VirusTotal Shares Analysis of 80 Million Ransomware Samples

At least 130 ransomware families were active in 2020 and in the first half of 2021, according to a recent data analysis from Google’s VirusTotal scanning service.

Analysis of more than 80 million potential ransomware-related samples submitted from 140 countries worldwide reveals that GandCrab has been the most active ransomware family hitting Windows systems since the beginning of 2020.

The analyzed samples were grouped by 30,000 clusters of malware, and GandCrab accounted for 6,000, followed by Cerber with nearly 5,000 clusters, and Congur, with roughly 2,500 clusters.

GandCrab remains the leader even when it comes to the number of different samples submitted to VirusTotal, accounting for 78.5% of them. Babuk, which emerged in early 2021 and was used in the attack on Washington DC Metropolitan Police Department, came in second with 7.61 percent of the submitted samples.  

Cerber (with 3.11 percent of the samples), Matsnu (2.63 percent), and WannaCry (2.41 percent) rounded up top five. According to Google, WannaCry is likely present on the list because of “a remnant of an old detection that still applies to some current ransomware families,” and not due to a new wave of attacks.

[ Related: Understanding the Cryptocurrency-Ransomware Connection ]

Many of the big ransomware campaigns are short lived, but there’s a constant activity of roughly 100 ransomware families that continues at all times, according to the VirusTotal analysis.

Fresh samples are typically used for new campaigns, with botnets and remote access Trojans (RATs) used as delivery mechanisms. Attackers also use exploits for privilege escalation and for spreading their malware within internal networks.

The VirusTotal analysis also found that most ransomware continues to target Windows systems, as roughly 95 percent of the samples were Windows-based executables or dynamic link libraries (DLLs). Android ransomware accounted for 2 percent of the samples and Google also observed roughly 1 million EvilQuest ransomware samples targeting macOS machines.

In terms of geographical distribution, Israel appears to have been affected the most, with a 600 percent increase in sample submissions compared to the baseline, followed by South Korea and Vietnam, with approximately 150 percent each.

Related: Ransomware Risk Assessment Service Aims to Deflect Attacks

Related: Understanding the Cryptocurrency-Ransomware Connection

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/sQ4robUYQjM/virustotal-shares-analysis-80-million-ransomware-samples




NFT Marketplace OpenSea Patches Flaw Potentially Leading to Cryptocurrency Theft

OpenSea, the world’s largest NFT marketplace, has addressed a security vulnerability that could have allowed hackers to hijack user accounts and empty their crypto wallets with the help of maliciously crafted NFTs (non-fungible tokens).

The issue was discovered by security researchers with Check Point, following complaints from OpenSea users of crypto-theft attempts after receiving and opening free airdropped NFTs.

NFTs are unique and non-interchangeable units of data that can be used to represent easily-reproducible items such as videos, audio and photos as unique items.

The security defect identified by Check Point could not be exploited without user interaction. The malicious NFTs would trigger pop-up messages on which the user had to accept subsequent operations that allowed hackers to grab their account information.

Specifically, the message would request for the user to allow a connection to their cryptocurrency wallet. With such pop-ups common on OpenSea for other activities, users would likely confirm the connection without too much pondering.

Thus, the victim believed they were enabling action on the received gifted NFT, but they were in fact providing the hackers with access to their wallet.

Subsequently, the hackers could initiate a fraudulent transaction from the victim’s wallet to an attacker-controlled wallet, which would trigger another pop-up message from OpenSea’s storage domain.

Should the victim accept the transaction without noticing what it was all about, their wallets would have been emptied.

It’s worth noting that the vulnerability was identified during the cybersecurity firm’s investigation into reports of wallet thefts, but this does not appear to be the flaw leveraged in those attacks.

Check Point says they informed OpenSea of the discovered security hole on September 26 and that the platform addressed the issue within an hour after receiving the report.

“These attacks would have relied on users approving malicious activity through a third-party wallet provider by connecting their wallet and providing a signature for the malicious transaction. We have been unable to identify any instances where this vulnerability was exploited,” OpenSea said.

Users are advised to carefully check all of the pop-up messages they receive and what is requested from them, to identify suspicious requests and reject them.

In August 2021, OpenSea recorded $3.4 billion in transaction volume.

Related: New ‘Hildegard’ Malware Targets Kubernetes Systems

Related: Sophos: Crypto-Jacking Campaign Linked to Iranian Company

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/kfYVjRpR1Jg/nft-marketplace-opensea-patches-flaw-potentially-leading-cryptocurrency-theft




Microsoft Adds Power Platform to Bug Bounty Program

Microsoft this week announced that it is now accepting vulnerability submissions for the Power Platform.

Security researchers who hunt for and report security errors in Power Platform can now earn up to $20,000 in bounty rewards for severe flaws, as part of the recently rebranded Dynamics 365 and Power Platform Bounty Program.

“Through this expanded program, we encourage researchers to discover and report high impact security vulnerabilities they may find in the new Power Platform scope to help protect customers,” Microsoft announced.

Power Platform products in scope of the bug bounty program include Power Apps, Power Automate, Power Virtual Agent, and Power Portals.

Dynamics 365 applications in scope include a broad range of online applications, as well as various on-premises products, as detailed on the program’s page.

Microsoft is willing to hand out payouts ranging between $500 and $20,000 for vulnerabilities identified in these products, depending on their impact.

Researchers may receive the highest bounty rewards for remote code execution bugs that feature a critical severity, while elevation of privilege and information disclosure issues may be awarded up to $8,000 in rewards.

“A high-quality report provides the information necessary for an engineer to quickly reproduce, understand, and fix the issue. This typically includes a concise write up or video containing any required background information, a description of the bug, and a proof of concept (PoC),” Microsoft explains.

The tech giant says it will grow the Dynamics 365 and Power Platform Bounty Program as it identifies new areas that are deemed eligible for rewards.

Related: Microsoft Adds Teams Mobile Applications to Bug Bounty Program

Related: Microsoft Paid Out $13.6 Million in Bug Bounties in Past Year

Related: Microsoft Pays $50,000 Bounty for Account Takeover Vulnerability

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/8wELgEclAig/microsoft-adds-power-platform-bug-bounty-program




Necro Python Botnet Starts Targeting Visual Tools DVRs

Security researchers have spotted signs of the Necro Python botnet targeting a vulnerability in Visual Tools DVR systems to install a Monero miner on infected systems.

First discovered in January this year, Necro Python is also tracked as N3Cr0m0rPh, FreakOut, Python.IRCBot and is known for attempting to exploit multiple known vulnerabilities.

In late September, the botnet added to its arsenal an exploit targeting a security vulnerability in Visual Tools DVR VX16 4.2.28.0, according to a warning from Juniper Threat Labs.

Based on Python, the botnet includes a broad range of capabilities, including the ability to sniff network traffic, launch distributed denial of service attacks, infect different types of files (HTML, JS, PHP), install a Monero miner, execute commands, and spread using exploits or brute-forcing.

What’s more, although it emerged in January as a piece of malware targeting Linux systems, the script can run on Windows systems as well and can install a Windows rootkit.

“The script has its own polymorphic engine to morph itself every execution which can bypass signature-based defenses. This works by reading every string in its code and encrypting it using a hardcoded key,” the researchers explain.

[ READ: New ‘FreakOut’ Malware Ensnares Linux Devices Into Botnet ]

The botnet uses a Domain Generation Algorithm (DGA) for both its command and control (C&C) and download server. Once connected to the C&C, it can scan IPs, add/remove ports from the scanner, launch a reverse shell, execute files, kill processes, update itself, launch UDP/SYN/TCP floods, launch amplification/reflection attacks, and more.

Since January, the botnet has received several updates, including the implementation of new exploits and the addition/removal of features (a SMB scanner observed in May has been removed in the latest version).

The latest exploit added to its arsenal is based on proof-of-concept code that was made publicly available in July 2021. Prior to launching the attack, the malware scans for open ports 22, 80, 443, 8081, 8081, and 7001.

Related: New ‘FreakOut’ Malware Ensnares Linux Devices Into Botnet

Related: ‘PGMiner’ Crypto-Mining Botnet Abuses PostgreSQL for Distribution

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/VWZnd53QtDw/necro-python-botnet-starts-targeting-visual-tools-dvrs




OpenSSF Bags $10 Million Investment

The Linux Foundation has secured a new $10 million investment that will help  expand and support the Open Source Security Foundation (OpenSSF).

The funding will help OpenSSF focus on identifying and addressing security vulnerabilities in open source software, thus securing the software supply chain. The foundation is also working on the development of best practices, tooling, training, and vulnerability disclosure practices.

OpenSSF received financial help from tech giants such as Amazon, Cisco, Dell, Facebook, Google, Intel, Microsoft, and Oracle. Other organizations committed to helping the cross-industry collaboration include Aiven, Cybertrust Japan, Deepfence, DTCC, GitLab, Tencent, and Wind River, among others.

[ READ: Google Pledges $1 Million to Secure Open Source Program ]

“This pan-industry commitment is answering the call from the White House to raise the baseline for our collective cybersecurity wellbeing, as well as ‘paying it forward’ to open source communities to help them create secure software from which we all benefit,” Jim Zemlin, executive director at the Linux Foundation, said in a statement announcing the investment.

In addition to the funding, OpenSSF announced that open source luminary Brian Behlendorf will serve as its General Manager.

OpenSSF is home to projects such as Scorecards and Best Practices Badge, but is also involved in the development of security policies, a security framework for the software supply chain, training initiatives, vulnerability disclosures, security reviews, and research.

Related: Cisco, Sonatype and Others Join Open Source Security Foundation

Related: Google Pledges $1 Million to Secure Open Source Program

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/oJ_o2EonRV4/openssf-bags-10-million-investment




Intel, VMWare Join Patch Tuesday Parade

Technology giants Intel Corp. and VMWare joined the Patch Tuesday parade this week, rolling out fixes for security defects that expose users to malicious hacker attacks.

Intel released two advisories to fix privilege escalation and information disclosure vulnerabilities in the SGX software development kit and Hardware Accelerated Execution Manager (HAXM) software products.

The more serious of the two flaws — CVE-2021-0186 — affects the Software Guard Extensions (SGX) Software Development Kit (SDK)applications compiled for SGX2-enabled processors and may allow escalation of privilege in certain circumstances.

Intel has tagged the bug with a “high risk” rating and a CVSS Base Score of 8.2 and credited multiple academic institutions with reporting the issue.

[ READ: MS Patch Tuesday: 71 Vulns, One Exploited as Zero-Day ]

The second Intel advisory covers a pair of security vulnerabilities in the Intel Hardware Accelerated Execution Manager (HAXM) software that may allow escalation of privilege or information disclosure.   The HAXM updates are available on Github.

Separately, VMWare released a trio of advisories to warn about security defects in the VMWare vRealize IT operations management platform.

VMWare released patches for an open-redirect flaw in the vRealize Orchestrator product (moderate severity), a CSV injection vulnerability in vRealize Log (medium-severity) and a low-risk SSRF flaw in vRealize Operations product.

The Intel and VMWare updates follow a major Patch Tuesday freight train for October with zero-day fixes from Microsoft and Apple (iOS 15.0.2), and critical updates from Adobe and SAP.

So far in 2021, there have been 73 documented in-the-wild zero day attacks, the majority hitting vulnerable code in products sold by Microsoft, Apple and Google.

Related: MS Patch Tuesday: 71 Vulns, One Exploited as Zero-Day

Related: Adobe Patches Critical Code Execution Vulnerabilities

Related: Microsoft Office Zero-Day Hit in Targeted Attacks 

Related: SAP Patches Critical Vulnerabilities in Environmental Compliance

view counter

http://feedproxy.google.com/~r/securityweek/~3/m1K9mpSYspA/intel-vmware-join-patch-tuesday-parade




MS Patch Tuesday: 71 Vulns, One Exploited as Zero-Day

The Microsoft Patch Tuesday freight train for October rolled in with fixes for at least 71 security defects in Windows products and components and an urgent warning about a newly discovered zero-day cyberespionage campaign.

The Redmond, Wash. software maker confirmed in-the-wild exploitation of one of the patched bugs — CVE-2021-40449 — in an exploit chain discovered and reported by malware hunters at Kaspersky.

Kaspersky separately said the vulnerability was used in a Chinese-speaking cyber-espionage campaign targeting IT companies, diplomatic entities and military and defense contractors.   

Kaspersky researchers Boris Larin and Costin Raiu documented the findings in a blog post on “MysterySnail” and warned that a second information-disclosure vulnerability that was used by the attacker was not fixed. 

“We discovered that it was using a previously unknown vulnerability in the Win32k driver and exploitation relies heavily on a technique to leak the base addresses of kernel modules. We promptly reported these findings to Microsoft. The information disclosure portion of the exploit chain was identified as not bypassing a security boundary, and was therefore not fixed,” the Kaspersky researchers said.

[ READ: Microsoft Raises Alarm for New Windows Zero-Day Attacks ]

Kaspersky described the issue as a use-after-free vulnerability in the Win32k’s NtGdiResetDC function and said it was intercepted by anti-exploit technologies built into its security product lines..

Microsoft slapped an “important” rating on the flaw and warned that it introduced elevation of privilege risks on unpatched Windows systems.

In total, Redmond shipped patches for 71 documented security vulnerabilities in the flagship Windows OS, the Chromium-based Edge browser, Microsoft Exchange, Microsoft Office Services and SharePoint Server.

Two of the 71 documented vulnerabilities are rated “critical,” Microsoft’s highest severity rating.

Security professionals are urging Windows fleet administrators to pay attention to CVE-2021-26427, a remote code execution flaw in Exchange Server that was reported by the U.S. government’s National Security Agency (NSA).

[ READ: Apple Confirms iOS 15 Zero-Day Exploitation ]

The Microsoft patches come one day after Apple rushed out an urgent iOS mobile platform patch to address a software flaw being “actively exploited” in the wild.

The Cupertino, Calif. device maker confirmed the latest zero-day in an advisory and urged iOS and iPad users to upgrade to the newest iOS 15.0.2.

So far in 2021, there have been 73 documented in-the-wild zero day attacks, the majority hitting vulnerable code in products sold by Microsoft, Apple and Google.

Related: Microsoft Office Zero-Day Hit in Targeted Attacks 

Related: Apple Confirms New Zero-Day Attacks on Older iPhones

Related: Google: Sophisticated APT Group Burned 11 Zero-Days

Related: Apple Ships Urgent Patch for FORCEDENTRY Zero-Days

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/kIOT5bz8J_E/ms-patch-tuesday-71-vulns-one-exploited-zero-day




Adobe Patches Critical Code Execution Vulnerabilities in Several Products

Adobe on Tuesday announced that it has patched a total of 10 vulnerabilities across its Acrobat and Reader, Connect, Commerce, and Campaign Standard products.

Adobe has patched four vulnerabilities in Acrobat and Reader for Windows and macOS. Two of the flaws, described as use-after-free and out-of-bounds issues, have been classified as critical and they can lead to arbitrary code execution in the context of the current user. The other two are moderate-severity flaws that can be exploited for privilege escalation.

In Reader for Android, the company fixed an important-severity issue that could lead to information disclosure and arbitrary code execution.

In Adobe Campaign Standard for Windows and Linux, the software giant addressed a critical cross-site scripting (XSS) bug. An XSS flaw was also patched in Connect, along with a critical code execution vulnerability related to deserialization of untrusted data.

A critical deserialization issue has also been resolved in Adobe ops-cli, an open source Python wrapper used internally by the company.

An XSS vulnerability has also been fixed in Adobe’s Commerce product. This is a stored XSS and it can be exploited without authentication, but the company only assigned it an important severity rating.

None of these vulnerabilities appears to have been exploited in attacks, and since they all have priority ratings of 2 or 3, Adobe believes they are unlikely to be leveraged by malicious actors in their operations.

Related: Adobe Warns of Critical Flaws in Magento, Connect

Related: Decade-Old Adobe ColdFusion Vulnerabilities Exploited by Ransomware Gang

Related: Adobe Patches 21 Vulnerabilities Across Seven Products

Related: Adobe: Critical Flaws in Reader, Acrobat, Illustrator

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/GHu8bBZ8Cag/adobe-patches-critical-code-execution-vulnerabilities-several-products




CISO Forum Panel: Navigating SBOMs and Supply Chain Security Transparency

At SecurityWeek’s 2021 CISO Forum, a high-powered panel of experts  discussed specific ways an SBOM can improve supply chain security and where expectations may be overblown.  The conversation covers edge cases that are turning out to be more troublesome than anticipated and what might come next after SBOM and where there are opportunities for innovation (e.g., new tooling or standards) on top of SBOMs.

[embedded content]

Speakers:

• Allan Friedman, SBOM Champion at U.S. Cybersecurity and Infrastructure Security Agency (CISA)

• Sounil Yu, CISO at JupiterOne

• Steve Springett, Chair at CycloneDX Core Working Group.

view counter

Previous Columns by SecurityWeek News:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/j4jYQRyzdis/ciso-forum-panel-navigating-sboms-and-supply-chain-security-transparency




ICS Patch Tuesday: Siemens and Schneider Electric Address Over 50 Vulnerabilities

Industrial giants Siemens and Schneider Electric on Tuesday released nearly a dozen security advisories describing a total of more than 50 vulnerabilities affecting their products.

The companies have released patches and mitigations to address these vulnerabilities.

Siemens

Siemens has released 5 new advisories covering 33 vulnerabilities. The company informed customers that an update for its SINEC network management system patches 15 flaws, including ones that can be exploited for arbitrary code execution. While some of them have been assigned a high severity rating, exploitation requires authentication.

For its ​​SCALANCE W1750D controller-based direct access points, Siemens released patches and mitigations covering 15 vulnerabilities, including critical weaknesses that can allow a remote, unauthenticated attacker to cause a DoS condition or execute arbitrary code on the underlying operating system. The W1750D is a brand-labeled device from Aruba, and a majority of the flaws exist in the ArubaOS operating system.

The company has also informed customers about a critical authentication vulnerability in the SIMATIC Process Historian. An attacker can exploit the flaw to insert, modify or delete data.

The two remaining advisories address high-severity denial of service (DoS) vulnerabilities in SINUMERIK controllers and RUGGEDCOM ROX devices. In the case of the RUGGEDCOM devices, an unauthenticated attacker could cause a permanent DoS condition in certain circumstances.


Schneider Electric

Schneider Electric has released 6 new advisories covering 20 vulnerabilities. One advisory describes the impact of 11 Windows flaws on the company’s Conext solar power plant products. The security holes were patched by Microsoft in 2019 and 2020 and many of them have critical or high severity ratings.

Another advisory describes two critical, one high-severity and one medium-severity vulnerabilities affecting Schneider’s IGSS SCADA system. The company says the worst case exploitation scenario “could result in an attacker gaining access to the Windows Operating System on the machine running IGSS in production.”

The company also informed users about a high-severity information disclosure vulnerability affecting spaceLYnk, Wiser For KNX, and fellerLYnk products, and a high-severity command execution issue in the ConneXium network manager software.

The last advisory describes the impact of two AMNESIA:33 vulnerabilities on Modicon TM5 modules. AMNESIA:33 is the name assigned to 33 flaws identified last year across four open source TCP/IP stacks.

Related: ICS Patch Tuesday: Siemens and Schneider Electric Address 100 Vulnerabilities

Related: ICS Patch Tuesday: Siemens, Schneider Electric Address Over 40 Vulnerabilities

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/wUDrf3lqKCQ/ics-patch-tuesday-siemens-and-schneider-electric-address-over-50-vulnerabilities