Showing posts with label URL. Show all posts
Showing posts with label URL. Show all posts

Friday, December 20, 2019

Emotet security attack causes shutdown of Frankfurt’s IT network

The city of Frankfurt, Germany, became the latest victim of Emotet after an infection forced it to close its IT network. But the financial center wasn’t the only area that was targeted by Emotet, as there were also incidents that occurred in Gießen and Bad Homburg, a town and a city north of Frankfurt, respectively, as well as in Freiburg, a city in southwest Germany.

The infection started after an employee of the Fechenheim (a district in Frankfurt) civil registry clicked on an Emotet-laden attachment from a malicious spam email, apparently sent by a city authority. Alarms were raised by the security system, prompting officials to restrict city services and take the IT system off the network as a precautionary measure.  


Germany has been a frequent target over the past few weeks by threat actors employing Emotet, and in general has been a target for malicious activity this year, according to data from the Trend Micro Smart Protection Network infrastructure. In fact, the German Federal Office for Information Security (BSI) issued a press release warning the public about malicious spam emails that carry Emotet.

First detected in 2014, Emotet has become one of the most notorious malware families of the past few years. Its original iteration was as an information-stealing banking malware — however, it has since undergone multiple evolutions, including acting as a loader for other malware families. It went into hiatus earlier in the year but came back after a few months with a vengeance. This recent spate of attacks on Germany is likely a continuation of Emotet’s comeback campaigns.

Despite all the changes Emotet has undergone, spam mail remains the malware’s most prominent distribution method. The key strategy organizations can implement is to educate their employees regarding email threats and to encourage them to follow the recommended security best practices when accessing their emails. This includes always double-checking an email for any red flags, as well as refraining from clicking any links or downloading any attachments haphazardly.

Combating threats like Emotet calls for a multilayered and proactive approach to security that involves protecting all fronts — gateway, endpoints, networks, and servers. Trend Micro endpoint solutions such as Trend Micro Smart Protection Suites and Worry-Free Business Security can protect users and businesses from these threats by detecting malicious files and spammed messages, as well as blocking all related malicious URLs.

To bolster their security capabilities and further protect their end users, organizations can consider security products such as the Trend Micro Cloud App Security solution, which uses machine learning (ML) to help detect and block spam and phishing attempts. 

If a malicious email is received by an employee, it will go through sender, content, and URL reputation analysis, which is followed by an inspection of the remaining URLs using computer vision and AI to check if website components are being spoofed. The solution can also detect suspicious content in the message body and attachments and provide sandbox malware analysis and document exploit detection.

Anomali, Trend Micro identify credential harvesting campaign targeting government procurement sites

Multiple government procurement services were targeted by a credential harvesting campaign that uses bogus pages to steal login credentials. Cybersecurity company Anomali uncovered a campaign that used 62 domains and around 122 phishing sites in its operations and targeted 12 countries, including the United States, Canada, Japan, and Poland.

The Anomali Threat Research Team identified a credential harvesting campaign designed to steal login details from multiple government procurement services. The procurement services are used by many public and private sector organisations to match buyers and suppliers. 


In this campaign, attackers spoofed sites for multiple international government departments, email services and two courier services. Lure documents sent via phishing emails were found to contain links to spoof phishing sites masquerading as legitimate login pages relevant to the spoofed government agencies. Victims duped into following the phishing email link would then be invited to login. Anyone who fell victim to the adversaries would have provided them with their credentials.

This credential harvesting campaign has been primarily targeting government bidding and procurement services. The focus on these services suggests the threat actor(s) are interested in potential contractor(s) and/or supplier(s) for those governments targeted. The purpose of this insight could be a financial incentive to out compete a rival bidder, or more long term insight regarding the trust relationship between the potential supplier and the government in question. 


Campaigns like these are difficult to protect against because unless the domains hosting the phishing pages are known as malicious, an organisations firewall will not know to block it. Legitimate sites were also hosting the phishing pages, and were likely compromised as part of the campaign. At the time of writing none of the sites in this campaign were active, Anomali researchers consider it likely that the actors will continue to target these services in the future.

The use of bogus login pages continues to be a popular method for credential harvesting campaigns. The Trend Micro Cloud App Security solution blocked 2.4 million attacks of this type in the first half of this year — a 59 percent increase from 1.5 million in the second half of last year.

Organizations should look into adopting advanced technologies such as the Trend Micro Cloud App Security solution. It combines artificial intelligence (AI) and computer vision in order to help detect and block attempts at credential harvesting in real time. 

After suspected phishing emails go through sender, content, and URL reputation analyses, computer vision technology and AI will examine the remaining URLs to check if a legitimate login page’s branded elements, login form, and other website components are being spoofed.

For this campaign, threat actors used phishing emails carrying documents written in the language of the country being targeted. The phishing emails were also found with URLs to fake but legitimate-looking login pages. If the recipient of the phishing email clicks on the malicious URL, they will be redirected to a login page that is an imitation of a legitimate website the campaign is spoofing. A login attempt will then lead to the theft of the user’s credentials.


Aside from the websites of international government departments, those belonging to email services and two courier services were also spoofed by the threat actors. The U.S. Department of Energy, Canada’s Government eProcurement service, China’s SF-Express courier service, and Australia’s Government eProcurement Portal were some of the target organizations.

Email users should always be aware of the latest phishing tactics in order to avoid falling victim to credential harvesting attacks. After all, such attacks are becoming highly deceptive; in fact, it has become relatively easy for cybercriminals to obtain a .gov domain that they can use to further disguise their schemes.

To minimize the chance of becoming a victim, users can be cautious of emails from individuals or organizations that ask for personal information. Most companies will not ask for sensitive data from its customers, especially with stricter data privacy laws; look out for grammatical errors and spelling mistakes in suspicious emails. Emails from legitimate companies are often proofread to ensure that the materials they send out are error-free. 

Emails that call on a sense of urgency or have an alarmist tone should not be hastily acted on. If in doubt, recipients should verify the status of their accounts with their company’s system administrator or service provider.

Friday, December 13, 2019

Barracuda boosts MSP offerings through integration of Content Shield Web Security Solution and Managed Workplace RMM

Barracuda Networks announced that it has integrated Barracuda Content Shield with Managed Workplace, its remote monitoring and management (RMM) platform. Managed service providers (MSPs) using the RMM can now leverage the cloud-based web security solution’s web filtering and malware protection to better protect their customers’ end users from web-borne threats. 


Barracuda Content Shield is a SaaS-based solution available at a per-user pricing model, which makes it easier for MSPs to scale based on demand.

Offering content filtering, malware protection, granular policy enforcement and reporting, Barracuda Content Shield works with existing antivirus (AV) solutions to protect against malicious files, stopping malware before it reaches the endpoint.


This integration helps MSPs enhance their end-user online security service offering with agent-based DNS and URL filtering; help protect their customers’ end-users from web-borne threats; and get at-a-glance visibility into threats prevented across all customers.

Additionally, through the combination of the two tools, MSPs will benefit from a centralized view of the threats detected and quarantined. If threats such as malicious files, domains, or URLs are discovered on any device connected by Barracuda’s threat intelligence network, every user is protected against that threat. 


“A recent survey by Spiceworks found that when companies don’t restrict internet activity, 58 percent of employees will spend at least four hours per week on websites unrelated to their jobs,” said Brian Babineau, senior vice president and general manager, Barracuda MSP. “And earlier this year, a study found that 40 percent of malicious URLs were located on good domains. These and other statistics point to the need for robust, easy-to-manage web content filtering that protects end-users from web-borne threats. Barracuda is answering that call with the integration of Barracuda Content Shield within Managed Workplace, a move that illustrates our commitment to providing our partners with a broad portfolio of security and data protection solutions spanning web, network, and e-mail, and backed by our global threat intelligence.”

Trend Micro warns Android users on malicious Christmas-themed shopping, game and chat apps that lure users with deals

Security researchers from Trend Micro have cautioned Android users when downloading apps for shopping, games, and Santa video chats as they found hundreds of malicious apps likely leveraging the season to defraud unwitting victims. 

A scan of thousands of apps revealed seven with malicious routines such as replacing the legitimate apps with a version downloaded from a command and control (C&C) server. They also found 35 apps containing adware with more invasive behaviors than standard in-app advertisements, and 165 apps enabling “excessive or dangerous combinations of permissions,” such as camera, microphone, contacts and text messages. 


Researchers from Barracuda Networks recommend that users examine the apps they download to their phones, especially as online shopping and banking are expected to reach new heights this year.

Invasive adware were reportedly related to DIY gift projects and used suspicious ad networks by displaying catchy deals and coupons. Cybercriminals can go after banking, email, and access credentials by replacing legitimate website forms, or by using malware or injected skimmers

The researchers noted the excessive permissions that users may grant apps can be used to steal stored information from the devices such as contacts for phishing and spam campaigns, as well as banking authentication tokens via SMS messages when shoppers finalize their purchases online.

When downloading apps and shopping online, users must check app reviews on reputable websites; review access permissions being requested by the app and evaluate if they are necessary for the functions of the app; directly type the retailers’ websites, and avoid clicking on URLs found in emails and text messages, especially from unknown senders; limit the amount of personal information provided to websites and apps; and regularly update devices’ operating systems and apps.


Users and enterprises can take advantage of multilayered mobile security such as the Trend Micro Mobile Security for Android solution. Trend Micro Mobile Security for Enterprise provides device, compliance and application management, data protection, and configuration provisioning, as well as protects devices from attacks that exploit vulnerabilities, prevents malicious and unauthorized access to apps, and detects and blocks malware and fraudulent websites. 

Trend Micro’s Mobile App Reputation Service (MARS) covers Android threats using leading sandbox and machine learning technologies, protecting devices against malware, zero-day and known exploits, malicious apps, privacy leaks, and application vulnerabilities.

Tuesday, November 26, 2019

Dell Security lists essential tips to help keep cybercriminals at bay this holiday season

With the start of the holiday season, Dell Security expects consumers to be doing some online shopping. However, cybercriminals are also shopping around the same time.

The uptick in online shopping during the holidays leaves more chances for cybercriminals to steal data. This can happen in any number of ways – visiting compromised websites, clicking on phishing emails or fake social media posts, falling for holiday charity scams and even buying from fraudulent shopping sites. The methods vary and cybercriminals get more innovative each year, but their goal remains the same: steal personal and financial information.




Here are a few precautions that users must take to help protect their information while shopping online. Users must make sure that the website they are using is secure by looking at the URL. If it begins with https:// (there must be an “s” after http), then the website is secure and will encrypt information. Also, strive to use sites with reputable brands which are known and trusted.


Consumers must completely avoid using public computers for online shopping. Public computers, like those in libraries and hotel business centers, may contain malicious software that could steal personal information. At the same time, users must be wary of public Wi-Fi, which may not be secure and could provide easy access for criminals to intercept personal data.

Adoption of strong passwords is critical and important way to securing devices. Use a combination of numbers, letters and symbols to make password complex and difficult to guess, and don’t use names of family members, pets or birthdays. Caution must be exercised and never use the same password across multiple sites. Clients must resist clicking on bogus links and attachments in emails, tweets, social media posts and online advertising are ways cybercriminals can compromise the device. 


If it looks suspicious, delete it. Also, always hover over a link with the mouse and review the destination address carefully before you click.
Users must remain in the know with account alerts by activating fraud alerts with bank, credit cards, and credit bureaus to help detect suspicious activities like new payee, money withdrawal, high-value credit card transaction, activity in unusual locations, etc.

Another precaution users must take is to be sure to ship their new purchases to a secure location. If the user is aware that they won’t be home, ship to the office or to a neighbor to help prevent package theft. Also, packages left on a porch or otherwise in site of the public could be an indicator, users may be away from home and invite criminal activity.

Staying safe online will continue to require vigilance, and the convenience of online shopping will continue to come with risks. But by being diligent when shopping online, users can help combat cybercriminal activity during the holidays and year-round.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...