Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Saturday, October 11, 2014

Hackers Use Google, Too?

Google is everyone's favorite search engine and it seems hackers love it, too! An article from Network World informed us that Google's many free services have recently been discovered to have been used by hackers to disguise data that was stolen from corporations and government computers. This form of attack has been deemed the Poisoned Hurricane. It uses a remote access tool known as Kaba, to infect systems and steal data. 
The unfortunate victims of this attack are US and Asian based companies and governments. The hackers used spear phishing attacks to compromise various systems, then installed malware to steal information and send it to remote servers. This type of attack is very unique according to Network World's Gonsavles because it "disguised traffic between the malware and command-and-control servers using Google developers and the public Domain Name System (DNS) service of Fremont, Calif. based, Hurricane Electric."
This is used as a sort of transfer station where traffic could be redirected and seemed to be headed toward legitimate domains such as adobe.com, update.adobe.com and outlook.com.  
These tactics are "clever enough to trick a network administrator into believing the traffic was heading to a legitimate site" claims Gonsalves. Hackers used forged HTTP's that identified with 21 legitimate domain names, and then would sign the Kaba malware up with a certificate from an expired organization. 
The hackers used both a Google Developer Platform along with Hurricane Electrics Platform to transfer the stolen data. Through the Google Developers platform, developers can use the site to share code. This is where the attackers used the service to host code that would decode the malware traffic and determine the IP address for the real destination, and then redirect the traffic to that location. 
With Hurricane Electric, the hackers took advantage of the fact that anyone can register for an account hosted DNS service, and this service allowed the hackers to "create A records for the zone and point them to any IP address" (Gonsalves). Google and Hurricane Electric have since removed the mechanisms that the hackers used. 
Hackers are becoming very creative in their means of attacks and have proven to use common resources to do so. Be very aware of these new tactics in order to know how to protect yourself from these data breaches.  
To learn how TCG can help protect your business from data breaches and other attacks, visit our Business Continuity Page! 
To read the full article, visit the page!
Gonsalves, Antone. “How hackers used Google in stealing corporate data.” Network World.  8 August, 2014. Online. 

Wednesday, June 18, 2014

Cyberattack Insurance

 As business owners working in a system that revolves around technology and online data, it is becoming essential for businesses to purchase Cyber Insurance. Today, over 50 different carriers provide Cyber Insurance to protect companies against online attacks and the accrued losses. What companies are realizing though is that the insurance is not nearly enough to fully protect the companies, and there are major obstacles for both businesses and insurance. 
      The first major issue both insurance companies and insured companies are facing is that there is not enough historical data to help insurers appropriate an estimate for how much a company would need to be insured for. In the past, many data breaches have either gone unnoticed or were not reported publicly in order to avoid damaged reputation, but that has left insurance companies with very little reliable data. Also, attacks are becoming more and more advanced as time goes on, and so the data that the insurers do have is often outdated and no longer applicable. Past statistics are now almost irrelevant. 
     Last year, the total amount of Cyber Insurance paid was $1.3 Billion. Cyber Insurance numbers are significantly smaller in comparison to that of Property Damage Insurance. Most current insurance plans only cover clean-up costs such as attorney fees, implemented call centers and other steps to help stabilize the company after the breach takes place, but since they cannot estimate how much it would be needed to cover losses, the insurance is limited. Larger corporations are trying to take much more caution and buying millions of dollars’ worth of insurance, hoping to be able to cover any major damages done, but small or medium sized companies are still left with less coverage and greater risk. 
    The second major issue that insurance has almost no ability to fix is the intangible effects a data breach can have on a company. Loss of trust from customers, damage to a brand or company reputation can create far greater losses for a company. Unfortunately, there is no accurate way to estimate what those effects will have on a company. If we look at the case of Target, their brand reputation was seriously injured and many customers no longer trust shopping at their stores. Also, the Cyber Insurance that Target did have cannot fully cover the charges that Target is trying to repay to its customers along with the changes it is trying to make to the company to ensure this type of attack cannot happen again. 
      One tactic that Insurance companies are trying to use in order to better get an idea of an estimate for a company is to hire a hacker and have them find the weak spots in a company’s website in order to get some idea of what their risk would be, but even this is not a completely accurate plan, since cyber criminals are constantly changing their tactics and moving to more advanced technology. Also, with more and more companies joining cloud computing, it is still unsure whether or not this will be safer for companies or create greater risk. In cloud computing, one breach could potentially damage many companies at once, and the new cyber Insurance Industry needs to figure out how to protect these companies as best they can. 

To read more about Cyberattack Insurance, check out the full article from the New York Times.
To learn how TCG can also help insure your company is protected from Cyberattacks, check out our Business Coninuity page and our Systems Management page and see how TCG can provide peace of mind for your business!

Update on Malvertising:Ransomware

  It seems that criminals no longer need to kidnap a family member to demand a ransom; instead, internet criminals have developed a ransomware to go after your money. Most internet users know to be weary of certain websites and advertisements in order to protect your computer from viruses and having malware downloaded. However, malicious advertisements have now started to appear on common domains such as Disney, Facebook, and the Guardian newspaper websites
     Most internet users believe these major sites to be a safe place to browse and check out the various interest-based advertisements, but Cisco Systems recently discovered while monitoring their own user's browsing, that certain advertisements on popular domains are being tampered with by an outside third party. The malicious advertisements are rerouting users to another domain and instantly installing a Rig Exploit Kit after guessing the users login's and passwords. Once installed, the malware locks all of the user’s data access and installs a ransomware called Cryptowall that demands a ransom from the user in order to regain full access to the user’s data. 
     Cisco recently worked with law enforcement to shut down some of these attacks, but they have not been able to learn who is behind the attacks, and how to fully stop them from happening. The problems that arise is that these malvertisements are extremely difficult for websites to detect or even know that they are being tampered with by an outside party. Along with that, these attacks could be made by more than one person, making it more difficult to track exactly where the source of these attacks are coming from. Finally, with the constant changes and upgrades in software and technology, unraveling these attacks and understanding them is only getting increasingly more difficult as time goes on. Law enforcement and Cisco are still working towards a solution. 
      As internet users, it is important to note that the malware seeks out users who are running unpatched versions of Flash, Java or Silverlight Mutlimedia programs. Also, if ransomware is installed into your computer, the longer you wait to pay, the larger the ransom becomes, so be sure to alert authorities immediately! As tempting as it is to be seduced by Facebook and Disney's online advertising, with the danger of Malvertising on the rise and the threat of Ransomware, take caution on what advertisements you decide to click on, or simply avoid them altogether. 

To learn more about Malvertising and Ransomware, read the full article at Network World.
To learn how TCG can help protect your business from internet criminals, check out our Business Continuity page and our Systems Management page.