Cyber4Dev weekly update 02.09.2022

/

02.09.2022 Cyber4Dev News

Cyber4Dev News

This week, we have had the please of continuing to support our partners across the globe, with missions in Botswana and Malawi this week. A key part of our renewed engagement, we were delighted to work alongside C3SA and Atlantic Council by supporting the Cyber 9/12 Challenge.

The Cyber 9/12 Strategy Challenge is a one-of-a-kind cyber competition designed to provide students from across academic disciplines with a deeper understanding of the policy and strategy challenges associated with management of trade-offs during a cyber crisis. 30 teams from universities across Africa and beyond were guided through a series of thought-provoking presentations from our guest experts Raul Rikk, Lauri Luht and Liina Lumiste, ahead of the final challenge which will take place at the end of September.

Cyber4Dev meeting in Mauritius

Last week, our communications expert Sylvia Beamish and FCDO expert Ewan Smith had constructive talks with our colleagues in Cyber4Dev African hub, Mauritius. Meeting with MU-CERT and Ministry of Information Technology, Communication and Innovation colleagues, exciting plans are now in place for a comprehensive, nationwide public awareness campaign in 2023.

NEWS:

Multifactor authentication has its limits, but don’t blame the technology

Multifactor authentication is widely regarded as a must-have among cybersecurity professionals and authorities, but it’s not always a quick fix. Threat actors can still evade and even exploit MFA via phishing or social engineering attacks, as evidenced by the persistent and widespread text-message phishing campaign dubbed Oktapus or Scatter Swine. Technology companies, telecommunications providers and organizations or individuals linked to cryptocurrency have been targeted since the attacks began in March. The adversary compromised almost 10,000 user credentials across 136 organizations, according to Group- IB, sometimes targeting employees at specific companies once access was gained directly or via third-party vendors.

https://www.cybersecuritydive.com/news/multifactor-authentication-limits/631046/

FBI’s Team to Investigate Massive Cyberattack in Montenegro

A rapid deployment team of FBI cyber experts is heading to Montenegro to investigate a massive and coordinated attack on the tiny Balkan nation’s government and its services, the country’s Ministry of Internal Affairs announced Wednesday. “This is another confirmation of the excellent cooperation between the United States of America and Montenegro and a proof that we can count on their support in any situation,” the ministry said of the deployment of the Cyber Action Team.

https://www.securityweek.com/fbis-team-investigate-massive-cyberattack-montenegro

Ransomware Attacks are on the Rise

After a recent dip, ransomware attacks are back on the rise. According to data released by NCC Group, the resurgence is being led by old ransomware-as-a-service (RaaS) groups. With data gathered by “actively monitoring the leak sites used by each ransomware group and scraping victim details as they are released,” researchers have determined that Lockbit was by far the most prolific ransomware gang in July, behind 62 attacks. That’s ten more than the month prior, and more than twice as many as the second and third most prolific groups combined.

INCIDENTS:

New ransomware hits Windows, Linux servers of Chile govt agency

Chile’s national computer security and incident response team (CSIRT) has announced that a ransomware attack has impacted operations and online services of a government agency in the country. The attack started on Thursday, August 25, targeting Microsoft and VMware ESXi servers operated by the agency. The hackers stopped all running virtual machines and encrypted their files, appending the “.crypt” filename extension. According to CSIRT, the malware used in this attack also had functions for stealing credentials from web browsers, list removable devices for encryption, and evade antivirus detection using execution timeouts.

https://www.bleepingcomputer.com/news/security/new-ransomware-hits-windows-linux-servers-of-chile-govt-agency/

Ragnar Locker ransomware claims attack on Portugal’s flag airline

The Ragnar Locker ransomware gang has claimed an attack on the flag carrier of Portugal, TAP Air Portugal, disclosed by the airline after its systems were hit on Thursday night. The company said the attack was blocked and added that it found no evidence indicating the attackers gained access to customer information stored on impacted servers. “TAP was the target of a cyber-attack, now blocked. Operational integrity is guaranteed,” the airline operator revealed in a statement on Friday via its official Twitter account.

https://www.bleepingcomputer.com/news/security/ragnar-locker-ransomware-claims-attack-on-portugals-flag-airline/

MALWARE:

ModernLoader delivers multiple stealers, cryptominers and RATs

Cisco Talos recently observed three separate, but related, campaigns between March and June 2022 delivering a variety of threats, including the ModernLoader bot, RedLine information-stealer and cryptocurrency-mining malware to victims. The actors use PowerShell, .NET assemblies, and HTA and VBS files to spread across a targeted network, eventually dropping other pieces of malware, such as the SystemBC trojan and DCRAT, to enable various stages of their operations. The attackers’ use of a variety of off-the-shelf tools makes it difficult to attribute this activity to a specific adversary.

https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html

A study on malicious plugins in WordPress Marketplaces

A team of researchers from the Georgia Institute of Technology has analyzed the backups of more than 400,000 unique web servers and discovered 47,337 malicious plugins installed on 24,931 unique WordPress websites. The experts studied the evolution of CMS plugins in the production web servers dating back to 2012, to do this they developed an automated framework named YODA to detect malicious plugins. The number of malicious plugins on WordPress websites has increased over the years, and malicious activity reached a peak in March 2020.

VULNERABILITIES:

Apple Quietly Releases Another Patch for Zero-Day RCE Bug

Apple continues a staged update process to address a WebKit vulnerability that allows attackers to craft malicious Web content to load malware on affected devices. Apple has quietly rolled out more updates to iOS to fix an actively exploited zero-day security vulnerability that it patched earlier this month in newer devices. The vulnerability, found in WebKit, can allow attackers to create malicious Web content that allows remote code execution (RCE) on a user’s device. An update released Wednesday, iOS 12.5.6, applies to the following models: iPhone 5S, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch 6th generation.

https://www.darkreading.com/vulnerabilities-threats/apple-patch-zero-day-rce-bug

WordPress 6.0.2 Patches Vulnerability That Could Impact Millions of Legacy Sites

The WordPress team this week announced the release of version 6.0.2 of the content management system (CMS), with patches for three security bugs, including a high-severity SQL injection vulnerability. Identified in the WordPress Link functionality, previously known as ‘Bookmarks’, the issue only impacts older installations, as the capability is disabled by default on new installations. However, the functionality might still be enabled on millions of legacy WordPress sites even if they are running newer versions of the CMS, the Wordfence team at WordPress security company Defiant says.

https://www.securityweek.com/wordpress-602-patches-vulnerability-could-impact-millions-legacy-sites

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.