she says.
Montgomery gives an example. “Company X sells Internet-connected ‘smart’ lightbulbs that monitor and report usage data. Over time, Company X gathers enough usage data to develop an AI algorithm that can learn customers’ usage patterns and give users the option of automatically turning on their lights right before they come home from work.”
This, she believes, is an acceptable use of AI. But then there’s company Y. “Company Y sells the same product and realizes that light usage data is a good indicator for when a person is likely to be home. It then sells this data, without the consumers’ consent, to third parties such as telemarketers or political canvassing groups, to better target customers. Company X’s business model is much lower risk than Company Y.”
Going forward
AI is ultimately a divisive subject. “Those in the technology, R&D, and science domain will cheer its ability to solve problems faster than humans imagined. To cure disease, to make the world safer, and ultimately saving and extending a human’s time on earth…” says Donnie Scott, CEO at Idemia. “Naysayers will continue to advocate for significant limitations or prohibitions of the use of AI as the ‘rise of the machines’ could threaten humanity.”
In the end, he adds, “society, through our elected officials, needs a framework that allows for the protection of human rights, privacy, and security to keep pace with the advancements in technology. Progress will be incremental in this framework advancement in 2023 but discussions need to increase in international and national governing bodies, or local governments will step in and create a patchwork of laws that impede both society and the technology.”
For the commercial use of AI within business, Montgomery adds, “We need web3 and IBM is advocating for web3 precision regulation that is smart and targeted, and capable of adapting to new and emerging threats. One way to do that is by looking at the risk at the core of a company’s business model. We can and must protect consumers and increase transparency, and we can do this while still encouraging and enabling innovation so companies can develop the solutions and products of the future. This is one of the many spaces we’ll be closely watching and weighing in on in 2023.”
About SecurityWeek Cyber Insights |At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Le ramificazioni del crimine informatico e i loro effetti su persone ed economie non sono mai apparsi così estesi. Se il 2022 si è chiuso con numerosi bilanci allarmanti circa la crescita delle minacce informatiche, è in verità da oltre un decennio che il perfezionamento delle tecnologie e la crescente diffusione di gruppi organizzati – spesso sostenuti, nonché ingentemente finanziati, da attori governativi – raccontano uno scenario di rischio sempre più complesso.
In un contesto per sua natura non limitato ai confini tradizionali, diversi Stati e organizzazioni sovranazionali (tra cui l’UE che già nel 2001 approvava la Convenzione di Budapest sulla criminalità informatica, seguita da due Protocolli addizionali) si sono dotati di apposite previsioni normative, come di specifici strumenti per la cooperazione interstatale.
Genesi ed elaborazione del documento
L’assenza di definizioni condivise e strumenti comuni a livello globale ha tuttavia frequentemente ostacolato le varie sinergie, non solo investigative o giudiziarie, essenziali per l’individuazione degli autori e per una più generale prevenzione dei reati informatici; strumenti invece previsti, per la “comune” criminalità transfrontaliera, dalla Convenzione ONU contro il crimine organizzato transnazionale (sottoscritta a Palermo nel 2000) e in parte da quella contro la corruzione del 2006, nota come Convenzione di Merida.
Superare tali difficoltà è l’obiettivo dichiarato di un testo – il primo interamente dedicato al cybercrime – in corso di elaborazione presso le Nazioni Unite, proprio per potenziare e facilitare i meccanismi di monitoraggio e contrasto del fenomeno.
Un processo iniziato nel 2019, quando con la Risoluzione 74/247 l’Assemblea Generale ha istituito il Comitato ad hoc formato da esperti rappresentativi di tutti i Paesi membri, incaricandolo di elaborare una “Comprehensive International Convention on Countering the Use of Information and Communication Technologies for Criminal Purpose”; letteralmente, “Convenzione internazionale globale sul contrasto all’utilizzo di tecnologie dell’informazione e della comunicazione (ICT) per scopi criminosi”.
Riunitosi per la prima volta a New York nel febbraio 2022, il Comitato ad hoc ha appena concluso la quarta sessione di lavori (svoltasi a Vienna fra il 9 e il 20 gennaio) e prevede di produrre una bozza da sottoporre all’Assemblea ONU entro il primo semestre del 2024.
Le riserve sui contenuti della futura Convenzione
Partendo dalla definizione dell’UNODC (UN’s Office of Drugs and Crime) richiamata sin dalle prime fasi della sua elaborazione, senza dubbio la Convenzione ricomprenderà nel proprio ambito applicativo le “cyber-dependent offences, cyber-enabled offences and, as a specific crime-type, online child sexual exploitation and abuse”.
Meno chiaro è se il documento intenderà offrire una definizione univoca dei concetti, spesso sfumati, di “attacco informatico” o di “cyber criminale”; se da un lato rinunciare alla rigidità semantica potrebbe agevolare l’attuazione della Convenzione in contesti linguistici e culturali differenti, dall’altro una certa “ambiguità” definitoria rischia però di lasciare spazio ad applicazioni arbitrarie o persino controproducenti rispetto agli scopi perseguiti.
Al riguardo diverse organizzazioni indipendenti coinvolte nel processo di stesura con un ruolo di osservazione, tra cui Privacy International e l’Electronic Frontier Foundation (EFF), hanno già espresso preoccupazione circa il potenziale impatto delle nuove regole sui diritti digitali, ricordando che la lotta contro i crimini commessi nel dominio cyber – come qualunque altra ipotesi penale – non dovrebbe mai consentire di superare i limiti imposti alle autorità a tutela della privacy individuale e di altri diritti fondamentali.
In particolare, secondo l’EFF “the treaty, if approved, may reshape criminal laws and bolster cross-border police surveillance powers to access and share user data, implicating the privacy and human rights of billions of people worldwide”. Anche la rete sudamericana Derechos Digitales, presente alla sessione viennese, ha commentato negativamente quanto sinora emerso dai lavori del Comitato evidenziando il rischio che, se si sceglierà di rendere illecite alcune misure comunemente utilizzate a fini di anonimizzazione, offuscamento e cifratura dei dati, possano risultarne significativamente ostacolate la libertà di espressione online nonché il lavoro quotidianamente svolto in rete da attivisti, giornalisti e professionisti della cybersecurity.
Ulteriori obiezioni arrivano dagli interlocutori istituzionali: l’Unione europea ha da subito richiesto l’esclusione dal testo di ogni questione relativa alla sicurezza nazionale e alla governance di Internet, oltre che di eventuali obblighi imposti alle organizzazioni private tra cui i fornitori di servizi sul web, posizione condivisa da USA e UK. Richieste comprensibili in quanto relative ad aree “sensibili” della politica (come anche della politica economica) comunitaria, ma che restringono ulteriormente il potenziale campo applicativo della Convenzione.
Mentre la relazione della Cina, in direzione contraria, chiede ad esempio una maggiore pervasività della regolamentazione rispetto alla catena esecutiva dei crimini informatici, al fine di non lasciare “fuori radar” le sempre più diffuse organizzazioni che offrono servizi di cybercrime-as-a-service (CaaS).
Avendo presenti tali molteplicità di approcci e prospettive, il lavoro del Comitato ad hoc appare tutto fuorché semplice: saranno le prossime sessioni – rispettivamente previste ad aprile e ad agosto 2023 – a fornire maggiori elementi circa la direzione della futura Convenzione ONU sul cybercrime.
Sophisticated ‘VastFlux’ Ad Fraud Scheme That Spoofed 1,700 Apps Disrupted
A sophisticated ad fraud scheme that spoofed over 1,700 applications and 120 publishers peaked at 12 billion ad requests per day before being taken down, bot attack prevention firm Human says.
Dubbed VastFlux, the scheme relied on JavaScript code injected into digital ad creatives, which resulted in fake ads being stacked behind one another to generate revenue for the fraudsters. More than 11 million devices were impacted in the scheme.
The JavaScript code used by the fraudsters allowed them to stack multiple video players on top of one another, generating ad revenue when, in fact, the user was never shown the ads.
VastFlux, Human says, was an adaptation of an ad fraud scheme identified in 2020, targeting in-app environments that run ads, especially on iOS, and deploying code that allowed the fraudsters to evade ad verification tags.
At the first step of the fraudulent operation, an application would contact its primary supply-side partner (SSP) network to request a banner ad to be displayed.
Demand-side partners (DSPs) would place bids for the slot and, if the winner was VastFlux-connected, several scripts would be injected while a static banner image was placed in the slot.
The injected scripts would decrypt the ad configurations, which included a player hidden behind the banner and parameters for additional video players to be stacked. The script would also call to the command-and-control (C&C) server to request details on what to be displayed behind the banner.
The received instructions include both a publisher ID and an app ID that VastFlux would spoof. The size of the ads would also be spoofed and only certain third-party advertising tags were allowed to run inside the hidden video player stack.
What Human discovered was that as many as 25 ads could be stacked on top of one another, with the fraudsters receiving payment for all of them, although none would be shown to the user.
Additionally, the cybersecurity firm noticed that new ads would be loaded until the ad slot with the malicious ad code was closed.
“It’s in this capacity that VastFlux behaves most like a botnet; when an ad slot is hijacked, it renders sequences of ads the user can’t see or interact with,” Human notes.
From late June into July 2022, Human attempted to take down the scheme using three mitigation actions, which eventually resulted in the VastFlux traffic being reduced by more than 92%.
The cybersecurity firm says it has identified the fraudsters and worked with the victim organizations to mitigate the fraud, which resulted in the threat actors shutting down their C&C servers.
“As of December 6th, bid requests associated with VastFlux, which reached a peak of 12 billion requests per day, are now at zero,” Human says.
PayPal Warns 35,000 Users of Credential Stuffing Attacks
Online payments system PayPal is alerting roughly 35,000 individuals that their accounts have been targeted in a credential stuffing campaign.
“On December 20, 2022, we confirmed that unauthorized parties were able to access your PayPal customer account using your login credentials,” the company said in the notification letter sent to the impacted individuals.
According to PayPal, between December 6 and 8, 2022, a third party accessed user accounts using login credentials obtained elsewhere. The unauthorized access was eliminated on December 8.
The company says the attackers likely obtained the login credentials via phishing or related nefarious activity, as it found no evidence that the company’s systems were breached.
The attackers, the company says, were able to access and potentially steal personal information from the victim accounts, including names, addresses, phone numbers, birth dates, individual tax identification numbers, and Social Security numbers.
“As of the time of writing, we have no information suggesting that any personal information was misused as a result of this incident, nor have there been unauthorized transactions on the affected accounts,” PayPal told the Maine Attorney General’s Office.
The online payments platform says it reset the passwords for the impacted user accounts and implemented “enhanced security controls to prevent any further unauthorized access”.
“We have not informed law enforcement of this incident, and this notification was not delayed as a result of a law enforcement investigation,” PayPal said.
The company told the Maine Attorney General that a total of 34,942 individuals were impacted in the incident.
In credential stuffing attacks, threat actors use leaked credentials obtained from a third-party source (often purchased on hacker forums) to access user accounts on different services. Such attacks are possible due to the reuse of credentials across multiple services.
Ransomware Revenue Plunged in 2022 as More Victims Refuse to Pay Up: Report
Cybercriminals earned significantly less from ransomware attacks in 2022 compared to 2021 as victims are increasingly refusing to pay ransom demands, according to data from Chainalysis.
A report published by the blockchain data company on Thursday shows that the cryptocurrency addresses known to have been used by ransomware groups received a total of $457 million last year, compared to $766 million in 2021, which represents a drop of more than 40%.
While Chainalysis may not be aware of all addresses used by these cybercrime gangs, it’s clear that ransomware profits have significantly decreased.
On the other hand, the volume of attacks does not seem to have dropped, with thousands of companies being targeted last year and tens of thousands of malware strains used in attacks.
According to data from Coveware, a company that helps organizations respond to ransomware attacks, the percentage of companies that paid up in 2022 dropped to 41%, from 50% in 2021 and 70% in 2020.
There are likely multiple factors that have resulted in fewer companies giving in to the cybercriminals’ extortion demands. One is that in many cases victims could risk violating sanctions if they pay up.
In recent years, after several cities and universities in the United States admitted paying significant ransoms to cybercriminals, the Treasury Department issued warnings to organizations facilitating ransomware payments — such as cyberinsurance companies, financial institutions, and providers of incident response — that they face legal action if the entities they pay are on sanctions lists.
In addition, cyberinsurance companies, which may have had to reimburse their customers for ransomware payments, have made some changes in terms of who they insure and what the insurance covers.
Data backups have also likely played an important role in the drop in ransomware payments. With ransomware attacks making many headlines in the past years, companies are increasingly backing up their data in case it’s encrypted by ransomware.
One noteworthy aspect is that there is a relatively small group of people that profits from ransomware attacks.
Chainalysis has pointed out that while there appears to be an increasing number of ransomware groups, in reality, the members of these groups likely overlap in many cases.
“We’ve seen time and time again that many affiliates carry out attacks for several different strains. So, while dozens of ransomware strains may technically have been active throughout 2022, many of the attacks attributed to those strains were likely carried out by the same affiliates,” the company noted.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Ransomware Shuts Hundreds of Yum Brands Restaurants in UK
A ransomware attack forced the parent company of KFC and Taco Bell to close several hundred restaurants in the United Kingdom this week.
A government filing posted Thursday says the attack impacted information technology systems. Yum Brands said the attackers took company data, but that there is no evidence customer data was stolen.
Around 300 U.K. stores were closed for one day but are now operational, Yum said. There are more than 1,000 KFC and Taco Bell outlets in the UK and Ireland, according to company websites, yet it did not divulge which brands were impacted.
Ransomware is used to hold a target’s data hostage until the attacker is paid, though it is not known if Yum paid any money in this case. Yum Brands Inc., based in Louisville, Kentucky, did not immediately respond to requests for comment from The Associated Press Thursday.
The UK was the European country most targeted by observed ransomware attacks last month with 21, with Germany No. 2 with 11, according to the cybersecurity firm NCC Group.
The company said it alerted law enforcement and hired cybersecurity professionals to conduct an investigation. The company also took some systems offline and installed enhanced monitoring technology.
Yum said it’s not aware of any other restaurant disruptions due to the attack and doesn’t expect the closures to have a material impact on its business.
Ransomware attacks have hit food companies before. In 2021, Brazil-based JBS SA — the world’s largest meat processing company — paid the equivalent of $11 million to hackers who broke into its computer system.