Showing posts with label endpoint. Show all posts
Showing posts with label endpoint. Show all posts

Friday, December 20, 2019

Emotet security attack causes shutdown of Frankfurt’s IT network

The city of Frankfurt, Germany, became the latest victim of Emotet after an infection forced it to close its IT network. But the financial center wasn’t the only area that was targeted by Emotet, as there were also incidents that occurred in Gießen and Bad Homburg, a town and a city north of Frankfurt, respectively, as well as in Freiburg, a city in southwest Germany.

The infection started after an employee of the Fechenheim (a district in Frankfurt) civil registry clicked on an Emotet-laden attachment from a malicious spam email, apparently sent by a city authority. Alarms were raised by the security system, prompting officials to restrict city services and take the IT system off the network as a precautionary measure.  


Germany has been a frequent target over the past few weeks by threat actors employing Emotet, and in general has been a target for malicious activity this year, according to data from the Trend Micro Smart Protection Network infrastructure. In fact, the German Federal Office for Information Security (BSI) issued a press release warning the public about malicious spam emails that carry Emotet.

First detected in 2014, Emotet has become one of the most notorious malware families of the past few years. Its original iteration was as an information-stealing banking malware — however, it has since undergone multiple evolutions, including acting as a loader for other malware families. It went into hiatus earlier in the year but came back after a few months with a vengeance. This recent spate of attacks on Germany is likely a continuation of Emotet’s comeback campaigns.

Despite all the changes Emotet has undergone, spam mail remains the malware’s most prominent distribution method. The key strategy organizations can implement is to educate their employees regarding email threats and to encourage them to follow the recommended security best practices when accessing their emails. This includes always double-checking an email for any red flags, as well as refraining from clicking any links or downloading any attachments haphazardly.

Combating threats like Emotet calls for a multilayered and proactive approach to security that involves protecting all fronts — gateway, endpoints, networks, and servers. Trend Micro endpoint solutions such as Trend Micro Smart Protection Suites and Worry-Free Business Security can protect users and businesses from these threats by detecting malicious files and spammed messages, as well as blocking all related malicious URLs.

To bolster their security capabilities and further protect their end users, organizations can consider security products such as the Trend Micro Cloud App Security solution, which uses machine learning (ML) to help detect and block spam and phishing attempts. 

If a malicious email is received by an employee, it will go through sender, content, and URL reputation analysis, which is followed by an inspection of the remaining URLs using computer vision and AI to check if website components are being spoofed. The solution can also detect suspicious content in the message body and attachments and provide sandbox malware analysis and document exploit detection.

Tuesday, December 17, 2019

McAfee joins with Google Cloud to integrate McAfee Security offerings with GCP for Linux and Windows workloads, containers

McAfee and Google Cloud entered into an alliance to integrate key McAfee solutions for endpoint and container security within Google Cloud. Under this new partnership, McAfee will tightly integrate its endpoint security solutions for Linux and Windows workloads, as well as its MVISION Cloud solution for container security, on Google Cloud infrastructure.

Several enterprise customers leverage virtual machines (VMs) running in the cloud to handle key Linux and Windows workloads. Ensuring security of these workloads is critical. With this new integration, customers will be able to deploy McAfee’s advanced endpoint security solutions across these key workloads and VMs via Google Cloud Marketplace.


McAfee’s workload security technology uses advanced machine learning and cloud analytics to help protect against file-based, fileless, and script-based threats at scale for workloads deployed on Google Cloud.

Google Cloud provides organizations with critical infrastructure, platform capabilities and solutions, along with expertise, to reinvent their business with data-powered innovation on modern computing infrastructure. The Mountain View, California-based company delivers enterprise-grade cloud solutions that leverage Google technology to help companies operate more efficiently, modernize for growth and innovate for the future. Customers in more than 150 countries turn to Google Cloud as their trusted partner to solve critical business problems.  

McAfee is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates business and consumer solutions that make the world a safer place. 


McAfee MVISION Cloud for Containers service extends data security, threat prevention, governance, and compliance capabilities of the MVISION Cloud platform to provide additional security for container-based workloads on Google Cloud. Organizations can also leverage MVISION to integrate security into DevOps processes and toolsets to discover and address security issues before applications are deployed.

“Increasingly, customers are choosing to move critical workloads and applications to the cloud because of the strong security protections it can provide,” said Anand Ramanathan, vice president of product and marketing at McAfee. “As more of these enterprises choose to leverage Google Cloud’s hyperscale capabilities, we’re excited to integrate our core capabilities in VM and container security to ensure Google Cloud customers can benefit from the highest levels of data protection and threat prevention.”

“We’re excited to partner with McAfee to bring their proven, trusted security capabilities to enterprise customers,” said Kevin Ichhpurani, corporate vice president, Global Ecosystem at Google Cloud. “Integrating McAfee’s solutions into Google Cloud means customers will have even more tools to ensure the highest levels of data security and protections as they migrate mission-critical workloads to the cloud.”

Friday, December 13, 2019

Trend Micro warns against sighting of ransomware bugs, Snatch and Zeppelin

Two ransomware families – Snatch and Zeppelin – with noteworthy features were spotted this week. Snatch ransomware is capable of forcing Windows machines to reboot into Safe Mode. Zeppelin ransomware, on the other hand, was responsible for infecting healthcare and IT organizations across Europe and the U.S.

Snatch reboots infected machines into Safe Mode to bypass security software and encrypt files without being detected. It was designed to do this because security software often do not run in Windows Safe Mode, since it’s meant for debugging and recovering a corrupt operating system (OS).


Researchers at SophosLabs found that the ransomware operators use a Windows registry key to schedule a Windows service called SuperBackupMan, which can run in Safe Mode and cannot be stopped or paused. The malware even goes further by deleting all volume shadow copies on the system, thus preventing the forensic recovery of encrypted files.

Snatch ransomware, first discovered back in 2018, does not target home users or use mass distribution methods such as spam campaigns or browser-based exploits. Instead, the malware operators go after a small list of targets that include companies and government organizations. The operators were also found recruiting hackers on hacking forums and stealing information from target organizations.


Zeppelin, which is a new variant of the VegaLocker/Buran ransomware, was spotted (with compilation timestamps no earlier than November 6, 2019) infecting companies located in Europe and the U.S. through targeted installs. Reported by BlackBerry Cylance, the Zeppelin ransomware, also a ransomware-as-a-service (RaaS) family, was found being used to infect certain healthcare and IT companies.

Zeppelin ransomware appears to be highly configurable and can be deployed as a .dll or .exe file, or wrapped in a PowerShell loader. Aside from encrypting files, it also terminates various processes, including those associated with backup, database, and mail servers. Zeppelin executables were found wrapped in three layers of obfuscation. Its ransom notes range from generic messages to elaborate notes tailored to specific organizations. Notably, it appears Zeppelin ransomware is not being widely distributed — or at least not yet.

The researchers believe that Zeppelin, similar to Sodinokibi ransomware, is being spread through managed service providers (MSPs) to further affect customers. Moreover, the ransomware can also be distributed through malvertising operations and watering hole attacks.


Aside from maintaining an up-to-date operating system to address exploitable vulnerabilities, users should adopt the standard best practice of backing up data via the 3-2-1 rule. Users can also consider deploying comprehensive, multilayered security solutions that will protect against ransomware attacks coming from different entry points. 

Trend Micro advises users and organizations to secure ports and services that are exposed on the internet; enable multi-factor authentication to protect admin accounts from potential brute-force attacks; secure remote access tools as they can be used as entry points; employ the principle of least privilege and regularly monitor the network for threats; and perform regular password audits for stronger access control to help prevent ransomware attacks.

Trend Micro solutions such as the Smart Protection Suites and Worry-Free Business Security solutions, which have behavior monitoring capabilities, can protect users and businesses from these types of threats by detecting malicious files, scripts, and messages as well as blocking all related malicious URLs. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques against a full range of threats for data centers, cloud environments, networks, and endpoints. It infuses high-fidelity machine learning with other detection technologies and global threat intelligence for comprehensive protection against advanced malware.

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Monday, December 2, 2019

Trend Micro reports on Microsoft discovering polymorphic malware ‘Dexphot’ that affected 80,000 Windows systems

For over a year, Microsoft has been monitoring a malware strain they named “Dexphot” that has been infecting Windows devices since October last year, Trend Micro revealed in a recent post. The malware used computer resources to mine cryptocurrency and profit from the attack. It reached its peak in June 2019, infecting almost 80,000 computers before gradually decreasing over the next months because of Microsoft’s intervention.

Despite the typical malware payload, Microsoft claimed that monitoring the Dexphot gave them insight into not only on how the malware worked but also the techniques that cybercriminals currently use.


This was largely because of the way Dexphot behaved over the course of last year, as noted by Microsoft. The simple payload was delivered through complex techniques that were constantly updated by the malicious actors behind the malware strain.

Microsoft found that the Dexphot malware strain was dropped by another malware known as ICLoader, which is unknowingly installed on a user’s system as part of software bundles. Dexphot was found downloaded and installed in Windows systems that were infected by ICLoader.


While Microsoft Defender Advanced Threat Protection’s pre-execution detection engines blocked Dexphot in most cases, behavior-based machine learning models provided protection for cases where the threat slipped through. Given the threat’s persistence mechanisms, polymorphism, and use of fileless techniques, behavior-based detection was a critical component of the comprehensive protection against this malware and other threats that exhibit similar malicious behaviors.

Microsoft Defender ATP data shows the effectiveness of behavioral blocking and containment capabilities in stopping the Dexphot campaign. Over time, Dexphot-related malicious behavior reports dropped to a low hum, as the threat lost steam.

Dexphot used legitimate system processes for its malicious activities. It used legitimate Windows apps such as msiexec.exe, unzip.exe, rundll32.exe, schtasks.exe, and powershell.exe to decrypt its data files. Using such tools allows Dexphot to evade detection, as the system would consider its activities as normal processes.

In addition, the decrypted files contained three executable files which are never written on filesystem. They remain on memory. This means Dexphot also used fileless techniques.

Dexphot instead laces the first two executable files into other legitimate system processes like svchost.exe or nslookup.exe. These are monitoring services that maintain Dexphot components. Finally, it replaces setup.exe contents with its third executable, a cryptocurrency miner.

Microsoft saw that Dexphot switched miners throughout their monitoring, using both programs like XMRig and JCE.

Microsoft noted that Dexphot was a malware strain that was not likely to garner much attention for its common payload. However, it does paint a good picture of the techniques that had been pervasive throughout this year, namely living off the land and fileless techniques.

Trend Micro’s most recent security roundup reported that threat actors have been increasingly living off the land. In fact, detections for fileless threats was 18 percent higher during the first half of 2019 compared to the total count for 2018.


Remaining vigilant and wary of similar cases as Dexphot can help in defending against fileless threats moving forward. Organizations would need to consider solutions like behavioral indicators and traffic monitoring to defend against the unique challenges that fileless threats present.

Trend Micro's Smart Protection Suites deliver several capabilities like high-fidelity machine learning and web reputation services that minimize the impact of persistent, fileless threats. 

Trend Micro Apex One protection employs a variety of threat detection capabilities, notably behavioral analysis that protects against malicious scripts, injection, ransomware, memory and browser attacks related to fileless threats. Additionally, the Apex One Endpoint Sensor provides context-aware endpoint investigation and response (EDR) that monitors events and quickly examines what processes or events are triggering malicious activity. 

The Trend Micro Deep Discovery solution has a layer for email inspection that can protect enterprises by detecting malicious attachments and URLs. Deep Discovery can detect remote scripts even if it is not being downloaded in the physical endpoint.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...