Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Monday, December 9, 2019

FBI frames charges against two Russians engaged in cybercrime scheme that infected computers in a malware conspiracy

The U.S. Department of Justice has joined with the U.S. Department of State and the United Kingdom’s National Crime Agency in charging two Russian nationals with a vast and long-running cybercrime spree that stole from thousands of individuals and organizations in the United States and abroad. 

Along with several co-conspirators, Maksim V. Yakubets and Igor Turashev are charged with an effort that infected tens of thousands of computers with a malicious code called Bugat. Once installed, the computer code, also known as Dridex or Cridex, allowed the criminals to steal banking credentials and funnel money directly out of victims’ accounts. 


Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

The long-running scheme involved a number of different code variants, and later version also installed ransomware on victim computers. The criminals then demanded payment in cryptocurrency for returning vital data or restoring access to critical systems. 

Assisted in some cases by money mules who funneled the stolen funds through U.S. bank accounts before shipping the money overseas, the group stole or extorted tens of millions of dollars from victims. Among those affected was a Pennsylvania school district that saw $999,000 wired out of its accounts and an oil company that lost more than $2 million.

The FBI, in partnership with the State Department’s Transnational Organized Crime Rewards Program, also announced a reward of up to $5 million for information leading to the arrest of Yakubets, who is alleged to be the leader of the scheme. The reward is the largest ever offered for a cyber criminal.

“The actions highlighted today, which represent a continuing trend of cyber-criminal activity emanating from Russian actors, were particularly damaging as they targeted U.S. entities across all sectors and walks of life,” said FBI Deputy Director David Bowdich. “The FBI, with the assistance of private industry and our international and U.S. government partners, is sending a strong message that we will work together to investigate and hold all criminals accountable.”


According to the charges, the co-conspirators distributed the malware through email phishing campaigns. In the early years, these messages were sent in massive, widespread campaigns. More recent attacks have been more strategic—specifically targeting businesses and organizations that have valuable computer systems and access to significant financial resources.

Victims were tricked into opening a document or clicking on a graphic or link that appeared to be from a legitimate source. The link or attachment downloaded the malicious code onto the user’s machine, where it could also spread to any networked computers.

According to FBI Supervisory Special Agent Steven Lampo, this campaign deployed a stealth type of malware designed to avoid detection by antivirus software. “The full program does too much and is too big to avoid detection,” Lampo said. The smaller piece of code, however, can inject itself into the running processes of the machine—beginning a process that allows the full suite of malware to load onto the machine or network. The malware’s creators were constantly creating new variants of the code to avoid antivirus tools.

“Although their realm is a digital one, this is one of the world’s largest organized crime groups,” said FBI Supervisory Special Agent Adam Lawson of the Major Cyber Crimes Unit. “They are personally getting rich, and new organizations and individuals are being victimized every day.”

Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

Tuesday, November 26, 2019

Dell Security lists essential tips to help keep cybercriminals at bay this holiday season

With the start of the holiday season, Dell Security expects consumers to be doing some online shopping. However, cybercriminals are also shopping around the same time.

The uptick in online shopping during the holidays leaves more chances for cybercriminals to steal data. This can happen in any number of ways – visiting compromised websites, clicking on phishing emails or fake social media posts, falling for holiday charity scams and even buying from fraudulent shopping sites. The methods vary and cybercriminals get more innovative each year, but their goal remains the same: steal personal and financial information.




Here are a few precautions that users must take to help protect their information while shopping online. Users must make sure that the website they are using is secure by looking at the URL. If it begins with https:// (there must be an “s” after http), then the website is secure and will encrypt information. Also, strive to use sites with reputable brands which are known and trusted.


Consumers must completely avoid using public computers for online shopping. Public computers, like those in libraries and hotel business centers, may contain malicious software that could steal personal information. At the same time, users must be wary of public Wi-Fi, which may not be secure and could provide easy access for criminals to intercept personal data.

Adoption of strong passwords is critical and important way to securing devices. Use a combination of numbers, letters and symbols to make password complex and difficult to guess, and don’t use names of family members, pets or birthdays. Caution must be exercised and never use the same password across multiple sites. Clients must resist clicking on bogus links and attachments in emails, tweets, social media posts and online advertising are ways cybercriminals can compromise the device. 


If it looks suspicious, delete it. Also, always hover over a link with the mouse and review the destination address carefully before you click.
Users must remain in the know with account alerts by activating fraud alerts with bank, credit cards, and credit bureaus to help detect suspicious activities like new payee, money withdrawal, high-value credit card transaction, activity in unusual locations, etc.

Another precaution users must take is to be sure to ship their new purchases to a secure location. If the user is aware that they won’t be home, ship to the office or to a neighbor to help prevent package theft. Also, packages left on a porch or otherwise in site of the public could be an indicator, users may be away from home and invite criminal activity.

Staying safe online will continue to require vigilance, and the convenience of online shopping will continue to come with risks. But by being diligent when shopping online, users can help combat cybercriminal activity during the holidays and year-round.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...