Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Monday, 30 September 2013

Smart spear phishing could kill the power grid, experts warn

While the energy industry may fear the appearance of another Stuxnet on the systems they use to keep oil and gas flowing and the electric grid powered, an equally devastating attack could come from a much more mundane source: phishing.

Rather than worry about exotic cyber weapons like Stuxnet and its big brother, Flame, companies that have Supervisory Control and Data Acquisition (SCADA) systems—computer systems that monitor and control industrial processes—should make sure that their anti-phishing programs are in order, say security experts.

"The way malware is getting into these internal networks is by social engineering people via email," Rohyt Belani, CEO and co-founder of the anti-phishing training firm PhishMe, said in an interview.

"You send them something that's targeted, that contains a believable story, not high-volume spam, and people will act on it by clicking a link or opening a file attached to it," he said. "Then, boom, the attackers get that initial foothold they're looking for."

In a case study cited by Belani, he recalled a very narrow attack on a single employee working the night shift monitoring his company's SCADA systems.

The attacker researched the worker's background on the Internet and used the fact he had four children to craft a bogus email from the company's human resources department with a special health insurance offer for families with three or more kids.

The employee clicked a malicious link in the message and infected his company's network with malware. "Engineers are pretty vulnerable to phishing attacks," Tyler Klinger, a researcher with Critical Intelligence, said in an interview.

He recalled an experiment he conducted with several companies on engineers and others with access to SCADA systems in which 26 percent of the spear phishing attacks on them were successful.

Success means that the target clicked on a malicious link in the phishing mail. Klinger's experiment ended with those clicks. In real life, those clicks would just be the beginning of the story and would not necessarily end in success for the attacker.

"If it's a common Joe or script kiddie, a company's [Intrusion Detection Systems systems will probably catch the attack," Klinger said. "If they're using a Java zero-day or something like that, there would be no defense against it."

In addition, phishing attacks are aimed at a target's email, which are usually located on a company's IT network. Companies with SCADA systems typically segregate them from their IT networks with an "air gap."

That air gap is designed to insulate the SCADA systems from the kinds of infections perpetrated by spear phishing attacks. "Air gaps are a mess these days," Klinger said. "Stuxnet taught us that."

"Once you're in an engineer's email, it's just a matter of cross-contamination," he added. "Eventually an engineer is going to have to access the Internet to update something on the SCADA and that's when you get cross-contamination."

Phishing attacks on SCADA systems are likely rare, said Raj Samani, vice president and CTO of McAfee's EMEA.

"I would anticipate that the majority of spear phishing attacks against employees would be focused against the IT network," Samani said in an interview. "The espionage attacks on IT systems would dwarf those against SCADA equipment."

Still, the attacks are happening. "These are very targeted attacks and not something widely publicized," said Dave Jevans chairman and CTO of Marble Security and chairman of the Anti-Phishing Work Group.

Jevans acknowledged, though, that most SCADA attacks involve surveillance of the systems and not infection of them. "They're looking for how it works, can a backdoor be maintained into the system so they can use it in the future," he said.

"Most of those SCADA systems have no real security," Jevans said. "They rely on not being directly connected to the Internet, but there's always some Internet connection somewhere."

Some companies even still have dial-in numbers for connection to their systems with a modem. "Their security on that system is, 'Don't tell anybody the phone number,'" he said.

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Friday, 27 September 2013

Apple is a tempting phishing target for scammers

Spam volumes took a usual seasonal drop in August, but phishing spiked, including a noticeable interest in hijacking Apple accounts.

Spam averaged 67.6 percent of all emails in August, down 3.6 percentage points compared to July, wrote Kaspersky Lab analysts Tatyana Shcherbakova and Maria Vergelis in a blog post. But 5.6 percent of those spam emails contained malicious attachments, an increase of 3.4 percentage points over a month prior.

The most prevalent malware program was "Trojan-Spy-html.Fraud.gen," which was in 8.1 percent of the emails containing malicious attachments. It's a very old piece of malware, first detected by Kaspersky Lab in 2004.

The malware is lodged inside a bogus HTML page that imitates a registration form for banks or payment services. It asks a victim for account information or personal information, which is then sent to a hacker.

The top 10 most common malicious attachments for August included four "ransomware" programs, which aim to extract money by locking victims' files or falsely warning they've been viewing illegal material.

The ransomware programs block "the work of the operating system and display a banner that gives instructions on how to unblock the computer. For example, the user is told to send a text message with a specific text to a premium-rate number," the analysts wrote.

Two other very old email worms, Bagle and Mydoom, also made the top 10. After infecting a computer, Bagle infiltrates a person's email contact list and sends itself out repeatedly. It was the third-most-common malware in August even though it was also discovered in 2004.

Two variations of Mydoom took the eighth and tenth places. Like Bagle, Mydoom also collects email addresses from infected computers and emails itself.

Phishing attacks rose tenfold, Kaspersky said, but still only amounted to a tiny fraction of overall spam, at .013 percent. Apple was one of the main phishing targets.

"We frequently came across emails that supposedly came from the official address of the company, but which in fact were phishing messages designed to deceive users and steal their logins and passwords," Kaspersky wrote.

Some of the phishing emails, which purported to come from the "Apple Security Center," warned users that their accounts had been frozen and that they have 48 hours to confirm their details.

Users are instructed to click on a link in the fraudulent email. "However, both the request to confirm the account information on third-party sites and the absence of a personal address should alert users to the risk of fraud," according to the post.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here

Thursday, 29 August 2013

Spear phishing led to DNS attack against New York Times, Twitter, others

The cyber attack that resulted in nytimes.com and some other high-profile websites being inaccessible to a large number of users Tuesday started with a targeted phishing attack against a reseller for Melbourne IT, an Australian domain registrar and IT services company.

The attack resulted in hackers changing the DNS (Domain Name System) records for several domain names including nytimes.com, sharethis.com, huffingtonpost.co.uk, twitter.co.uk and twimg.com -- a domain owned by Twitter -- Jaime Blasco, director of the research lab at security firm AlienVault, said Tuesday in a blog post.

[ Get your websites up to speed with HTML5 today using the techniques in InfoWorld's HTML5 Deep Dive PDF how-to report. | For a quick, smart take on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. ]

This resulted in traffic to those websites being temporarily redirected to a server under the attackers' control.

Hackers also made changes to the registration information for some of the targeted domains, including Twitter.com. However, Twitter.com itself was not impacted by the DNS hijacking attack.

A hacker group called the Syrian Electronic Army (SEA) that publicly supports Syrian President Bashar al-Assad and his government took credit for the attack via Twitter. During the past several months the group broke into the websites or Twitter accounts of several media organizations including the Financial Times, the Associated Press, The Guardian, BBC, and Al Jazeera.

Initial information suggested that the systems of Melbourne IT, the company through which all of the affected domain names were registered and administered, might have been hacked. However, the company later revealed that it was one of its resellers whose account was actually compromised.

"The credentials of a Melbourne IT reseller (username and password) were used to access a reseller account on Melbourne IT's systems," Tony Smith, general manager of corporate communications at Melbourne IT, said Wednesday via email. "The DNS records of several domain names on that reseller account were changed, including nytimes.com."

The name of the reseller was not disclosed.

According to Smith, the affected DNS records have been reverted back to their original values and have been locked from further modification at the .com registry level. The .com registry and DNS zone are operated by VeriSign.

In a subsequent statement sent via email, Bruce Tonkin, the chief technology officer of Melbourne IT, revealed that the compromise was the result of a targeted phishing attack that might have affected multiple accounts.

"We have obtained a copy of the phishing email and have notified the recipients of the phishing email to update their passwords," Tonkin said Tuesday via email. "We have also temporarily suspended access to affected user accounts until passwords have been changed."

Some users likely remained affected by the attack even after the DNS records were corrected by Melbourne IT in its system, as the recursive DNS servers of their ISPs continued to serve the compromised records from cache until their time-to-live (TTL) value expired. Because of caching, DNS record changes can take up to 24 hours to propagate through the entire Internet.


View the original article here

Spear phishing led to DNS attack against the New York Times, others

The cyberattack that resulted in nytimes.com and some other high-profile websites being inaccessible to a large number of users Tuesday started with a targeted phishing attack against a reseller for Melbourne IT, an Australian domain registrar and IT services company.

The attack resulted in hackers changing the DNS (Domain Name System) records for several domain names including nytimes.com, sharethis.com, huffingtonpost.co.uk, twitter.co.uk and twimg.com—a domain owned by Twitter—Jaime Blasco, director of the research lab at security firm AlienVault, said Tuesday in a blog post.

This resulted in traffic to those Websites being temporarily redirected to a server under the attackers’ control.

Hackers also made changes to the registration information for some of the targeted domains, including Twitter.com. However, Twitter.com itself was not impacted by the DNS hijacking attack.

A hacker group called the Syrian Electronic Army (SEA) that publicly supports Syrian President Bashar al-Assad and his government took credit for the attack via Twitter. During the past several months the group broke into the websites or Twitter accounts of several media organizations including the Financial Times, the Associated Press, The Guardian, BBC, and Al Jazeera.

Initial information suggested that the systems of Melbourne IT, the company through which all of the affected domain names were registered and administered, might have been hacked. However, the company later revealed that it was one of its resellers whose account was actually compromised.

”The credentials of a Melbourne IT reseller (username and password) were used to access a reseller account on Melbourne IT’s systems,” Tony Smith, general manager of corporate communications at Melbourne IT, said Wednesday via email. “The DNS records of several domain names on that reseller account were changed, including nytimes.com.”

The name of the reseller was not disclosed.

According to Smith, the affected DNS records have been reverted back to their original values and have been locked from further modification at the .com registry level. The .com registry and DNS zone are operated by VeriSign.

In a subsequent statement sent via email, Bruce Tonkin, the chief technology officer of Melbourne IT, revealed that the compromise was the result of a targeted phishing attack that might have affected multiple accounts.

”We have obtained a copy of the phishing email and have notified the recipients of the phishing email to update their passwords,” Tonkin said Tuesday via email. “We have also temporarily suspended access to affected user accounts until passwords have been changed.”

Some users likely remained affected by the attack even after the DNS records were corrected by Melbourne IT in its system, as the recursive DNS servers of their ISPs continued to serve the compromised records from cache until their time-to-live (TTL) value expired. Because of caching, DNS record changes can take up to 24 hours to propagate through the entire Internet.

DNS hijacking attacks can affect users beyond just preventing them from accessing a website, because they also allow attackers to redirect users to malicious content. According to Matthew Prince, CEO of CloudFlare, a company that provides website optimization and security services, this actually happened during this particular attack.

”Technical teams from CloudFlare, OpenDNS and Google jumped on a conference call and discovered what appeared to be malware on the site to which the NYTimes.com site was redirected,” Prince said Tuesday in a blog post.

”The registrar of the primary domain the Syrian Electronic Army was using as a name server for the domains they hacked revoked the domain’s registration this afternoon,” he said. “Since the cache TTL on the domain was relatively short, shortly after the domain was revoked traffic largely stopped flowing to the malware infected sites.”

Prince and CloudFlare did not immediately respond to an inquiry seeking more information about the type of malware that had been served during the attack.

In order to prevent rogue modification of DNS records, domain owners can ask their registrars to put registry locks in place for their domains, like Melbourne IT did for nytimes.com and the other affected websites. This lock is placed at the registry level, meaning with those companies that administer the .com, .net, .org, and other domain extensions.

”Registrars generally do not make it easy to request registry locks because they make processes like automatic renewals more difficult,” Prince said. “However, if you have a domain that may be at risk, you should insist that your registrar put a registry lock in place. It’s worth noting that while some of Twitter’s utility domains were redirected, Twitter.com was not—and Twitter.com has a registry lock in place.”

SEA claimed Wednesday on Twitter that they hacked Melbourne IT’s blog site. A message left on the site read “Hacked by SEA, Your servers security is very weak,” suggesting that the hacker group might still have some level of access to Melbourne IT’s systems.


View the original article here

Monday, 19 August 2013

British royal baby's birth drafted as phishing bait

It may be old news now, but hackers are still using news of the U.K. royal baby's birth to entice people into clicking on malicious links, according to researchers at Trend Micro.

When the official announcement was made on July 22, the researchers spotted plenty of spammed messages related to the birth of Price George. In a statement, they described the speed with which this spam hit the Internet as "remarkable."

"These messages appear to be from ScribbleLive, a service that provides real-time engagement platforms.

phishingThe false page (click to enlarge)

The offer, of course, is false, and clicking on links in the email will only trigger multiple redirections that are typical among Blackhole exploit kit (BHEK) spam runs," the researchers said.

BHEK is a page that cybercriminals use to determine what software versions are used by a victim so that the page can deliver the "correct" exploit. Generally, people using outdated software are more at risk of being caught by exploits.

In this case, the script that triggers the redirections is detected as JS_OBFUSC.BEB, the researchers said. This particular exploit targets two vulnerabilities in Java: CVE-2013-1493 and CVE-2013-2423. Both of these vulnerabilities have been patched by Oracle, though many people still run on older versions of Java.

Trend Micro described this technique of taking advantage of current affairs as a social engineering lure, adding that they often come in the form of highly publicized events. The researchers gave the Boston Marathon incident and the election of Pope Francis as prime examples. What's more, they said, hackers take advantage of more than one big news story at a time.

"This particular BHEK run is not limited to the royal baby alone. Other spammed messages took advantage of the controversy surrounding the upcoming sci-fi film Ender's Game," they said.

"While these messages are made to look like an article from CNN, clicking on links will trigger the same redirections as that of the royal baby spam."


View the original article here