Cyber4Dev weekly update

/

20.01.2023

NEWS:

What threatens corporations in 2023: media blackmail, fake leaks and cloud attacks

Last year, the cybersecurity of corporations and government agencies was more significant than ever before, and will become even more so in 2023. As part of the Kaspersky Security Bulletin, the DFI (Digital Footprint Intelligence) and DFIR (Digital Forensics and Incident Response) teams have come up with an overview of threats that will be relevant to the segment in question.

Ransomware profits drop 40% in 2022 as victims refuse to pay

Ransomware gangs extorted from victims about $456.8 million throughout 2022, a drop of roughly 40% from the record-breaking $765 million recorded in the previous two years. According to data from blockchain analytics company Chainalysis, this drastic decline in ransomware profits is not driven by fewer attacks but the victims’ refuse to pay the hackers. 2022 was one of the most active years in ransomware activity, with thousands of file-encrypting malware strains targeting organizations of all sizes.

https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-40-percent-in-2022-as-victims-refuse-to-pay/

Ransomware gangs are starting to ditch encryption

Criminal gangs are using a new method to guarantee a ransomware payout: They’re ditching the part where they lock up a target firm’s systems by encrypting them and are skipping straight to holding the company’s precious data for ransom. The big picture: As law enforcement attention on ransomware grows, gangs are constantly looking for less-flashy, but still efficient ways to keep their ransomware attacks going.

How it works: A ransomware attack typically starts with hackers installing file-encrypting malware onto an organization’s networks and then displaying a ransom note on every screen. In recent years, ransomware criminals have added another layer to their schemes: They steal data before locking an organization out, then demand a second payment to stop them from dumping all the data in public online.

https://www.axios.com/2023/01/13/ransomware-gangs-cut-out-encryption

UK cyber reform campaign gets boost from global body

CyberUp says the UK’s three-decades-old cybersecurity law is in desperate need of an overhaul to protect the country from 21st-century threats – and now its campaign has been officially endorsed by global digital accreditation body CREST. The Computer Misuse Act, dating back to 1990, has come under fire in recent years, with ministers failing to deliver on promises made in 2021 of a parliamentary overhaul of Britain’s existing legal framework. The core issue around the law is that in its current form, it criminalizes certain activities that penetration testers, who are nowadays recognized as the backbone of cybersecurity efforts to test defenses among organizations from ransomware attacks and the like, say they need to carry out to ensure safety.

https://cybernews.com/news/uk-cyber-reform/

INCIDENTS:

Disruption on High Seas: Shipping Software Hit by Ransomware Attack

The company targeted in the ransomware attack is DNV, a prominent and widely-recognized provider of digital ship management solutions. The company has confirmed that approximately 1,000 vessels had been affected and that they were in close contact with the 70 affected customers. On January 7th, DNV, a digital ship management solutions provider, was targeted in a ransomware attack, causing it to take its ShipManager software offline.

Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner

Yum! Brands, the fast food brand operator of KFC, Pizza Hut, Taco Bell, and The Habit Burger Grill fast- food restaurant chains, has been targeted by a ransomware attack that forced the closure of 300 locations in the United Kingdom. Yum! Brands operates 53,000 restaurants across 155 countries and territories, with over $5 billion in total assets and $1.3 billion in yearly net profit. “Promptly upon detection of the incident, the Company initiated response protocols, including deploying containment measures such as taking certain systems offline and implementing enhanced monitoring technology,” Yum! Brands explained in a press statement.

https://www.bleepingcomputer.com/news/security/ransomware-gang-steals-data-from-kfc-taco-bell-and-pizza-hut-brand-owner/

T-Mobile hacked to steal data of 37 million accounts in API data breach

T-Mobile disclosed a new data breach after a threat actor stole the personal information of 37 million current postpaid and prepaid customer accounts through one of its Application Programming Interfaces (APIs). An API is a software interface or mechanism commonly used by applications or computers to communicate with each other. Many online web services use APIs so that their online apps or external partners can retrieve internal data as long as they pass the right authentication tokens.

https://www.bleepingcomputer.com/news/security/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach/

Hacktivists Leak 1.7TB of Cellebrite, 103GB of MSAB Data

The Israeli mobile forensics firm, Cellebrite, has apparently suffered yet another data breach in which hackers managed to steal 1.7 TB of data. The hackers are also claiming to have stolen 103 GB of data from MSAB, a Sweden-based forensics firm. In both cases, the trove of information is available for download on DDoSecrets and the official website Enlace Hacktivista. It is worth noting that, according to Enlace Hacktivista, the Cellebrite and MSAB data was provided to them by an “anonymous whistleblower.”

MALWARE:

Attackers Crafted Custom Malware for Fortinet Zero-Day

The “BoldMove” backdoor demonstrates a high level of knowledge of FortiOS, according to Mandiant researchers, who said the attacker appears to be based out of China. Researchers analyzing data associated with a recently disclosed zero-day vulnerability in Fortinet’s FortiOS SSL-VPN technology have identified a sophisticated new backdoor specifically designed to run on Fortinet’s FortiGate firewalls. The malware appears to be the work of a China-based threat actor engaged in cyber-espionage operations targeting government organizations and those working with these organizations.

https://www.darkreading.com/threat-intelligence/china-based-attacker-crafted-custom-malware-for-fortinet-zero-day

Experts spotted a backdoor that borrows code from CIA’s Hive malware

Researchers from Qihoo Netlab 360 reported that unidentified threat actors using a new backdoor based on the US CIA’s Project Hive malware suite. One of the 360Netlab’s honeypot caught a suspicious ELF file on October 2021, the experts reported that the malware was spread by exploiting F5 zero-day exploit. The researchers noticed that the malicious code was contacting the IP address 45.9.150.144 using SSL with forged Kaspersky certificates. Additional analysis revealed that the malware borrows code from the Hive project that was leaked in 2017 as part of Vault 8 series.

VULNERABILITIES:

Researchers found a new critical remote code execution (RCE) flaw impacting multiple services related to Microsoft Azure.

Researchers from Ermetic found a remote code execution flaw, dubbed EmojiDeploy, that impacts Microsoft Azure services and other cloud services including Function Apps, App Service and Logic Apps. The issue is achieved through CSRF (Cross-site request forgery) on the ubiquitous SCM service Kudu. Kudu is the engine behind a number of features in Azure App Service related to source control based deployment, and other deployment methods like Dropbox and OneDrive sync. An attacker can exploit the flaw to deploy malicious zip archives containing a payload to the victim’s Azure application.

Critical Security Vulnerabilities Discovered in Netcomm and TP-Link Routers

Security vulnerabilities have been disclosed in Netcomm and TP-Link routers, some of which could be weaponized to achieve remote code execution. The flaws, tracked as CVE-2022-4873 and CVE-2022-4874, concern a case of stack-based buffer overflow and authentication bypass and impact Netcomm router models NF20MESH, NF20, and NL1902 running firmware versions earlier than R6B035. “The two vulnerabilities, when chained together, permit a remote, unauthenticated attacker to execute arbitrary code,” the CERT Coordination Center (CERT/CC) said in an advisory published Tuesday.

https://thehackernews.com/2023/01/critical-security-vulnerabilities.html

Cisco Patches High-Severity SQL Injection Vulnerability in Unified CM

Cisco on Wednesday announced patches for a high-severity SQL injection vulnerability in Unified Communications Manager (CM) and Unified Communications Manager Session Management Edition (CM SME).Designed as enterprise call and session management platforms, Cisco Unified CM and Unified CM SME ensure the interoperability of applications such as Webex, Jabber, and more, while also maintaining availability and security.Tracked as CVE-2023-20010 (CVSS score of 8.1), the vulnerability exists because user input is improperly validated in the web-based management interface of the platforms. The bug allows a remote, authenticated attacker to launch an SQL injection attack on a vulnerable system.

https://www.securityweek.com/cisco-patches-high-severity-sql-injection-vulnerability-unified-cm

Cyber4Dev collates data from Open-Source websites, any opinions or attributions expressed in the articles are not those of Cyber4Dev and are not endorsed by the project or the EU.