231-922-9460 | Google +

Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Thursday, February 19, 2015

BANK HACKERS STEAL MILLIONS VIA MALWARE

Original Story: nytimes.com

PALO ALTO, Calif. — In late 2013, an A.T.M. in Kiev started dispensing cash at seemingly random times of day. No one had put in a card or touched a button. Cameras showed that the piles of money had been swept up by customers who appeared lucky to be there at the right moment.

But when a Russian cybersecurity firm, Kaspersky Lab, was called to Ukraine to investigate, it discovered that the errant machine was the least of the bank’s problems. An Atlanta IP lawyer is following this story closely.

The bank’s internal computers, used by employees who process daily transfers and conduct bookkeeping, had been penetrated by malware that allowed cybercriminals to record their every move. The malicious software lurked for months, sending back video feeds and images that told a criminal group — including Russians, Chinese and Europeans — how the bank conducted its daily routines, according to the investigators. A Detroit intellectual property lawyer have experience litigating IP infringement cases.

Then the group impersonated bank officers, not only turning on various cash machines, but also transferring millions of dollars from banks in Russia, Japan, Switzerland, the United States and the Netherlands into dummy accounts set up in other countries.

In a report to be published on Monday, and provided in advance to The New York Times, Kaspersky Lab says that the scope of this attack on more than 100 banks and other financial institutions in 30 nations could make it one of the largest bank thefts ever — and one conducted without the usual signs of robbery.

The Moscow-based firm says that because of nondisclosure agreements with the banks that were hit, it cannot name them. Officials at the White House and the F.B.I. have been briefed on the findings, but say that it will take time to confirm them and assess the losses. An Atlanta data privacy lawyer assists clients with privacy issues, data protection, information security, and consumer protection matters.

Kaspersky Lab says it has seen evidence of $300 million in theft through clients, and believes the total could be triple that. But that projection is impossible to verify because the thefts were limited to $10 million a transaction, though some banks were hit several times. In many cases the hauls were more modest, presumably to avoid setting off alarms.

The majority of the targets were in Russia, but many were in Japan, the United States and Europe.

No bank has come forward acknowledging the theft, a common problem that President Obama alluded to on Friday when he attended the first White House summit meeting on cybersecurity and consumer protection at Stanford University. He urged passage of a law that would require public disclosure of any breach that compromised personal or financial information.

But the industry consortium that alerts banks to malicious activity, the Financial Services Information Sharing and Analysis Center, said in a statement that “our members are aware of this activity. We have disseminated intelligence on this attack to the members,” and that “some briefings were also provided by law enforcement entities.” A Los Angeles computer and software lawyer represents clients in computer fraud and computer security cases.

The American Bankers Association declined to comment, and an executive there, Douglas Johnson, said the group would let the financial services center’s statement serve as the only comment. Investigators at Interpol said their digital crimes specialists in Singapore were coordinating an investigation with law enforcement in affected countries. In the Netherlands, the Dutch High Tech Crime Unit, a division of the Dutch National Police that investigates some of the world’s most advanced financial cybercrime, has also been briefed.

The silence around the investigation appears motivated in part by the reluctance of banks to concede that their systems were so easily penetrated, and in part by the fact that the attacks appear to be continuing.

The managing director of the Kaspersky North America office in Boston, Chris Doggett, argued that the “Carbanak cybergang,” named for the malware it deployed, represents an increase in the sophistication of cyberattacks on financial firms.

“This is likely the most sophisticated attack the world has seen to date in terms of the tactics and methods that cybercriminals have used to remain covert,” Mr. Doggett said.

As in the recent attack on Sony Pictures, which Mr. Obama said again on Friday had been conducted by North Korea, the intruders in the bank thefts were enormously patient, placing surveillance software in the computers of system administrators and watching their moves for months. The evidence suggests this was not a nation state, but a specialized group of cybercriminals.

But the question remains how a fraud of this scale could have proceeded for nearly two years without banks, regulators or law enforcement catching on. Investigators say the answers may lie in the hackers’ technique.

In many ways, this hack began like any other. The cybercriminals sent their victims infected emails — a news clip or message that appeared to come from a colleague — as bait. When the bank employees clicked on the email, they inadvertently downloaded malicious code. That allowed the hackers to crawl across a bank’s network until they found employees who administered the cash transfer systems or remotely connected A.T.M.s.

Then, Kaspersky’s investigators said, the thieves installed a “RAT”— remote access tool — that could capture video and screenshots of the employees’ computers.

“The goal was to mimic their activities,” said Sergey Golovanov, who conducted the inquiry for Kaspersky Lab. “That way, everything would look like a normal, everyday transaction,” he said in a telephone interview from Russia.

The attackers took great pains to learn each bank’s particular system, while they set up fake accounts at banks in the United States and China that could serve as the destination for transfers. Two people briefed on the investigation said that the accounts were set up at J.P. Morgan Chase and the Agricultural Bank of China. Neither bank returned requests for comment.

Kaspersky Lab was founded in 1997 and has become one of Russia’s most recognized high-tech exports, but its market share in the United States has been hampered by its origins. Its founder, Eugene Kaspersky, studied cryptography at a high school that was co-sponsored by the K.G.B. and Russia’s Defense Ministry, and he worked for the Russian military before starting his firm.

When the time came to cash in on their activities — a period investigators say ranged from two to four months — the criminals pursued multiple routes. In some cases, they used online banking systems to transfer money to their accounts. In other cases, they ordered the banks’ A.T.M.s to dispense cash to terminals where one of their associates would be waiting.

But the largest sums were stolen by hacking into a bank’s accounting systems and briefly manipulating account balances. Using the access gained by impersonating the banking officers, the criminals first would inflate a balance — for example, an account with $1,000 would be altered to show $10,000. Then $9,000 would be transferred outside the bank. The actual account holder would not suspect a problem, and it would take the bank some time to figure out what had happened.

“We found that many banks only check the accounts every 10 hours or so,” Mr. Golovanov of Kaspersky Lab said. “So in the interim, you could change the numbers and transfer the money.”

The hackers’ success rate was impressive. One Kaspersky client lost $7.3 million through A.T.M. withdrawals alone, the firm says in its report. Another lost $10 million from the exploitation of its accounting system. In some cases, transfers were run through the system operated by the Society for Worldwide Interbank Financial Telecommunication, or Swift, which banks use to transfer funds across borders. It has long been a target for hackers — and long been monitored by intelligence agencies.

Mr. Doggett likened most cyberthefts to “Bonnie and Clyde” operations, in which attackers break in, take whatever they can grab, and run. In this case, Mr. Doggett said, the heist was “much more ‘Ocean’s Eleven.’ ”

Wednesday, May 30, 2012

Flame Malware A Real Scare

Story first appeared in The Wall Street Journal.
The complexity, size and geographic location of the computers affected by Flame, the malware that came to light Monday, points to state-sponsored cyber-espionage, and has been seen mainly as a geopolitical event. But the Flame code, which extracts data from networked computers and sends it to remote servers controlled by hackers, should also be seen by CIOs as a potential commercial threat and should cause them to reassess their Security Solutions – both on-premise and in the cloud.

Flame represents a next generation of malware because, while it combines many known ways of attacking systems and transmitting data back to remote servers, it is unique in how it has combined all of those malicious characteristics. Although many cyber-security experts have said most companies that create intellectual property – including a wide assortment of activities from pharmaceutical research to financial services and oil drilling – have already had their systems hacked, it may not be too late for CIOs to protect critical data. But, say experts, they will have to carefully assess their own networks, as well as their relationships with software vendors and cloud service providers with whom they do business.

Help Desk Services and analysts say that Flame should serve as a reminder to CIOs of how vulnerable they are, and give them a greater sense of urgency. Indeed the CIO of Land O’ Lakes, says he learned about Flame on the radio on his way into the office Tuesday, and his thoughts turned immediately to his cloud vendors. Like many CIOs, he has software running both on-premise and in the cloud, and says Flame is equally threatening to cloud and on-premise applications, but he wonders more about the risk mitigation strategies employed by his cloud partners. The question is, who will respond more quickly — cloud providers or his own internal data centers?

That’s a good question – cloud vendors generally do not accept liability for their clients data in the cloud.

The terms of service for Amazon’s AWS web services stipulate that the cloud vendor doesn’t accept liability for lost or altered data, and that customers are responsible for taking your own steps to maintain appropriate security, protection and backup of Your Content, which may include the use of encryption technology to protect Your Content from unauthorized access and routine archiving Your Content.

A Microsoft spokesperson said the company does accept liability for customer data on its Azure cloud platform, unless the customers themselves configured software improperly or otherwise created the conditions for a data breach. Rackspace and Google did not reply to requests for comment at the time of this writing.

Maintaining network security is hard enough on company-owned networks, but if you throw it over the wall to the cloud vendor and you don’t have visibility and control, it becomes impossible. Cloud vendors should provide customers with security tools, even if the customers themselves are responsible for configuring them.

The senior vice president and CIO of Hostess Brands Corporation, seemed to have these challenges in mind when he said he believes companies are limiting much of the data that they move to the cloud to less-critical information, because they are concerned about security.  Until CIOs can get a comfort level that is tenable and sustained, the movement to the cloud will be selective.

Closer to home, however, CIOs still have work to do. A security and privacy expert with the IEEE, a professional IT organization, says even a next generation of malware such as Flame can only get a toehold in an organization’s network by taking advantage of bad software. He blames vendors for building software that leaves customers susceptible to a malware attack, but says customers have to ask their vendors if the stuff you’re buying from them is secure or not, because a lot of people don’t even ask.

He says responsible vendors will respond honestly to that question.

CIOs need to ensure that software written by their own developers has security built into it, and can do this by following guidelines established in the BSIMM [Building Security In Maturity Model] standard. Beyond that, he said good security practice includes using tools to analyze existing software architecture, review code, and regularly hiring third parties to test the network for vulnerabilities by trying to penetrate it. McGraw says he’s “optimistic we’re actually making progress” in making safe software more ubiquitous. But, he said, the only way we can get in front of [issues like Flame] is building systems to be secure in the first place.

A Gartner analyst says Flame highlights the fact that we have to take a multi-pronged approach to malware. No single approach will be a silver bullet. New technologies that analyze the behavior of applications on networks can identify malware before it executes its code. Older anti-virus applications depend on being able to recognize the code used by malware, whereas newer generations of technology can see whether a particular type of application, like a PDF file, is trying to execute code – which it shouldn’t normally do.

An independent cybersecurity analyst, says CIOs should create an inventory of all a company’s data and classify it according to its value, much like the government does with state secrets. They should then take the equivalent of “top secret” data off the Internet. CIOs should also segregate data that is important but not critical, and monitor which persons and applications have access to it.

The reason this isn’t common practice is that many CIOs think about security in terms of legal requirements rather than common-sense approaches. Security is often a matter of compliance. Knowing where your critical data is isn’t an obligation, so it’s not done.


For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.
For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.

Tuesday, May 8, 2012

Cyber Hackers Attack Natural Gas Lines

Story first appeared in USA Today.

Homeland Security has warned U.S. utilities that the computer networks controlling natural gas pipelines have been under attack since December, according to news reports out of Washington.

Canadian pipelines may also be affected by the cyber intrusion campaign, according to confidential Homeland Security alerts first reported by the Christian Science Monitor.

A Homeland Security spokesman today told The Hill that DHS is working with the FBI and other federal agencies to address the spear-phishing attacks, which involve fraudulent e-mails sent to gas company employees. The companies were not named.

DHS has issued at least three "amber" alerts -- the second-highest warning -- since March 29. Those warnings were reiterated late Friday in a report from Homeland Security's Industrial Control Systems Cyber Emergency Response Team based in Idaho.

ICS-CERT has recently identified an active series of cyber intrusions targeting natural gas pipeline sector companies. Multiple natural gas pipeline organizations have reported either attempts or intrusions related to this campaign. The campaign appears to have started in late December 2011 and is active today.

But DHS has asked utilities to not remove any malware or patch security holes if they don't jeopardize safe operations, according to people who have seen the alerts. One would expect stronger Security Solutions to be put in place once this is resolved.

The newspaper says that about 200,000 miles of pipelines deliver 25% of U.S. energy.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Thursday, April 19, 2012

Cyber Security Not Getting Better

Story first appeared on eSecurityPlanet.com.

For years, security solution vendors have been in an arms race with hackers. As the rate of discovery of new vulnerabilities continued to grow, attackers have enjoyed an ever-expanding menu of security flaws to exploit. But last year, something happened: The number of new vulnerability reports actually declined.

According to HP's new Top Cyber Security Risks Report for 2011, there was a 19.5 percent decrease in the number of new publicly reported vulnerabilities over the course of last year.

But don't start celebrating just yet, because attack volume still continues to increase. Attack data from HP TippingPoint shows approximately 475 million attacks in 2010 vs. 531 million in 2011 -- an 11 percent increase.

So while the number of publicly reported vulnerabilities is down, the overall security risks have not actually declined. That's according to the security product marketing manager at HP DVLabs, who told eSecurity Planet that a deeper analysis of the new vulnerabilities that were disclosed in 2011 shows that the proportion of high-severity vulnerabilities has actually increased. In 2011, high-severity vulnerabilities (those with a CVSS score of between 8 and 10) jumped by 24 percent. CVSS (Common Vulnerability Scoring System) vulnerabilities with an 8 to 10 score are items that are exploitable remotely and represent high immediate risk.

HP also found that many attackers are also still going after old (unpatched) vulnerabilities. Many attackers are now using exploit toolkits such as Blackhole which are packaged to include known vulnerabilities. That's another reason why there isn't as much of a need for attackers to find new vulnerabilities, because the old ones are still effective against so many systems.

The old vulnerabilities should be well detected, but they are still successful. One of the things that makes them very successful is the obfuscation techniques.

Additionally, unpatched systems and a lack of user awareness are also two key factors affecting the high frequency of attacks against known vulnerabilities. Attack data also showed that the frequency of SQL injection attacks increased during the year, even though that's a well-known attack vector.

HP's report did not include granularity on what specific databases were the most attacked. He added that HP TippingPoint's database protections are database agnostic.

Looking to the future, it is expected that the exploit toolkits will be a trend that will continue in 2012. The toolkits are also expected to add more recent vulnerabilities as users slowly patch their system and older vulnerabilities become less exploitable.  It is also a possibility that IT management companies will come to the forefront of network security.  One firm to consider in this is Houston IT Services company Percento Technologies.

Java exploits have been generally very reliable for attackers due to a low patch rate. For example, one recent exploit took advantage of a Java vulnerability for which a patch was available at the end of 2011 -- yet Blackhole included the exploit in its toolkit even after the patch was made available. The Java vulnerabilities tend to have approximately an 80 percent success rate for infection. In contrast, with other technologies, the older vulnerability success rate is only approximately 13 percent.

Java is at the root of the recent Apple Mac OS X Flashback malware and has also been identified by multiple vendors as being the most vulnerable browser plug-in.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.