What the Hack? March 2022
www.seconcyber.com
Secon
02
Ukraine security advisory and guidance. It’s been difficult to see the scenes of devastation in Ukraine. Like everyone this month, we’ve been keenly aware of the escalation of the conflict and our hearts and minds go out to everyone in Ukraine who are dealing with this affront to their personal safety and security. Additionally, we know there’s been a lot of uncertainty around cyber safety following the ongoing war in Ukraine. We understand that organisations are nervous about the increased cyber threat presented by this conflict and want to know how they can protect themselves. If you’d like to keep up to date with new developments in this cyber war, Security Affairs publishes weekly timelines of these attacks. You can read them here: 6 March - 12 March, 13 March - 19 March, 20 March - 26 March. By following resources such as these, you can stay on top of the latest security risks and advisories that may be applicable to your organisation. Additionally, the US’s Cybersecurity & Infrastructure Security Agency (CISA) issued a security advisory warning organisations outside the conflict zone that Russian state-backed hackers could potentially gain access to organisations by exploiting a default multifactor authentication (MFA) protocol and by taking advantage of the “PrintNightmare” vulnerability.
Vulnerability Scanning as a Service and Patching as a Service can help. •
You don’t want a disused account to be an open door for a bad actor. Ensure you’re continually disabling your inactive accounts across your entire network to stop them from being used as an access point for hackers. •
Multifactor authentication (MFA) CISA has warned that Russian state-sponsored cyber actors have already taken advantage of one NGO as far back as May 2021. By using a misconfigured account, the group set default MFA protocols, which allowed them to enrol a new device and access the entire network. Implementing MFA across your entire network should be high on your priority list already, but this recent example shows just how important it is. If you’re unable to implement MFA quickly, you should follow the NCSC’s guidance on strong passwords (using three random words), which you can read about here.
•
Patching Identifying and patching vulnerabilities will always be fundamental for cyber security best practice. In CISA’s example, once the NGO had been breached using the misconfigured account, the group exploited the critical vulnerability “PrintNightmare” and ran “arbitrary code with system privileges, and then were able to access cloud and email accounts for document exfiltration.” If you find it difficult to stay on top of the latest patches or don’t have the capacity to apply them quickly in-house, our
Continuous network log monitoring In the current climate, it’s best to assume breach. There is no such thing as 100% protection. The best way to protect yourself from a breach is to identify and respond at the earliest opportunity. In order to get to this position, it’s recommended to be constantly monitoring your security logs for any early indications of compromise. If you don’t have centralised visibility of your logs or your own in-house SOC, outsourcing to a trusted partner like Secon for Managed Detection and Response could be a solution.
•
Higher level of alert It is recommended to have a slightly raised level of cyber alertness during times like these. Ensure your processes are firing on all cylinders and take this time to re-evaluate your incident response and recovery plans.
In light of this security advisory and additional growing concerns, here are some tips and guidance we think every organisation should follow if they want to stay safe in today’s cyber climate. •
Disable unused accounts
•
Additional best practice tips and recommendations Although it can be nerve-wracking living through times of heightened cyber awareness, following general cyber security best practice recommendations is always the best course of action. You can view a list of these tips, which include blocking high-risk sign-in attempts and enforcing geolocation for all users, in our Lapsus$ recap on page 5 of this newsletter.
Ultimately, all these tips contribute to maintaining best practice and ensuring everything is up to date and configured correctly. If you’re looking for additional guidance or are unsure how you can address some of these areas, our team is more than happy to have a security consultation with you to determine how else you can protect your organisation. Additionally, we can provide you with a full Cyber Risk Assessment to identify the areas you can improve to reduce the risk of threats getting into your organisation. We’ll also assess your ability to both detect and recover from a potential cyber attack. Feel free to contact us today with any security questions or concerns and we’ll be happy to help.
What the Hack? - March 2022
03
How to simplify your security with Microsoft. On-demand webinar Organisations are spending more than ever on security and yet, the average time to detect a breach was 212 days in 2021. The problem is, despite increased spending, managing multiple different siloed security tools is extremely operationally intensive. Not only is it time consuming for your team to sift through the alerts generated by each of these tools, but you could also be missing early indications of compromise since they’re operating in isolation. In March, we ran a series of webinars on how organisations can centralise their cyber security with Microsoft to reduce both complexity and cost. If you missed the webinar and are curious how you can simplify your security without compromising on protection, you can click below to watch it on-demand.
How to stop email-borne ransomware. Upcoming webinar One of the main attack vectors for ransomware is email. If you want to stop it from infiltrating your organisation, you need to stop it at the root cause. Unfortunately, email gateways are struggling to keep up with new attacks and more emails are getting through — ultimately ending up in employees’ inboxes. Join one of our upcoming webinars on 5 April 14:00 or 7 April 10:00 with our partner Red Sift to learn how their solutions can help protect both your employees and your brand from emailborne ransomware threats. We’ll give you an overview of how you can stop domain impersonation attacks, detect new malicious variations of your domain, and alert employees of sophisticated malicious emails.
Register now
Secon
04
The vexing immortality of the world’s top malware. Insight recap Malware is here to stay. As soon as one malware gang is taken down, it seems like many more are on standby, ready to take its place. If we’re going to win the war against malware, especially in the midst of both real-world and cyber warfare between Russia and Ukraine, we need to know what we’re up against. In our most recent insight, Senior Security Engineer Mars Cacacho breaks down some of the top malware groups and discusses whether we’ve really seen the end of them. Here’s a summary, but you can read the full article here.
REvil - The king of ransomware In mid-2021, US President Joe Biden personally called on Vladimir Putin to crack down on ransomware gangs after a series of large-scale cyber fiascos like the Colonial Pipeline and Kaseya VSA attacks. It seemed like the request may have been heeded as news broke in January of FSB arrests of suspected REvil ransomware gang members. This concluded the yearlong joint chase of what was dubbed as Operation GoldDust, which involved law enforcement agencies in as many as 17 countries. However, have we seen the last of the members of REvil? Similar tactics have been spotted in other attacks, which leads to questions about whether memeber of the gang simply joined another ransom cartel.
Emotet - Revenge of the fallen Another group that was “taken down” was Emotet. The simultaneous seizure of valuable equipment, as well as arrest of key Ukrainian members, was meant to disarm the most prolific threat of the decade. Meanwhile, just few months after the apparent take down, in November of 2021 new sightings were observed and confirmed by both security companies and independent researchers, which evidently proved the resurgence of Emotet.
Trickbot – The sophisticated malware that resurrected Emotet Two years ago, and after infecting millions of computers, Trickbot C&C servers and domains were seized. However,
days after the orchestrated take-down from a coalition of security companies, the infrastructure has been replaced, and the havoc has continued. Regardless of multiple take-down efforts by authorities, Trickbot survived and remained intact. However, Trickbot has now formally dismantled its crimeware platform and ceased campaigns in 2022, with its core developers pirated by the Conti Ransomware crew. This marks the end of one of the most persistent malware skirmish series in recent history – or is more likely the calm before a looming, massive storm as Conti just grows stronger.
Russia’s Ukraine invasion, and how it changed the threat landscape Russia’s continued attacks on Ukraine are not only on land, but also through round-the-clock cyber attacks targeting vital infrastructure. Most of this cyber warfare is operating without direct orders from the Kremlin. To respond to this hybrid warfare, Ukraine has started its counterstrike by building an IT army of its own. A face-off between ransomware operators residing in Russia and Ukraine is something we anticipate, believing that their cyber prowess could further exacerbate each cyber front. Unfortunately, the cyber world is nothing but a vast, borderless space, and it’s just a matter of time before households, offices, businesses, and government organisations outside the RUS-UKR region will have to deal with the same threat strains.
What the Hack? - March 2022
05
What do I need to do about Lapsus$? March security news Some well-known brands including Microsoft, Samsung, and Okta have been compromised by hacking group Lapsus$. Do we need to be concerned and what can we do to reduce our risk? So far Lapsus$ has taken a very targeted approach. There’s evidence that they’re actively trying to recruit employees of telecommunications companies, large software/gaming companies, and call centre and server hosting providers. This approach allows Lapsus$ gain access and take advantage of these organisations’ business relationships with their customers and supply chain. Lapsus$ has been offering financial compensation to employees of these organisations in exchange for login credentials for VPN or RDP-related solutions at each targeted organisation. Once Lapsus$ has established access using the acquired VPN or RDP credentials, their mode of operation is to move laterally by exploiting unpatched vulnerabilities on internally accessible servers. They then search code repositories for further credentials and intellectual property. After exfiltration, the group has also been known to delete the target’s systems and resources. The aim is to trigger the organisation’s incident response process. The group then goes on to join the organisation’s incident response calls and internal discussion chat forums. But what you can do? As always, cyber security best practice applies, especially with regards to vulnerability management, identity & access management, and security monitoring. To keep yourself protected from Lapsus$, you should: •
Enforce multifactor authentication for all users accessing your environment. It’s advised to avoid MFA solutions that leverage SMS.
•
Ensure all devices with access to your environment are trusted, patched, and running up to date security software before granting access.
•
Ensure least privileged access for all your administrator and service accounts.
•
Ensure you are proactively scanning for and patching vulnerabilities across all your IT assets.
•
Strengthen and monitor your cloud security posture.
•
Monitor logs for suspicious activity 24×7 with particular focus on any suspicious activity related to identities and access. Block any medium or
high-risk sign-in attempts, or other tenant wide security configuration changes. •
Encourage your users to report any suspicious or unusual contact from your organisation’s help desk or third-party IT/ application service providers.
•
Enforce geolocation for all users when using a VPN and force all VPN connections to route the connecting device’s internet connection to the firewall’s network.
•
Set your VPN solution to have certain conditional access requirements via compliance before a user can connect to the VPN.
•
Understand your estate’s internet bound traffic and document behaviour to easily flag suspicious traffic.
Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707
www.seconcyber.com