News: 1665704105

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Banks face their 'darkest hour' as malware steps up, maker of antivirus says

(2022/10/14)


Interview Crimeware targeting banks and other financial-services organizations today features sophisticated capabilities and evasion tools, according to Kaspersky's lead security researcher Sergey Lozhkin.

"The darkest hour is now for the financial industry, especially for big and medium-sized corporations," Lozhkin said, during a panel discussion on threats to financial services organizations.

BlackLotus, a Unified Extensible Firmware Interface (UEFI) firmware rootkit used to backdoor Windows machines, is one such newly discovered tool. Kaspersky hasn't yet published full research about the malicious implant, but Lozhkin said it appeared for sale with a $5,000 price tag on the cybercrime scene earlier this month.

[1]

This malicious code allows miscreants to bypass computers' secure boot feature, which is supposed to prevent the machine from running unauthorized software. Instead, by targeting the UEFI, the BlackLotus malware loads before anything else in the booting process including the operating system and any security tools that could stop it.

[2]

[3]

"So basically, if a bad guy gets access to a network or a computer, he can install this tool, and it will be fully undetected, fully persistent, on the UEFI level," Lozhkin said.

If a bad guy gets access to a network or a computer, he can install this tool, and it will be fully undetected, fully persistent, on the UEFI level

BlackLotus and [4]other sophisticated malware are usually, but not exclusively, wielded by government-level teams, who have deep pockets and highly skilled developers on the payroll. Criminals can also get their hands on the tools.

"These threats and technologies before were only accessible by guys who were developing advanced persistent threats, mostly governments," Lozhkin claimed. "Now these kinds of tools are in the hands of criminals all over the forums."

As soon as he saw BlackLotus on one such forum, "I wanted it immediately because I need to reverse engineer it and warn our customers immediately," Lozhkin added.

How to catch a crook

Lozhkin spends his days monitoring criminal underground forums and reverse engineering malware shared via these nefarious channels, and he previously was VP of cybersecurity operations for JP Morgan Chase.

While he won't name the cybercrime gangs he sees lurking around in the shadows because of ongoing investigative purposes, these financially-motivated cybercriminals have become really good at repurposing government-created cyberespionage tools to pull off massive bank heists — like the [5]EUR$1 billion robbery that infiltrated more than 100 financial institutions in 40 countries.

[6]

Lozhkin was one of the private security researchers who participated in the takedown, led by the Spanish National Police with the support of Europol, the US FBI, and the Romanian, Moldovan, Belarussian and Taiwanese authorities.

"Modern crimeware is really sophisticated, and the guys coding these tools are really, really smart," Lozhkin said. "And sometimes they don't even need to code anything. Why write your own code when you can just as easily buy it online?"

Red-team tools gone bad

As a case in point: ransomware gangs and Cobalt Strike. This is a legitimate penetration testing tool that has since become a favorite method for cybercriminals to move laterally through victims' networks, establish persistence, and download and execute malicious payloads.

"And then we have Brute Ratel," Lozhkin said.

This, of course, is the post-exploitation toolkit developed by a former Mandiant red teamer. The [7]nearly undetectable malware , which can evade antivirus and endpoint detection and response software, was selling for $3,000 before a cracked version was [8]leaked for free on underground forums.

[9]

"I've seen a huge increase in the last year using legal tools to attack financial institutions," Lozhkin said. "Cobalt Strike is everywhere. Brute Ratel is everywhere."

This illustrates the "biggest problem" with these types of software tools that emulate adversaries in an IT environment and are designed to remain undetected, he added.

"When you are creating a weapon — and I consider this a cyberweapon, a really dangerous tool that could be used to infiltrate every organization, every company — cybercriminals immediately get this tool and use it against organizations," Lozhkin said.

Meanwhile, ransomware economy booms

Plus, all of these malicious tools for sale also contribute to the booming initial access broker economy. These are the criminals who sell or provide a route into an organization for a fee or cut of the profits. This access is then used by extortionists to siphon sensitive data, encrypt files using ransomware, and demand payment to keep quiet about the intrusion and clean up the mess.

"These guys are everywhere: they hack into an organization and sell access," Lozhkin said, adding that the price tag for initial access to high-revenue corporations that criminals believe will pay ransom demands can run upwards of $50,000.

[10]Huge nonprofit hospital network suffers IT meltdown after 'security incident'

[11]US election workers slammed with phishing, malware-stuffed emails

[12]Pro-Putin goons claim responsibility for blowing US airport websites offline

[13]When are we gonna stop calling it ransomware? It's just data kidnapping now

"The final customers of this data are ransomware groups," he noted. Ransomware gangs have their own forums, and they, too, are becoming better at the trade, using [14]modern programming languages to write code, nonstandard cryptography to lockup organizations' files, and even [15]professional business operations models.

Ransomware developers are becoming more professional, too, and recent market downturns and big tech layoffs aren't helping, according to Lozhkin. "Lots of people are coming to the darkside because the darkside is hiring."

Somehow, though he remains optimistic. "The darkest hour is just before the dawn. There is a light. There is always a light," Lozhkin said.

Following weeks of ransomware attacks against [16]schools and [17]hospitals , and [18]publicity stunts aimed at US airports, it's hard to share in that optimism. But here's hoping he's right. ®

Get our [19]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y0je3@1-@B8BiQ9Kqpji7QAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0je3@1-@B8BiQ9Kqpji7QAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0je3@1-@B8BiQ9Kqpji7QAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://usa.kaspersky.com/about/press-releases/2022_kaspersky-uncovers-third-known-firmware-bootkit

[5] https://www.europol.europa.eu/media-press/newsroom/news/mastermind-behind-eur-1-billion-cyber-bank-robbery-arrested-in-spain

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0je3@1-@B8BiQ9Kqpji7QAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/07/06/brc4_state_sponsored_apt29/

[8] https://twitter.com/BushidoToken/status/1575054022784208897

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0je3@1-@B8BiQ9Kqpji7QAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/10/06/commonspirit_health_cyberattack/

[11] https://www.theregister.com/2022/10/12/us_election_workers_phishing/

[12] https://www.theregister.com/2022/10/10/ddos_us_airport_websites/

[13] https://www.theregister.com/2022/10/09/extortion_ransomware_threats_category/

[14] https://www.theregister.com/2022/10/02/in-brief-security/

[15] https://www.theregister.com/2022/05/18/wizard-spider-ransomware-conti/

[16] https://www.theregister.com/2022/09/06/lausd_ransomware_fbi_cisa_los_angeles/

[17] https://www.theregister.com/2022/10/12/hospital_outages_ransomware/

[18] https://www.theregister.com/2022/10/10/ddos_us_airport_websites/

[19] https://whitepapers.theregister.com/



UEFI attack surface

Anonymous Coward

UEFI is just too big. And as most mobos, especially Notebooks don't expose the more often than not SPI pins, not only can't you recover from a bad flash, you cannot even check to see what is lurking on it.

Oh and not to mention that I had an NOR flash device wear our (64MBit) in the few sectors where it (UEFI) would update some variables after each boot.

Increasingly sophisticated thieves

trindflo

Now all they need is some way into the network to get started. Maybe a drone... [1]El Reg: drone-roof-attack

[1] https://www.theregister.com/2022/10/12/drone-roof-attack/?td=rt-3a

Hacker's Guide To Cooking:
2 pkg. cream cheese (the mushy white stuff in silver wrappings that doesn't
really come from Philadelphia after all; anyway, about 16 oz.)
1 tsp. vanilla extract (which is more alcohol than vanilla and pretty
strong so this part you *GOTTA* measure)
1/4 cup sugar (but honey works fine too)
8 oz. Cool Whip (the fluffy stuff devoid of nutritional value that you
can squirt all over your friends and lick off...)
"Blend all together until creamy with no lumps." This is where you get to
join(1) all the raw data in a big buffer and then filter it through
merge(1m) with the -thick option, I mean, it starts out ultra lumpy
and icky looking and you have to work hard to mix it. Try an electric
beater if you have a cat(1) that can climb wall(1s) to lick it off
the ceiling(3m).
"Pour into a graham cracker crust..." Aha, the BUGS section at last. You
just happened to have a GCC sitting around under /etc/food, right?
If not, don't panic(8), merely crumble a rand(3m) handful of innocent
GCs into a suitable tempfile and mix in some melted butter.
"...and refrigerate for an hour." Leave the recipe's stdout in a fridge
for 3.6E6 milliseconds while you work on cleaning up stderr, and
by time out your cheesecake will be ready for stdin.