Saturday, 13 May 2017

WannaCry : The Largest Ransomware Infection in History

The IT systems of around 40 NHS organizations across the UK have been affected by a ransomware attack. Non-emergency operations have been suspended and ambulances are being diverted as a result of the attack.

Whoever is behind this ransomware has invested heavy resources into Wannacry's operations. In the few hours this ransomware has been active, it has made many high-profile victims all over the world. According to Avast security researcher Jakub Kroustek, WannaCry made over 57,000 victims in just a few hours.


The ransomware's name is WCry, but is also referenced online under various names, such as WannaCry, WannaCrypt0r, WannaCrypt, or Wana Decrypt0r. As everybody keeps calling it but all are the same thing, which is version 2.0 of the lowly and unimpressive WCry ransomware that first appeared in March.

Let's have a look at WannaCry:

WannaCry is believed to use the EternalBlue exploit, which was allegedly developed by the U.S. National Security Agency to attack computers running Microsoft Windows operating systems. Although a patch to remove the underlying vulnerability had been issued on March 14, 2017, delays in applying security updates left some users and organisations vulnerable. A public exploit for this vulnerability had been released in April by a group subbed as ShadowBrokers while leaking files containing offensive tools belonging to the NSA including a remote SMB exploit called ETERNALBLUE which affects the above vulnerability.

On 12 May 2017, WannaCry began affecting computers worldwide. After gaining access to the computers, the ransomware encrypts the computer's hard disk drive, then attempts to exploit the SMB vulnerability to spread to random computers on the Internet, and "laterally" between computers on the same LAN.

The Windows vulnerability is not a zero-day flaw, but one for which Microsoft had made available a security patch on 14 March 2017 – almost exactly two months before. The patch was to the Server Message Block (SMB) protocol used by Windows. Microsoft has also been urging people to stop using old SMB1 protocol and use new, secure SMB3 protocol instead.

Organizations that lacked this security patch were affected for this reason, also any organization still running the end-of-life Windows XP would be particularly at risk, as no security patches for that have been issued by Microsoft since April 2014.

How does it work?

WannaCry is a form of ransomware that locks up files on your computer and encrypts them in a way that you cannot access them anymore. It targets Microsoft's widely used Windows operating system.

When a system is infected, a pop-up window appears with instructions on how to pay a ransom amount of $300. The pop-up also features two countdown clocks; one showing a three-day deadline before the ransom amount doubles to $600; another showing a deadline of when the target will lose its data forever. Payment is only accepted in bitcoin. 

The initial spread of WannaCry is coming through spam, in which fake invoices, job offers and other lures are being sent out to random email addresses. Within the emails is a .zip file, and once clicked that initiates this infection.

Some security researchers say the infections in the case of WannaCry seem to be deployed via a worm, spreading by itself within a network rather than relying on humans to spread it by clicking on an infected attachment. The programme encrypts your files and demands payment in order to regain access, without any guarantee that access will be granted after payment.

Given the malware is scanning the entire internet for vulnerable machines, and as many as 150,000 were deemed open to the Windows vulnerability as of earlier this month, this ransomware explosion is only expected to get worse over the weekend.


Which files are affected?

  1. \msg— This folder contains the RTF describing the different instructions for the ransom-ware. Totalling 28 languages.
  2. b.wnry— BMP image used as a background image replacement by the malware.
  3. c.wnry— configuration file containing the target address, but also the tor communication endpoints information.
  4. s.wnry— Tor client to communication with the above endpoints.
  5. u.wnry— UI interface of the ransom-ware, containing the communications routines and password validation (currently being analysed)
  6. t.wnry— “WANACRY!” file
  7. r.wnry— Q&A file used by the application containing payment instructions
  8. taskdl.exe / taskse.exe —

Who is impacted?

A number of organizations globally have been affected, the majority of which are in Europe. This ransomware attack impacted many NHS hospitals in the UK. Whereas on 12 May, some NHS services had to turn away non-critical emergencies, and some ambulances were diverted. Over 1,000 computers at the Russian Interior Ministry, the Russian Emergency Ministry and the Russian telecommunications company MegaFon, have been infected.


What you can do to prevent this infection?

Since 12th Apr 2017, a Ransomware exploiting MS17-010 has been wreaking havoc worldwide. Here are the steps you should take to protect yourself against ransomware:

1 - Patch Management
Ensure all Workstations and Servers have the latest Microsoft patches, especially the ones related to MS17-010.

2 - Antivirus
Ensure AV signatures are updated on all assets. Identify critical assets and target them first. Block IOCs on AV solution. Get the details with regards to the name of the malware and verify if this malware has been detected in the logs for last 1 week.

3 - IPS
Ensure IPS signatures are updated. Verify if the signature that can detect this vulnerability / exploit attempt is enabled and is in blocking mode. Get the details with regards to the name of the Signature and verify if this Signature has been detected in the logs for last 1 week.

4 - eMail Gateway
Ensure eMail Gateway solutions has all relevant updates for detecting possible mails that may bring the Trojan in the environment.

5 - Proxy
Ensure Proxy solution has updated database. Block IOCs for IP Address and Domain names on the Proxy. Verify last one week logs for the IOCs on Proxy and take action on sources of infection.

6 - Firewall
Block the IP addresses on Perimeter Firewall. Verify logs for last one week.

7 - Anti - APT Solutions (FireEye, Trend Micro)
Ensure signatures are up to date. Check for possible internal sources of infection and take actions.

8 - SIEM
Check logs to verify if any of the IOCs have been detected in 1 week logs.

9 - Internet Explorer
Ensure you have smart screen (in Internet Explorer) turned on, which helps identify reported phishing and malware websites and helps you make informed decisions about downloads.

10 - Email Pop-up Blocker
Avoid clicking on links or opening attachments or emails from people you don't know or companies you don't do business with. Unless you are absolutely sure that this is a genuine email from a trusted source, do not enable macros and instead immediately delete the email. Have a pop-up blocker running on your web browser.

11 - Regular Backup
Regularly backup your important files is the single most effective way of combating ransomware infection. Attackers have leverage over their victims by encrypting valuable files and leaving them inaccessible. If the victim has backup copies, they can restore their files once the infection has been cleaned up. However organizations should ensure that back-ups are appropriately protected or stored off-line so that attackers can’t delete them.


Note:
  • If required, raise case with OEM for getting details
  • All changes to follow proper approvals and change management process
Follow this link to see the real time heat map: https://intel.malwaretech.com/botnet/wcrypt


Wednesday, 26 April 2017

Fraudsters attack from almost everywhere. Have you been to any of these hotels?

Have you given a second thought before swiping your card while booking hotels? I bet you never rethink on doing that... but what if we say you have to...

This is something that had happened at InterContinental Hotels recently. IHG didn’t reveal just how many hotel properties were considered to be at risk, but the examination shows that the state-by-state lookup tool they published online reveals it to be higher than 1170. 

In recent years many hotel chains – including Hyatt, Omni, Hilton Hotels, Starwood Hotels, and Trump Hotels – have found themselves targeted by criminals using malware to steal payment card information. The problem has become so serious that you might start to wonder whether it might be safer to pay on hotel properties with cash, or at least with a card which has a low payment limit.

The investigation identified signs of the operation of malware designed to access payment card data from cards used onsite at front desks for certain IHG-branded franchise hotel locations between September 29, 2016 and December 29, 2016. Although there is no evidence of unauthorized access to payment card data after December 29, 2016, confirmation that the malware was eradicated did not occur until the properties were investigated in February and March 2017. Before this incident began, many IHG-branded franchise hotel locations had implemented IHG’s Secure Payment Solution (SPS), a point-to-point encryption payment acceptance solution. the implementation of SPS ended the ability of the malware to find payment card data and, therefore, cards used at these locations after SPS implementation were not affected.

The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) read from the magnetic stripe of a payment card as it was being routed through the affected hotel server. There is no indication that other guest information was affected.

It is always advisable to remain vigilant to the possibility of fraud by reviewing your payment card statements for any unauthorized activity. You should immediately report any unauthorized charges to your card issuer because payment card rules generally provide that cardholders are not responsible for unauthorized charges reported in a timely manner. The phone number to call is usually on the back of your payment card. 


Be aware, Be safe !

Tuesday, 25 April 2017

Mastercard Unveils Next Generation Biometric Card

If you have read the subheading, then you must be wondering as to how the simple implementation of the ultra-common fingerprint sensor on your debit card will change the banking experience? Consider your cash withdrawals during the period of "demonetization" in 2016. You must be remembering that it was a tricky method to enter your debit card PIN while hiding the num-pad of the ATM machine from prying eyes behind you, pushing each other to get a glimpse of your transaction details.

If you remove that num-pad based PIN entry from the scene, no one in the world would get a clue about your debit card PIN, apart from your bank. This implementation would also make card payments at restaurants or shopping malls a lot more secure.



However, all fingerprint sensors are not alike. Mastercard implementation as involving a trip to "an enrollment center," where a user could store one or two different prints (of their own) on their card. An encrypted digital template of your fingerprint is stored on the card's EMV chip. The new cards authenticate when a matching fingerprint is supplied by the user after inserting the card into a Chip and Pin terminal (not swiped). The card sensor would also not work when used in an ATM that ingests the card.

MasterCard is keen on embedding this basic technology on its line-up of credit and debit cards to enhancing the user security. Not only security, a biometric authentication would make payments faster, in the same way as unlocking your smartphone is just a tap away instead of those complex mazes that you used (many of you still do it) to set as your pattern password.

The demo cards are currently being tested in South Africa and MasterCard plans to roll it out to the world by the end of 2017. The cards are not any different from your regular credit/debit card that you carry in your wallet. While the basic architecture remains mostly the same, you will notice only a matte coloured sensor patch on the top left corner of the card.

The card itself is no thicker than a regular credit card. The fingerprint sensor is a small, thumbnail-sized rectangle that sits at the top right corner, and is easily accessible when you stick the card into a payment terminal.

When the terminal asks you to insert the card, it's communicating to the bank information like your identity and the amount of the transaction. Then, it verifies your identity by asking for your fingerprint. The sensor reads your finger, and sends the information to the card's chip, which determines if you're the owner. If you are, it sends a "Yes" or "Authorized" message to the bank, which then allows the payment to pass.

As for the vendors, there’s no need to upgrade any hardware, unless you are still using the magnetic-type swipe-based transaction machine on your billing desk.

While MasterCard is planning a global roll-out of the fingerprint-enabled debit card, you can be assured that it will take a few years due to the additional time being taken by banks and financial institutions to get their approvals from the management for the implementation of this new convenience.

Android Spyware SMSVova found on Google Play Store

Millions of users have been tricked into downloading Android spyware disguised as a system update in the Play Store. The app that claims to give users access to the latest Android updates remained undetected in the Play Store for three years and was downloaded between one and five million times. 

Experts at Zscaler discovered that the bogus app was posing as a legitimate application called “System Update” and claiming to provide users with access to the latest Android software release.

It has been estimated that the fake application hiding the SMSVova spyware was uploaded in the Google Play in 2014, and has been downloaded between 1,000,000 and 5,000,000 times.

Experts reported the discovery to Google that promptly removed it from the store.

The SMSVova spyware was developed to track the physical location of the users, it was controlled by attackers via SMS messages.

“In our ongoing effort to hunt malware, the Zscaler ThreatLabz team came across a highly suspicious app on the U.S. Google Play Store that has been downloaded between one and five million times since 2014.” reads theanalysis published Zscaler. “Upon analysis, we found it to be an SMS-based Spyware, which can steal and relay a victim’s location to an attacker in real time.”

According to Zscaler, once the app was installed when users try to open it they were displayed the message:

‘Unfortunately, Update Service has stopped.’


Then the app hides itself from the main screen and launches the phone’s MyLocationService which collect location data and stores it in the Shared Preferences directory of the mobile device.

Despite the error message, the spyware sets up an Android service and broadcast receiver:
  • MyLocationService: Fetches last known location
  • IncomingSMS (Receiver): Scans for incoming SMS message
SMSVova monitors specific incoming SMS messages with specific characteristics, messages with more than 23 characters in length and that contain the text string “vova-” and “get faq.”

It is curious to note that according to the recent Google Android Security 2016 Year In Review report, in 2016 devices that installed applications only from Google Play had fewer than 0.05 percent of potentially harmful applications installed.

“There are many apps on the Google Play store that act as a spyware; for example, those that spy on the SMS messages of one’s spouse or fetch the location of children for concerned parents. But those apps explicitly state their purpose, which is not the case with the app we analyzed for this report,” concluded the analysis.

It is unclear why exactly was the malware focusing on user location alone. The app also hasn’t been updated since December 2014, however, millions of people kept downloading it. Google has now removed it from the store after being alerted, but the app did go undetected since it first appeared in 2014. We are still to hear back from the search giant on why this app remained active for three years in the Play Store.

Monday, 24 April 2017

IOT security and Mobile application security trends

How about taking a look a look at the latest mobile application & IOT security trends. Here is a summary of the Mobile application and IOT application security study conducted. The CIO, CISO, CTO, CRO and the COOs were surveyed from organizations pertaining to Financial Services, Health & Pharmaceuticals, Public Sector, Retail, Technology and Services and several other industries.


58% - Organizations were concerned that they could get hacked through an IOT application.
53% - Organizations were concerned that they could get hacked through a mobile device.

84% - Organizations were concerned about the threat of malware to mobile apps
66% - Organizations were concerned about the threat of malware to IOT apps


79% - People believe that use of mobile apps increases risk
75% - People believe that use of IOT apps increases risk

15% - People say that CISOs are responsible for the security of the mobile application
31% - People say that Head - Applications are responsible for the security of the IOT apps

54% - People believe that only a serious hacking incident influences the organization to increase budget
46% - People believe that New regulations also influences the organization to increase budget

Application security assessment frequency

42% - Organizations care to secure their IOT apps urgently
32% - Organizations care to secure their mobile apps urgently

48% - Organizations do not test their IOT apps
18% - Organizations test the mobile apps when there is a code change

Difficulty levels in fixing OWASP vulnerabilities

57% - People believe that pentesting the primary means of securing mobile apps
30% - People believe that security testing through SDLC is the primary means of securing mobile apps

69% - People believe that the rush to release the mobile app on the development team leaves the code vulnerable
40% - People believe that the lack of testing procedures leaves the code vulnerable

32% - Mobile applications are tested in the development environment
26% - IOT apps are tested in the development environment

Credits: Ponemon Institute.