News: 1607018753

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Crooks posing as COVID-19 'cold chain' company phished EU for vaccine intel, says IBM

(2020/12/03)


An unidentified group of malicious sorts impersonated a so-called "cold chain" company involved in COVID-19 vaccine distribution networks then targeted an EU governmental agency, according to IBM.

Infosec researchers from Big Blue's X-Force threat intelligence unit "uncovered targets across multiple industries, governments and global partners" involved in setting up the vaccine cold chain, it said in a [1]blog post today.

"Our analysis indicates that this calculated operation started in September 2020," wrote IBM's Claire Zaboeva and Melissa Fryrych. "While firm attribution could not be established for this campaign, the precision targeting of executives and key global organizations hold the potential hallmarks of nation-state tradecraft."

The phishing campaign's operators reportedly posed as an executive from the Chinese arm of Haier Biomedical, a business IBM described as "a credible and legitimate member company of the COVID-19 vaccine supply chain and qualified supplier for the CCEOP program."

FYI Russia is totally hacking the West's labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies [2]READ MORE

CCEOP stands for Cold Chain Equipment Optimization Platform, an initiative to make sure there are enough fridges and refrigerated transport available between vaccine factories and vaccination sites. Some of the most [3]recently announced vaccines need be stored and transported at temperatures between -20°C and -70°C to preserve the vaccine in a usable state before it is administered.

Spear-phishing emails were sent to other companies by the malicious people, targeting those working in sales, procurement, IT and finance departments – but also to the EU's Directorate-General for Tax and the Customs Union, which also sets rules on how vaccines cross the political bloc's borders.

According to IBM: "The Haier Biomedical employee who is purported to be sending these emails would likely be associated with Haier Biomedical's cold chain distribution operations based on his role, which is listed in the email signature block."

We have asked Haier's UK arm for comment and will update this article if we hear back from the firm.

"In times like these, knowledge is power – and so it inevitably becomes a big target," said Jake Moore, cybersecurity specialist at ESET. "Malicious actors from around the world will be attempting to steal any data possible, however trivial it may seem, on the most sought-after vaccines the world has seen in generations. The potential impact of these vaccines naturally attracts attention from bad actors wanting to monetize or disrupt the situation."

Earlier this year The Register reported how eavesdropping agency GCHQ claimed to be [4]actively targeting Russian hackers who were trying to illicitly access UK coronavirus research. Back in summer we also reported how GCHQ offshoot the National Cyber Security Centre, along with the US NSA spy agency, had [5]explicitly accused Russian agents of trying to break into Western research institutions.

Chris Ross, a Barracuda Networks veep, opined: "The purpose of today's concerted attack on the COVID vaccine supply 'cold chain' is likely to acquire leverage in a multimillion-pound ransomware attempt, to sell key data on the 'black market' to the highest international bidder, or, quite simply, to disrupt the UK's standing as the first country in the world to start vaccinating its citizens on a mass scale."

While IBM has not attributed the phishing campaign to any country or known hacking crew, it would be unusual for an intelligence-gathering campaign impersonating a Chinese company – even the Western divisions of a Chinese company – to originate from the West. ®

Get our [6]Tech Resources



[1] https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/

[2] https://www.theregister.com/2020/07/16/russia_coronavirus_hacking/

[3] https://www.sciencemag.org/news/2020/11/temperature-concerns-could-slow-rollout-new-coronavirus-vaccines

[4] https://www.theregister.com/2020/11/09/gchq_hacks_russia_vaccine_disinfo/

[5] https://www.theregister.com/2020/07/16/russia_coronavirus_hacking/

[6] https://whitepapers.theregister.com/

Crooks phishing for COVID vaccine intel

IceC0ld

the depths to which humankind will sink to, in the chase to 'earn' a few $$$ more

will NEVER cease to disgust me :o(

Re: Crooks phishing for COVID vaccine intel

Tom Paine

Depending who's doing it, they may be motivated by patriotism, or by fear of the state (China in particular likes acquiring cheap cyber talent by nicking crooks and offering them the choice of a labour camp or Unit 17xyz.)

cornetman

I must admit that I am puzzled as to what the aims of these "bad actors" might be as it is not elaborated on.

If they are wishing to disrupt our ability to distribute and manufacture vaccines, then that is obviously a bad thing, but I don't see any specific suggestion that that might be their aim.

Tom Paine

Off the top of my head:

- nicking email or other docs that can be selectively leaked to give the impression the vaccine's unsafe, or was stolen from Russia, or contains Bill Gates' famous microchips or whatever.

- straightforward industrial espionage

- blackmail attacks

- to compromise part of the pharmaceutical industry via the supply chain for the same motives as anyone else attacks pharma targets (fraud, theft, blackmail etc); nothing to do with SARS-Cov-2 per se, it just happens to be what's going on RN so that's the angle they're using

- straightforward financial fraud or theft ("Hi this is China FreezerCo Inc, pls remit payment for latest deliveries in bitcoin to: ... ")

No doubt experts can suggest several others

"Unusual"

Tom Paine

...it would be unusual for an attack impersonating a Chinese company to originate in the West.

If you were planning a false flag op, wouldn't you twamt to pick an org least likely to be suspected to be a front? Nothing particularly secure about Chinese commercial IT ops, in terms of security. You'd need to know the language and some of the culture, of course...

*strokes chin, steeples fingers, reaches for the metaphorical bong

Hi there

Boris the Cockroach

we've encyrpted your entire virus supply chain.

Pay us 25 million dollars in bitcoin to get your supply chain unscrambled, remember every hour you delay puts the price up 1 million dollars and another 100 people die from the virus.

Yours ransomware scum.

Although if a group tried something like that , I'm pretty sure that they'd get a visit from some non state actors before being found face down in some quick lime with large steel weights on their backs...

Re: Hi there

Version 1.0

How long has this been going on? And how many gangs have been stopped?

It's been going on for years and maybe two or three people have been arrested ... virtually none of the money has been recovered. Tech companies and governments are doing very little to prevent this, mostly they just blame the lusers for opening emails ... "But sir, I was sent a new invoice as a picture so I had to open the New_Invoice8365485.img email."

... before I could come to any conclusion it occurred to me that my speech
or my silence, indeed any action of mine, would be a mere futility. What
did it matter what anyone knew or ignored? What did it matter who was
manager? One gets sometimes such a flash of insight. The essentials of
this affair lay deep under the surface, beyond my reach, and beyond my
power of meddling.
-- Joseph Conrad