Website of Canadian Liquor Distributor LCBO Infected With Web Skimmer

Canadian liquor distributor Liquor Control Board of Ontario (LCBO) has announced that a web skimmer injected into its online store was used to steal users’ personal data.

One of the largest liquor sellers in Canada, LCBO retails and distributes alcoholic beverages throughout the Ontario province, operating over 670 stores and employing more than 8,000 people.

Last week, the company abruptly took offline its online store and mobile application, only to later explain that it fell victim to a cyberattack in which a web skimmer was injected into LCBO.com.

“At this time, we can confirm that an unauthorized party embedded malicious code into our website that was designed to obtain customer information during the checkout process,” the retailer said.

According to LCBO, all individuals who provided their personal information on the online store’s check-out pages and made payments between January 5 and 10, 2023, are impacted.

The compromised personal information, the company says, includes names, addresses, email addresses, LCBO.com account passwords, Aeroplan numbers, and credit card information.

“This incident did not affect any orders placed through our mobile app or vintagesshoponline.com,” the company said.

The company did not share information on the number of impacted customers, but said that it disabled customer access to both the online store and mobile app as a precautionary measure, and that it also forced a password reset for all user accounts.

“LCBO.com and our mobile app have been restored and are fully operational. We have also reset all LCBO.com account passwords. Registered customers will be prompted to reset their password on login,” the company said.

Web skimmer attacks, also referred to as Magecart attacks, are typically the result of a misconfiguration or unpatched vulnerabilities that allow threat actors to inject information stealer malware into a website and harvest the information of unsuspecting users.

Magecart attacks have been around for years, with multiple groups operating under the umbrella and hundreds of online stores compromised to date. In 2019, a free service called URLscan.io was made available to help customers and retailers alike check for the presence of web skimmers.

Related: Hundreds of eCommerce Domains Infected With Google Tag Manager-Based Skimmers

Related: Target Open Sources Web Skimmer Detection Tool

Related: Web Skimmer Injected Into Hundreds of Magento-Powered Stores

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/website-canadian-liquor-distributor-lcbo-infected-web-skimmer




Tesla Returns as Pwn2Own Hacker Takeover Target

Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to complete vehicle compromise.

Tesla, in tandem with Pwn2Own organizations Zero Day Initiative, is offering a $600,000 cash prize to any hacker capable of writing exploits that pivot through multiple systems in the car to gain arbitrary code execution.

“Success here gets a big payout and, of course, a brand-new Tesla,” contest organizers announced Thursday.

This isn’t the first time Tesla has sought to attract the attention of advanced exploit writers at Pwn2Own. Back in 2019, the company gave away a Tesla Model 3 to a pair of researchers demonstrating successful exploits and this year the organizers plan to raise the level of complexity of what constitutes a successful car-hacking exploit.

Hackers can register an entry against either a Tesla Model 3 (Intel or Ryzen-based) or the Tesla Model S (Ryzen-based).

This year, the organizers are looking for exploits targeting Tesla’s Tuner, Wi-Fi, Bluetooth or Modem components.  Hackers must demonstrate a successful intermediate pivot to the vehicle’s infotainment system and execute code against VCSEC, Gateway or Autopilot.

In addition to the vehicle itself and $500,000, contestants can go for the additional options to raise the payout to $600,000. “This represents the single largest target in Pwn2Own history,” conference organizers said in a note posted Thursday.

Organizers believe a complete vehicle takeover exploit is a tough undertaking. “It’s difficult to express the complexity of completing such a demonstration, but we’re certainly hopeful that someone can show off their exploit skills and drive off a winner.”

Pwn2Own is also offering cash prizes ranging from $250,000 to $400,000 to entice attackers to showcase exploits pivoting through some of the vehicle’s sub-systems. “This level requires the contestant to get arbitrary code execution on two different sub-systems in the vehicle, which is certainly a difficult challenge.”

Pwn2Own also announced the addition of a Steam VM Escape category with both a Tesla Model 3 and a Tesla Model S available as targets.

The annual hacker contest will also offer prizes for exploits for VMWare virtual machine escapes, attacks against Microsoft DNS Server and ISC BIND, and exploits for enterprise collaboration tools Zoom and Microsoft Teams.

Related: Pwn2Own 2019: Researchers Win Tesla After Hacking Its Browser 

Related: $200,000 Awarded for Zoom Zero-Click Zoom Exploit at Pwn2Own

Related: Over $1.1 Million Awarded at Pwn2Own 2022 for 25 Zero-Day Vulns

Related: ICS Exploits Earn Hackers $400,000 at Pwn2Own Miami 2022

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series.
Ryan is a veteran cybersecurity strategist who has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s past career as a security journalist included bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

https://www.securityweek.com/tesla-returns-pwn2own-hacker-takeover-target




ChatGPT is enabling script kiddies to write functional malware

OpenAI logo displayed on a phone screen and ChatGPT website displayed on a laptop screen.
Getty Images

Since its beta launch in November, AI chatbot ChatGPT has been used for a wide range of tasks, including writing poetry, technical papers, novels, and essays, planning parties, and learning about new topics. Now we can add malware development and the pursuit of other types of cybercrime to the list.

Researchers at security firm Check Point Research reported Friday that within a few weeks of ChatGPT going live, participants in cybercrime forums—some with little or no coding experience—were using it to write software and emails that could be used for espionage, ransomware, malicious spam, and other malicious tasks.

“It’s still too early to decide whether or not ChatGPT capabilities will become the new favorite tool for participants in the Dark Web,” company researchers wrote. “However, the cybercriminal community has already shown significant interest and are jumping into this latest trend to generate malicious code.”

Last month, one forum participant posted what they claimed was the first script they had written and credited the AI chatbot with providing a “nice [helping] hand to finish the script with a nice scope.”

A screenshot showing a forum participant discussing code generated with ChatGPT.
Enlarge / A screenshot showing a forum participant discussing code generated with ChatGPT.
Check Point Research

The Python code combined various cryptographic functions, including code signing, encryption, and decryption. One part of the script generated a key using elliptic curve cryptography and the curve ed25519 for signing files. Another part used a hard-coded password to encrypt system files using the Blowfish and Twofish algorithms. A third used RSA keys and digital signatures, message signing, and the blake2 hash function to compare various files.

The result was a script that could be used to (1) decrypt a single file and append a message authentication code (MAC) to the end of the file and (2) encrypt a hardcoded path and decrypt a list of files that it receives as an argument. Not bad for someone with limited technical skill.

“All of the afore-mentioned code can of course be used in a benign fashion,” the researchers wrote. “However, this script can easily be modified to encrypt someone’s machine completely without any user interaction. For example, it can potentially turn the code into ransomware if the script and syntax problems are fixed.”

In another case, a forum participant with a more technical background posted two code samples, both written using ChatGPT. The first was a Python script for post-exploit information stealing. It searched for specific file types, such as PDFs, copied them to a temporary directory, compressed them, and sent them to an attacker-controlled server.

Screenshot of forum participant describing Python file stealer and including the script produced by ChatGPT.
Enlarge / Screenshot of forum participant describing Python file stealer and including the script produced by ChatGPT.
Check Point Research

The individual posted a second piece of code written in Java. It surreptitiously downloaded the SSH and telnet client PuTTY and ran it using Powershell. “Overall, this individual seems to be a tech-oriented threat actor, and the purpose of his posts is to show less technically capable cybercriminals how to utilize ChatGPT for malicious purposes, with real examples they can immediately use.”

A screenshot describing the Java program, followed by the code itself.
Enlarge / A screenshot describing the Java program, followed by the code itself.
Check Point Research

Yet another example of ChatGPT-produced crimeware was designed to create an automated online bazaar for buying or trading credentials for compromised accounts, payment card data, malware, and other illicit goods or services. The code used a third-party programming interface to retrieve current cryptocurrency prices, including monero, bitcoin, and etherium. This helped the user set prices when transacting purchases.

Screenshot of a forum participant describing marketplace script and then including the code.
Enlarge / Screenshot of a forum participant describing marketplace script and then including the code.
Check Point Research

Friday’s post comes two months after Check Point researchers tried their hand at developing AI-produced malware with full infection flow. Without writing a single line of code, they generated a reasonably convincing phishing email:

A phishing email generated by ChatGPT.
Enlarge / A phishing email generated by ChatGPT.
Check Point Research

The researchers used ChatGPT to develop a malicious macro that could be hidden in an Excel file attached to the email. Once again, they didn’t write a single line of code. At first, the outputted script was fairly primitive:

Screenshot of ChatGPT producing a first iteration of a VBA script.
Screenshot of ChatGPT producing a first iteration of a VBA script.
Check Point Research

When the researchers instructed ChatGPT to iterate the code several more times, however, the quality of the code vastly improved:

A screenshot of ChatGPT producing a later iteration.
Enlarge / A screenshot of ChatGPT producing a later iteration.
Check Point Research

The researchers then used a more advanced AI service called Codex to develop other types of malware, including a reverse shell and scripts for port scanning, sandbox detection, and compiling their Python code to a Windows executable.

“And just like that, the infection flow is complete,” the researchers wrote. “We created a phishing email, with an attached Excel document that contains malicious VBA code that downloads a reverse shell to the target machine. The hard work was done by the AIs, and all that’s left for us to do is to execute the attack.”

While ChatGPT terms bar its use for illegal or malicious purposes, the researchers had no trouble tweaking their requests to get around those restrictions. And, of course, ChatGPT can also be used by defenders to write code that searches for malicious URLs inside files or query VirusTotal for the number of detections for a specific cryptographic hash.

So welcome to the brave new world of AI. It’s too early to know precisely how it will shape the future of offensive hacking and defensive remediation, but it’s a fair bet that it will only intensify the arms race between defenders and threat actors.

https://arstechnica.com/?p=1908471




Il business dei ransomware continuerà a evolversi


Il business del ransomware sta per evolversi di nuovo e questa volta in maniera più profonda. I gruppi di cybercriminali hanno creato una vera e propria industria che, di fronte alle risposte di organizzazioni e governi, potrebbe rivoluzionarsi ancora per far fronte alle nuove sfide.

Trend Micro ha elaborato una ricerca in cui analizza i possibili scenari di evoluzione delle minacce in relazione alle risposte della sicurezza. I gruppi criminali continueranno a modificare i propri scopi e schemi di attacco per rispondere alle nuove strategie di difesa e ai cambiamenti socio-economici mondiali.

business ransomware

L’azienda di sicurezza ha individuato tre trigger che potrebbero portare a un’evoluzione dei ransomware, se non a un profondo cambiamento del business degli attacchi:

  • aumento di leggi e sanzioni contro i gruppi criminali: se le campagne di arresti si riveleranno sempre più proficue, i criminali alzeranno l’attenzione e svilupperanno attacchi più aggressivi;
  • più norme per le criptovalute: l’aumento della popolarità delle cryptocurrency ha permesso ai cybercriminali di effettuare trasferimenti di denaro cross-border in totale anonimato. La volontà dei governi è di aumentare i controlli su criptovalute, trasferimenti e riciclaggio di denaro, spingendo così i gruppi criminali a spostarsi su altre attività;
  • molti gruppi criminali hanno sofferto di alcune falle nelle loro operazioni che hanno permesso ai team di sicurezza di infiltrarsi e raccogliere dati sulle loro campagne. Ciò ha portato a indagini fruttuose e alla cattura di numerosi criminali; breach di questo genere spingono i gruppi dietro i ransomware a rivedere il proprio modello di business ed evolversi.

Di fronte a questi cambiamenti i gruppi criminali possono evolversi e rivoluzionarsi per abbracciare nuovi modelli di business e nuove tecniche per lo sfruttamento dei dati delle vittime. Il business dei rainsomware potrà andare incontro a cambiamenti piccoli e grandi e modificare il proprio modello di attacco:

  • monetizzazione dei dati esfiltrati: il guadagno economico può arrivare non solo dal riscatto, ma anche dal valore dei dati ottenuti. I gruppi criminali potrebbero collaborare con data miners e altri cyberattaccanti per sfruttare il valore finanziario e strategico delle informazioni cifrate;
  • attacchi ad ambienti cloud: il cloud computing è la tecnologia del futuro e sempre più realtà stanno migrando verso una nuova architettura. I cybercriminali si evolveranno di conseguenza, migliorando le proprie conoscenze e affinando le tecniche per muoversi in un ambiente “nuovo”;
  • creazione di team di ricerca e penetration testing: molti gruppi potrebbero investire su team di penetration testing per analizzare la rete della vittima e identificare i possibili punti di accesso, o persino definire team di ricerca per trovare falle nei prodotti e vendere l’informazione ad altri gruppi;
    business ransomware
  • hacker al servizio dei governi: il conflitto attuale ci ha insegnato che i gruppi criminali potrebbero, nel prossimo futuro, essere reclutati dai governi in cambio di protezione;
  • manipolazione del mercato azionario: i cybercriminali possono sfruttare gli accessi alle reti delle organizzazioni per ottenere informazioni sensibili o identificare falle del sistema. A quel punto i criminali possono decidere di attaccare i sistemi e rendere nota l’operazione, causando una diminuzione del valore delle azioni e una conseguente perdita di denaro per l’azienda;
  • attacchi a supply chain: tutte le organizzazioni usano l’outsourcing per software e specifici task. Gli attaccanti possono compromettere l’intera catena di approvvigionamento per colpire più vittime a partire dal fornitore, distribuendo aggiornamenti software malevoli.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/12/22/ransomware-business-evoluzione/?utm_source=rss&utm_medium=rss&utm_campaign=ransomware-business-evoluzione




Malware QBot distribuito tramite immagini SVG


Cisco Talos ha individuato diverse campagne di phishing che usano immagini SVG per distribuire il malware QBot. I file sono integrati negli allegati HTML delle email che, una volta aperti, eseguono codice malevolo.

La tecnica, chiamata “HTML smuggling”, sfrutta le feature di HTML5  e Javascript per eseguire script malevoli quando l’utente apre l’allegato e naviga nella pagina web. Non appena il browser apre il file .html, decodifica anche lo script che assembla il payload sul dispositivo della vittima. Questa tecnica permette di “creare” il malware direttamente sulla macchina, senza inviarlo via rete col rischio che venga bloccato dal firewall o da altri strumenti di protezione.

QBot malware

Nel caso del malware QBot, i file HTML contengono un tag SVG all’interno del quale è presente uno script, una funzionalità del tutto legittima del tag, in grado di creare un archivio .zip e proporre all’utente una finestra di dialogo per scaricarlo. Una volta effettuato il download, si richiede all’utente di inserire una password, contenuta nella mail, per estrarre i file; dopo l’estrazione lo script esegue un’immagine ISO che assembla il trojan Qbot.

Questo malware, conosciuto anche come Qakbot, sottrae le credenziali di accesso ai servizi di banking, permettendo agli attaccanti di avere completo accesso ai conti correnti delle vittime. Le varianti precedenti erano in grado di monitorare la navigazione dell’utente e registrare le informazioni inserite nei form di accesso.

QBot malware

Il malware inoltre ottiene il controllo dell’email della vittima ed è in grado di rispondere a thread esistenti per tentare la distribuzione su altre macchine. Generalmente riprende thread di mail vecchi, risalenti anche a 1 o 2 anni precedenti: questo va visto come un campanello d’allarme nel caso si ricevano email con allegati sospetti.

Gli attacchi di HTML smuggling sono più frequenti di ciò che si pensa: gli allegati .html e .htm sono gli allegati tra i più usati dagli attaccanti, dopo le immagini .jpg.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/12/16/malware-qbot-immagini-svg/?utm_source=rss&utm_medium=rss&utm_campaign=malware-qbot-immagini-svg




Microsoft digital certificates have once again been abused to sign malware

A low-angle view on a blue digital key made to resemble a circuit and placed on a surface with encrypted text.
Getty Images

Microsoft has once again been caught allowing its legitimate digital certificates to sign malware in the wild, a lapse that allows the malicious files to pass strict security checks designed to prevent them from running on the Windows operating system.

Multiple threat actors were involved in the misuse of Microsoft’s digital imprimatur, which they used to give Windows and endpoint security applications the impression malicious system drivers had been certified as safe by Microsoft. That has led to speculation that there may be one or more malicious organizations selling malicious driver-signing as a service. In all, researchers have identified at least nine separate developer entities that abused the certificates in recent months.

The abuse was independently discovered by four third-party security companies, which then privately reported it to Microsoft. On Tuesday, during Microsoft’s monthly Patch Tuesday, the company confirmed the findings and said it has determined the abuse came from several developer accounts and that no network breach has been detected.

The software maker has now suspended the developer accounts and implemented blocking detections to prevent Windows from trusting the certificates used to sign the compromised certificates. “Microsoft recommends that all customers install the latest Windows updates and ensure their anti-virus and endpoint detection products are up to date with the latest signatures and are enabled to prevent these attacks,” company officials wrote.

Code-signing primer

Because most drivers have direct access to the kernel—the core of Windows where the most sensitive parts of the OS reside—Microsoft requires them to be digitally signed using a company internal process known as attestation. Without this digital signature, Windows won’t load the driver. Attestation has also become a de facto means for third-party security products to decide if a driver is trustworthy. Microsoft has a separate driver validation process known as the Microsoft Windows Hardware Compatibility Program, in which the drivers run various additional tests to ensure compatibility.

To get drivers signed by Microsoft, a hardware developer first must obtain an extended validation certificate, which requires the developer to prove its identity to a Windows trusted certificate authority and provide additional security assurances. The developer then attaches the EV certificate to their Windows Hardware Developer Program account. Developers then submit their driver package to Microsoft for testing.

Researchers from SentinelOne, one of three security firms that discovered the certificate misuse and privately reported it to Microsoft, explained:

The main issue with this process is that most security solutions implicitly trust anything signed by only Microsoft, especially kernel mode drivers. Starting with Windows 10, Microsoft began requiring all kernel mode drivers to be signed using the Windows Hardware Developer Center Dashboard portal. Anything not signed through this process is not able to load in modern Windows versions. While the intent of this new requirement was to have stricter control and visibility over drivers operating at the kernel level, threat actors have realized if they can game the process they would have free rein to do what they want. The trick however, is to develop a driver that doesn’t appear to be malicious to the security checks implemented by Microsoft during the review process.

Mandiant, another security firm to discover the abuse, said that “several distinct malware families, associated with distinct threat actors, have been signed through the Windows Hardware Compatibility Program.” Company researchers identified at least nine organization names abusing the program. Besides somehow gaining access to Microsoft certificates, the threat actors also managed to obtain EV certificates from third-party certificate authorities.

https://arstechnica.com/?p=1904163




Aikido wiper sfrutta gli antivirus per cancellare i dati


Or Yair, un ricercatore di SafeBreach, ha ideato una tecnica per sfruttare le funzioni degli antivirus o delle soluzioni Edr installate nel sistema per agire come un data wiper, una categoria di malware che elimina o distrugge i dati con lo scopo di danneggiare la vittima.Il ricercatore ha avuto l’idea di sfruttare le funzioni di protezione offerte dagli strumenti di sicurezza, che spesso agiscono preventivamente individuando ed eliminando i file che considerano pericolosi.

Questi tool sono infatti sempre attivi e analizzano il filesystem alla ricerca di potenziali pericoli. Il ricercatore ha spiegato che il processo di eliminazione di una minaccia si svolge generalmente in due fasi: prima il tool identifica il pericolo, e poi lo elimina. Yair ha pensato di sfruttare l’intervallo che intercorre tra i due eventi per sostituire il file originale e quindi far agire l’antivirus su dati diversi da quelli rilevati.

Windows esegue senza fare domande

L’antivirus non consente modifiche ai file rilevati prima della cancellazione, ma è stato sufficiente mantenere attivo un handle per evitare il blocco da parte dell’antivirus. Il software di sicurezza non è quindi in grado di cancellare il file e suggerisce il riavvio per completare la pulizia.

Fonte: SafeBreach

Le operazioni da completare al reboot vengono memorizzate in una specifica chiave del registro, che Windows legge al riavvio eseguendo poi le istruzioni senza effettuare nessuna ulteriore verifica.

Seguendo questa strategia, il ricercatore ha creato un tool chiamato Aikido Wiper che ha poi provveduto a testare con 11 strumenti antimalware, con risultati piuttosto preoccupanti: oltre la metà dei software, infatti, è risultato vulnerabile a questa tecnica. L’elenco comprende Microsoft Defender e Defender for Endpoint, SentinelOne, TrendMicro Apex One e gli antivirus di Avast e Avg. Hanno invece resistito le soluzioni di PaloAlto, Cylance, CrowdStrike, McAfee e Bitdefender.

Il problema è stato segnalato ai produttori tra luglio e agosto, e nel frattempo la vulnerabilità è stata risolta con la distribuzione di aggiornamenti per i motori di scansione.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/12/13/aikido-wiper-sfrutta-gli-antivirus-per-cancellare-i-dati/?utm_source=rss&utm_medium=rss&utm_campaign=aikido-wiper-sfrutta-gli-antivirus-per-cancellare-i-dati




Zombinder: malware nascosti in centinaia di app Android


ThreatFabric, un’azienda di sicurezza di Amsterdam, ha individuato Zombinder, una piattaforma della darknet che “lega” i malware ad applicazioni Android legittime per infettare i dispositivi. La vittima veniva infettata senza che se ne accorgesse: le applicazioni potevano essere usate senza particolari problemi, sfruttandone tutte le funzionalità.

Come spiegato nel report stilato da ThreatFabric, le campagne dietro Zombinder sfruttavano i portali per l’accesso al Wi-Fi per distribuire il malware. Queste pagine fake chiedevano all’utente di scaricare un’applicazione per poter procedere e connettersi a internet; questa, però, conteneva il malware.

Zombinder

Il programma installato era in grado di eseguire attacchi di keylogging, sottrarre email da Gmail e codici per la 2-factor authentication e ottenere informazioni sensibili della vittima.

Le vittime non si accorgevano dell’attacco proprio perché le applicazioni scaricate erano legittime. Gli hacker hanno usato un servizio di terze parti disponibile nella darknet per legare i malware alle app originali. Il software originale non veniva rimosso dagli attaccanti: Zombinder appendeva un loader malevolo al codice sorgente. 

Le campagne hanno colpito non solo le applicazioni Android, ma anche quelle per Windows. L’utente, dopo aver navigato sul sito per l’autorizzazione di accesso al Wi-Fi, viene invitato a scaricare un’applicazione che nascondeva in realtà un malware.

Tra i malware desktop spiccavano Erbium Stealer, Laplas Clipper e Aurora Stealer, spesso installati insieme. Il primo è un malware in grado di sottrarre le password, salvate, le informazioni sulle carte di credito, i cookies dei vari browser e i portafogli offline di cryptovalute.

Zombinder

Il secondo, un prodotto piuttosto nuovo nei mercati della darknet, è in grado di sostituire i portafogli di cryptovalute con alcuni controllati dall’attaccante: in questo modo ogni trasferimento di denaro viene effettuato sul portafoglio di quest’ultimo. Infine, Aurora Stealer entra in possesso dei dati mantenuti nei browser, estensioni e applicazioni, comprese quelle per gestire le cryptomonete.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/12/10/zombinder-malware-app-android/?utm_source=rss&utm_medium=rss&utm_campaign=zombinder-malware-app-android




La grande crescita del ransomware mirato


Kaspersky ha rilasciato un nuovo documento di analisi delle minacce in cui sottolinea la notevole crescita degli attacchi ransomware mirati, che sono passati dallo 0,016% allo 0,026% nei primi dieci mesi del 2022 rispetto allo stesso periodo dell’anno precedente.

In termini assoluti si tratta di percentuali piccole rispetto alla enorme massa degli attacchi, ma se si considera che anche il numero complessivo di eventi è cresciuto moltissimo dallo scorso anno, l’incremento percentuale degli attacchi mirati diventa ancora più significativo.

L’ultimo report sul crimeware di Kaspersky rivela come i gruppi criminali stiano continuando a migliorare i loro prodotti: per esempio, il già molto noto gruppo Lockbit ha aggiunto nuove funzioni ai suoi malware, tra cui il supporto di una nuova tecnica di dumping delle credenziali che permette di prendere il controllo del dominio e poi creare una named pipe per resettare le credenziali del sistema operativo.

Nuove varianti e nuove funzioni

I ransomware continuano a proliferare: nel corso dei primi dieci mesi del 2022, l’azienda ha infatti già rilevato oltre 21.400 varianti. Grande attività si è registrata specialmente in agosto, con un numero di nuovi sample individuati che ha sfondato il muro degli 8.000.

Tra le novità individuate da Kaspersky, particolarmente interessante è il malware Play; si tratta di un ransomware altamente offuscato, il cui codice non mostra nessuna somiglianza con altri campioni individuati in precedenza.

Jornt van der Wiel, Security Expert di Kaspersky.

Quello che rende Play particolarmente interessante è la capacità di auto propagarsi. Jornt van der Wiel, Security Expert di Kaspersky, ha dichiarato: “Gli sviluppatori di ransomware tengono d’occhio il lavoro dei concorrenti. Se uno di loro implementa con successo una determinata funzionalità, è molto probabile che anche altri lo facciano. L’auto propagazione del ransomware ne è un chiaro esempio”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/12/09/la-grande-crescita-del-ransomware-mirato/?utm_source=rss&utm_medium=rss&utm_campaign=la-grande-crescita-del-ransomware-mirato




Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices

Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices

Mayors’ offices and courts in Russia are under attack by never-before-seen malware that poses as ransomware but is actually a wiper that permanently destroys data on an infected system, according to security company Kaspersky and the Izvestia news service.

Kaspersky researchers have named the wiper CryWiper, a nod to the extension .cry that gets appended to destroyed files. Kaspersky says its team has seen the malware launch “pinpoint attacks” on targets in Russia. Izvestia, meanwhile, reported that the targets are Russian mayors’ offices and courts. Additional details, including how many organizations have been hit and whether the malware successfully wiped data, weren’t immediately known.

Wiper malware has grown increasingly common over the past decade. In 2012, a wiper known as Shamoon wreaked havoc on Saudi Arabia’s Saudi Aramco and Qatar’s RasGas. Four years later, a new variant of Shamoon returned and struck multiple organizations in Saudi Arabia. In 2017, self-replicating malware dubbed NotPetya spread across the globe in a matter of hours and caused an estimated $10 billion in damage. In the past year, a flurry of new wipers appeared. They include DoubleZero, IsaacWiper, HermeticWiper, CaddyWiper, WhisperGate, AcidRain, Industroyer2, and RuRansom.

Kaspersky said it discovered the attack attempts by CryWiper in the last few months. After infecting a target, the malware left a note demanding, according to Izvestia, 0.5 bitcoin and including a wallet address where the payment could be made.

“After examining a sample of malware, we found out that this Trojan, although it masquerades as a ransomware and extorts money from the victim for ‘decrypting’ data, does not actually encrypt, but purposefully destroys data in the affected system,” Kaspersky’s report stated. “Moreover, an analysis of the Trojan’s program code showed that this was not a developer’s mistake, but his original intention.”

CryWiper bears some resemblance to IsaacWiper, which targeted organizations in Ukraine. Both wipers use the same algorithm for generating pseudo-random numbers that go on to corrupt targeted files by overwriting the data inside of them. The name of the algorithm is the Mersenne Vortex PRNG. The algorithm is rarely used, so the commonality stuck out.

CryWiper shares a separate commonality with ransomware families known as Trojan-Ransom.Win32.Xorist and Trojan-Ransom.MSIL.Agent. Specifically, the email address in the ransom note of all three is the same.

The CryWiper sample Kaspersky analyzed is a 64-bit executable file for Windows. It was written in C++ and compiled using the MinGW-w64 toolkit and the GCC compiler. That’s an unusual choice since it’s more common for malware written in C++ to use Microsoft’s Visual Studio. One possible reason for this choice is that it gives the developers the option of porting their code to Linux. Given the number of specific calls CryWiper makes to Windows programming interfaces, this reason seems unlikely. The more likely reason is that the developer writing the code was using a non-Windows device.

Successful wiper attacks often take advantage of poor network security. Kaspersky advised network engineers to take precautions by using:

  • Behavioral file analysis security solutions for endpoint protection.
  • Managed detection and response and security operation center that allow for timely detection of an intrusion and take action to respond.
  • Dynamic analysis of mail attachments and blocking of malicious files and URLs. This will make email attacks, one of the most common vectors, more difficult.
  • Conducting regular penetration testing and RedTeam projects. This will help to identify vulnerabilities in the organization’s infrastructure, protect them, and thereby significantly reduce the attack surface for intruders.
  • Threat data monitoring. To detect and block malicious activity in a timely manner, it is necessary to have up-to-date information about the tactics, tools, and infrastructure of intruders.

Given Russia’s invasion of Ukraine and other geopolitical conflicts raging around the globe, the pace of wiper malware isn’t likely to slow in the coming months.

“In many cases, wiper and ransomware incidents are caused by insufficient network security, and it is the strengthening of protection that should be paid attention to,” Friday’s Kaspersky report stated. “We assume that the number of cyberattacks, including those using wipers, will grow, largely due to the unstable situation in the world.”

https://arstechnica.com/?p=1901752