Lapsus$ extortionists dump data online as Samsung admits breach
- Reference: 1646673111
- News link: https://www.theregister.co.uk/2022/03/07/samsung_lapsus_data_theft/
- Source link:
"We were recently made aware that there was a security breach relating to certain internal company data," said the Korean multinational in a statement this afternoon.
Lapsus$, previously known as the criminal crew that stole [1]internal data from Nvidia in a separate ransomware attempt, published 190GB of files on Bittorrent, according to reports. Bleeping Computer [2]reported the torrent contained "source code and related data" for Samsung Knox, the firm's containerisation and security management framework, Bootloader, its Trusted Apps feature and more.
[3]
We have asked Samsung for further comment and will update this article if the chaebol responds. No detail in the [4]statement given to CNBC directly addressed the question of what data was stolen.
[5]
[6]
Industry reaction was unhappy at the exposure of what appeared to be source code for security and remote management features of Galaxy smartphones. If source code for Samsung's proprietary security features on its handsets has leaked, the company may be in trouble.
Chris Vaughan, EMEA area vice president of technical account management at US infosec firm Tanium opined: "I believe that this breach is genuine and it could cause significant damage to the company."
[7]
He continued: "Some specific parts of the code that have been leaked are key security components for Samsung devices, this could make cracking and breaking into phones easier. I expect attackers to test if biometric security controls such as fingerprint and face ID can be bypassed. This could even be leveraged by law enforcement and could be a privacy concern for Samsung users."
Jake Moore, Slovakian infosec firm ESET's global cyber security advisor, said: "Data breaches like this often have a price tag attached but these bad actors have just gone straight to releasing the data without a ransom note, leaving the targeted victims scrambling around trying to reduce the impact where possible."
[8]Leaked stolen Nvidia cert can sign Windows malware
[9]Samsung finally admitted to Google’s Enterprise Android Recommended club
[10]Samsung shipped '100 million' phones with flawed encryption
[11]Samsung commits to 5 years of Android updates... for its enterprise smartphone users at least
Knox was admitted to the UK government's security framework [12]in 2014 for "official" (low level) classified data, with the US NSA [13]following suit that year .
These efforts at breaking into what was then the Blackberry-dominated secure enterprise mobile device market eventually bore fruit in 2020; Google finally admitted Samsung, the world's number 1 maker of Android smartphones, into its [14]Android Enterprise Recommended programme . It is intended to provide enterprises with a readymade list of vendors whose products meet Google-approved security standards, including remote device management and inbuilt secure storage features.
Shane Curran, CEO of encryption firm, Evervault, said: "Strong encryption, when properly applied, is a business asset and a tool in the arsenal of successful companies. The widespread adoption of strong encryption will reduce the ongoing incentive for businesses to pay ransoms, a harmful tendency that promotes the global expansion of cybercriminal operations."
[15]
So far there is no information about whether Lapsus$ has demanded a ransom from Samsung, as it did with Nvidia after stealing data from the chipmaker and threatening to leak it online unless anti-cryptominer features in GPU firmware were removed from current and future products.
Lapsus$ does not appear to follow the usual ransomware gang method of privately demanding a payoff to prevent data theft and leakage. The gang, which appeared to align itself to cryptocurrency miners' interests, instead dumps data online as a means of ramping up pressure on its targets to do their bidding.
Data theft and leakage can have unintended consequences even from the attacker's point of view; last week a code-signing certificate included in Lapsus$'s dump from Nvidia was [16]being used to sign Windows malware , according to infosec industry sources. ®
Get our [17]Tech Resources
[1] https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
[2] https://www.bleepingcomputer.com/news/security/hackers-leak-190gb-of-alleged-samsung-data-source-code/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YiaOmbQ18gnEpKtptGt5OAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.cnbc.com/2022/03/07/samsung-hackers-breached-company-data-source-code-for-galaxy-devices.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiaOmbQ18gnEpKtptGt5OAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiaOmbQ18gnEpKtptGt5OAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiaOmbQ18gnEpKtptGt5OAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
[9] https://www.theregister.com/2020/11/12/samsung_joins_android_recommended_scheme/
[10] https://www.theregister.com/2022/02/23/samsung_encryption_phones/
[11] https://www.theregister.com/2021/06/29/samsung_five_year_android/
[12] https://www.theregister.com/2014/05/16/samsung_knox_gets_official_security_clearence/
[13] https://www.theregister.com/2014/10/21/nsa_spooks_to_spy_on_the_galaxy/
[14] https://www.theregister.com/2020/11/12/samsung_joins_android_recommended_scheme/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiaOmbQ18gnEpKtptGt5OAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
[17] https://whitepapers.theregister.com/
I don't understand how having the source code to Knox helps you bypass it. I mean, it's written by competent security engineers isn't it? Otherwise how could it have received the government's sign-off?
You think a government sign off is a guarantee there are no security holes?
(can't tell if you're serious or not, so just in case...)
You wouldn't be suggesting that the very same governments might have required Samsung to build in backdoors, would you?
Software can have vulnerabilities from things besides programming errors, in fact I'd be willing to bet that most CVEs are malicious combinations of features working exactly as intended.
Hackers are capable of misdirection too....
@Ken_Hagan
Quote: "...it's written by competent security engineers..."
Sorry Ken, it's not the CURRENT security software that's the problem........maybe to 190GB dump is cunning misdirection for other types of misdeed....
(1) The Ken Thompson Hack: https://wiki.c2.com/?TheKenThompsonHack
(2) The SolarWinds Hack: https://www.csoonline.com/article/3601508/solarwinds-supply-chain-attack-explained-why-organizations-were-not-prepared.html
So.....the hack on Samsung precludes the hackers WRITING BACK their own code as part of the hack?
Would Samsung know this has happened? (c.f. SolarWinds)
And suppose Samsung's development infrastructure were to be compromised, how long would it take to find out? (c.f. SolarWinds)
And what about future Samsung customers buying product with third party hacks embedded in the product?
Bootloader
Hopefully info on how to unlock the bootloader is out there now so I can get the official Samsung malware off the device.
The Leaky Cauldron
Security through obscurity, effective as ever. I'm sure this'll never happen to government backdoors.