A Campaign Everyone Can Support

From the activities of political parties to the rise of electronic, wireless voting and tabulation machines, the electoral process has increasingly become technology-driven expanding voter participation. On the one hand, improved access and outreach through cyber innovations encourages more citizenry to help shaping their community’s or nation’s future. On the other, it has meant that elections and the electoral process are now vulnerable to cybersecurity attacks.

Although media outlets worldwide are treating the recent Democratic National Committee hacks in the United States as if it were a new phenomenon, using cyberspace to influence election outcomes is not new. In a demonstration this year, David Levin, of Vanguard Cybersecurity, pierced cybersecurity measures safeguarding elections information at the Florida Divisions of Elections not once, but three separate times. The 2008 and 2012 campaigns of both U.S. political parties fell victim to cyberattacks. Further, such activity is not a uniquely American phenomenon. Just this year, a hacker claimed to have been hired to affect the 2012 and 2014 national election outcomes in Mexico and Colombia, respectively, as well as several similar efforts in South and Central America. Digital spying on the opposition, the installation of malware, the hacking of websites, the creation of false social media profiles—all of these tactics and more have been and continue to be deployed by hackers to move electorates around the world toward a particular candidate.

Trained Cybersecurity Professionals Needed
To address this vulnerability, campaigns and political parties are increasing outreach to the IT and cybersecurity communities for well-trained, certified professionals to ensure cybersecurity for political and electoral efforts. This acceleration and opportunity is critically important: these events, scale and scope are not merely caused by technology; they are caused by people who are compromising the integrity of the electoral process. The solution lies with people as well. Our focus, a campaign platform plank, if you will, is on the pressing need for cybersecurity professionals to help ensure clean, fair, non-cyber-influenced elections.

Elections have an impact and history that extends over time, as do technologies. However, even the humblest of tools can accomplish little on its own. To maximize its value, cyber technology tools are best utilized by trained and certified individuals, people with the competencies, expertise and experience. To that end, it is imperative that we increase the ranks of our cybersecurity professionals, and their involvement globally, to preserve the integrity of electoral processes and results. No election—or business outcome—should be subjected to cybersecurity-based influences when the solution is at hand: highly skilled, trained and certified professionals.

Matthew S. Loeb, CGEIT, FASAE, CAE, Chief Executive Officer of ISACA

[ISACA Now Blog]

GRC Solution: Now More Than Ever After Brexit

Author’s note:  Whatever your political views on the United Kingdom’s recent “Brexit” from the European Union, I am writing this article to share some of my thinking on the need for a Governance, Risk and Compliance (GRC) solution in the aftermath of this decision. It’s just my opinion, but it has been formed after extensive discussions about the implications of the decision.

Thursday 23rd June was a most momentous day in Great Britain; the UK voted to leave the EU!

It was widely believe, before the Brexit vote, that leaving the EU was highly unlikely. Thus, when the Brexit referendum results were announced, the decision to leave the European Union was so unexpected that £120 billion was wiped off from FTSE 100 and value of the pound fell to its lowest since 1985. The Brexit decision has had global impact, creating a ripple effect across European Union referendums and the US presidential elections.

Brexit will have a long lasting and dramatic impact on international financial markets, investment, prices and jobs. Industries, both within the UK and globally, will feel the repercussions of this decision. As a result of these upheavals, it is likely that a post-Brexit global landscape will forcefully push organizations to fix their broken processes and siloed business approaches, while minimizing unnecessary interfaces and addressing the lack of linkage between corporate objectives and informed decisions.

Good Governance Desperately Needed
Now, more than ever, board and senior management will be desperate for ‘line of sight’ across all business functions, and better aligned resources that contribute to the delivery of desired outcomes.

Failure of good governance, a rising tide of cyber threats on the global risk landscape in both frequency and scale, a deluge of regulations, including the EU’s General Data Protection Regulation, to be complied with and the enormous headcount for the ‘eight eyes’1 control system, are keeping boards and senior management awake at night.

In our post-Brexit world, now is the best time for organizations around the world to act in aligning their three lines of defense by using automated governance, risk and compliance (GRC) solutions.

The current situation provides a compelling business case for formulating and investing in an automated GRC solution. I am convinced that organizations will benefit by integrating technology into their GRC activities.

Six Automated GRC Solutions
An automated GRC solution will provide an integrated and holistic approach to organization-wide governance, risk, and compliance efforts to ensure that the organization acts ethically and in accordance with its risk appetite, internal policies and external regulations through the alignment of strategy, processes, technology and people, thereby improving efficiency and effectiveness. More precisely, automated GRC solution will help organizations to:

  1. Manage third-party risk and compliance issues.
  2. Manage regulatory content and change management in dealing with regulatory proliferation.
  3. Develop risk analytics to support integration of risk management and performance management.
  4. Perform business performance audits as a key internal audit feature.
  5. Decide which business processes/assets are critical to their operations in term of confidentiality, integrity, availability ratings so they can prioritize and focus on critical applications.
  6. Create a risk culture by articulating the organization’s risk appetite.

In my view, the lessons generated from Brexit will give management the opportunity and ability to constructively challenge and help boards to develop robust GRC plans. The board needs a fine sense of risk appetite against which to judge investment decisions, allowing ‘line of sight’ for key objectives, from top to bottom, before making any decisions.

It is clear that, in the wake of Brexit, we will experience some choppy waters. As far as the political landscape is concerned, it is now a monumental challenge for those in power to figure out how this new world is going to actually work. As professionals working in governance, risk and compliance, we need to be ready for the economic surprises popping up around us.

1 Most organizations still have manual control testing, requiring nonessential headcounts due to the frequency of the control reviews in managing operational and compliance risk, so it is difficult to determine how effective these reviews are as failures can still occur.

Rehan Haque, CISA, CISM, CRISC, Academic Relations & Research Director, ISACA London Chapter Board

[ISACA Now Blog]

White House Strategy Proposes The Next Cyber Career Trend

In mid-July, the White House released its “first-ever”Cybersecurity Workforce Strategy, a directive under the Cybersecurity National Action Plan (CNAP) and the President’s 2017 budget. Its goal is to “…grow the pipeline of highly skilled cybersecurity talent entering federal service, and retain and better invest in the talent already in public service.” The government believes that by implementing this Strategy, it will elevate the attractiveness of public service to such a level that every private sector cybersecurity leader will ultimately deem it essential to his/her career to complete a tour of duty in federal service. How many cyber and IT professionals are they looking to attract? According to the White House blog, the magic number is 3,500. How long will it take? The goal is to reach its target number of new hires in six months’ time.

For those industry stakeholders who have evolved their corporate mission and dedicated significant organizational resources to solving this extremely complex cybersecurity workforce shortage, at first glance, this Strategy might appear to be lofty at best. On the other hand, it is extremely validating. This new Strategy demonstrates that the government is listening to the voice of (ISC)2 and to the many other organizations that have done the work to develop and provide sound recommendations, including those cited in the survey we just released in May. This Strategy demonstrates that those responsible for the government’s cybersecurity workforce challenge at least know what it’s going to take to fix the problem.

I am honored to participate in one of the sub working groups under the National Initiative for Cybersecurity Education (NICE) Working Group at large, which operates out of the National Institute of Standards and Technology (NIST). These subgroups provide a mechanism in which public and private sector participants can develop concepts, design strategies and pursue actions that advance cybersecurity education, training and workforce development. I am thrilled that NICE and its National Cybersecurity Workforce Framework was mentioned as part of the White House Strategy and will continue to be a key initiative moving forward.

Will the government successfully recruit, retain and train enough cyber candidates to meet its magic number by the start of 2017? Probably not, but it has to start somewhere. As (ISC)2 and our U.S. government members support the government in these efforts, we would encourage the following:

1) Shift the focus from quantity to quality. The government’s hiring process needs to be restructured to recruit qualified IT and security professionals. While it is tempting to throw bodies at the problem, if recruits are not properly vetted and have no proven track record, the government will have an even greater challenge on its hands than a workforce shortage.

2) Push the government to fund it. This Strategy is yet another unfunded requirement, a challenge magnified by the fact that the country is getting ready to enter a lame duck session. If we don’t do something to fund this Strategy quickly, we will find ourselves reading the next iteration of the same Strategy this time next year.

3) Keep relationships strong, communicate often. The White House Cybersecurity Workforce Strategy validates everything we have been saying about how to approach the global shortage of cyber personnel. Government is listening, industry needs to keep talking.

As to what it will realistically take to attract private sector leaders to federal service, we would like to hear from our members and the cybersecurity community at large. Are the Strategy’s proposed efforts to make federal service more attractive sufficient? If not, what will it take for our private sector members to view a stint in federal service an essential career move? Let us know in the comments below.

By Dan Waddell, CISSP, CAP, PMP, Managing Director, North America Region and Director of U.S. Government Affairs, (ISC)² 

(ISC)² Management

[(ISC)² Blog]

Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

By mid-July 2016, the Afraidgate campaign stopped distributing CryptXXX ransomware. It is now distributing the “.zepto” variant of Locky. Afraidgate has been using Neutrino exploit kit (EK) to distribute malware after Angler EK disappeared in early June 2016. As we previously reported, this campaign continues to utilize gate domains using name servers from afraid.org.

Changing Payloads

As early as June 29, 2016, we saw the Afraidgate campaign deliver Locky ransomware. This campaign switched between delivering CryptXXX and Locky ransomware during the next two weeks. July 11, 2016, was the last time we saw Afraidgate deliver CryptXXX. Since then, this campaign has been consistently delivering Locky.

Figure 1: Flow chart for an infection from the Afraidgate campaign.

This variant of Locky uses a .zepto file extension for any encrypted files. We started seeing this Zepto variant of Locky after a three-week outage of the Necurs botnet ended on June 21, 2016. Locky had been absent during the outage, but after the botnet returned, Locky also reappearedwith new anti-sandboxing and evasion techniques.

Some security vendors have named this new variant Zepto ransomware, but they still highlight its similarities with the previous Locky variant.

Figure 2: Desktop of a Windows host infected with the Zepto variant of Locky.

From Angler EK to Neutrino

Like most campaigns, Afraidgate switched to Neutrino EK after Angler EK disappeared in early June 2016. We have seen two other large-scale campaigns also move from Angler to Neutrino EK: the EITest and pseudo-Darkleech campaigns. For now, Neutrino appears to be distributing the majority of ransomware for EK-based infections. Outliers still exist, like Magnitude EK distributing Cerber ransomware. Rig EK has also been noted for an occasional ransomware infection. But the bulk of EK-based ransomware infections are most often attributed to Neutrino EK.

Example of an Afraidgate Infection

Figure 3: Traffic from an Afraidgate infection filtered in Wireshark.

As noted in our previous post on EK fundamentals, EK-based campaigns start with a compromised website. Pages from the compromised site have injected script that, in this case, lead to an Afraidgate domain behind the scenes.

Figure 4: Injected script in page from a compromised website.

After the victim’s computer connects to the URL on an Afraidgate domain, the server returns more Javascript with an iframe leading to a Neutrino EK landing page.

Figure 5: Afraidgate domain leading to the Neutrino EK landing page.

Neutrino EK domains for this campaign tend to use .top as the top level domain (TLD). Otherwise, we see no surprises. Neutrino is a well-known EK that has been documented by others.

Conclusion

Domains, IP addresses, and other indicators associated with Neutrino EK and Locky are constantly changing. We continue to investigate this activity for applicable indicators to inform the community and further enhance our threat prevention platform.

WildFire continues to detect submitted samples of Locky ransomware, and AutoFocus identifies this threat under the Unit 42 Locky tag.

Indicators of Compromise

So far in July 2016, we have seen the following indicators of compromise associated with the Afraidgate campaign:

Gates:

  • 46.101.26.161 port 80 – ƒleon.stmaryschooldmt[.]com – GET /scripts/jquery.form.js
  • 46.101.26.161 port 80 – motor.atchisoncountyrecorder[.]com – GET /js/blog.js
  • 46.101.26.161 port 80 – motor.atchisoncountyrecorder[.]com – GET /scripts/custom.js
  • 46.101.26.161 port 80 – oskol.migustapizza.com[.]br – GET /gantry-totop.js
  • 46.101.26.161 port 80 – snow.blautechnology[.]com – GET /scripts/libs.js
  • 46.101.26.161 port 80 – start.puterasyawal[.]com – GET /js/addOnLoad.js
  • 188.166.38.125 port 80 – nepal.laderatutors[.]com – GET /rokmediaqueries.js
  • 188.166.38.125 port 80 – siber.activebeliever[.]com – GET /plugins/fancybox-for-wordpress/js/jquery.easing.1.3.min.js?ver=1.3
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /scripts/jquery.sliderkit.1.9.2.pack.js
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /html5shiv.js
  • 188.166.38.125 port 80 – zine.polatoglumimarlik[.]com – GET /to_top.js

Neutrino EK:

  • 5.2.72.236 port 80 – avukytj.oautumnyellow[.]top
  • 5.2.72.236 port 80 – azbepfasz.yintored[.]top
  • 5.2.72.236 port 80 – bkubf.bsuperpink[.]top
  • 5.2.72.114 port 80 – iynwzttqd.hautumngreen[.]top
  • 5.2.72.236 port 80 – mxoug.yintored[.]top
  • 5.2.72.236 port 80 – yegoxmvzpx.bsuperpink[.]top
  • 185.140.33.76 port 80 – erfxsnvj.mafterred[.]top
  • 185.140.33.76 port 80 – hxmst.rautumngreen[.]top
  • 185.140.33.99 port 80 – bkhrdfngwg.blueelizabeth[.]top
  • 185.140.33.99 port 80 – clfdkbl.bluechristian[.]top
  • 185.140.33.99 port 80 – drhffhveq.greenjessica[.]top
  • 185.140.33.99 port 80 – rklfdprel.blueelizabeth[.]top

Locky post-infection traffic:

  • 5.9.253.173 port 80 – 5.9.253.173 – POST /upload/_dispatch.php
  • 5.187.0.137 port 80 – 5.187.0.137 – POST /upload/_dispatch.php
  • 77.222.54.202 port 80 – 77.222.54.202 – POST /upload/_dispatch.php
  • 185.5.250.135 port 80 – 185.5.250.135 – POST /upload/_dispatch.php
  • 185.117.153.176 port 80 – 185.117.153.176 – POST /upload/_dispatch.php
  • 185.118.66.83 port 80 – 185.118.66.83 – POST /upload/_dispatch.php

Domains from the decryption instructions:

  • mphtadhci5mrdlju.tor2web[.]org
  • mphtadhci5mrdlju.onion[.]to
  • zjfq4lnfbs7pncr5.tor2web[.]org
  • zjfq4lnfbs7pncr5.onion[.]to

[Palo Alto Networks Research Center]

Building Strategies to Make Sure Cybersecurity Is Everybody’s Business

Cybersecurity is continually a focus of news headlines and remains very much a topic under discussion across the globe. As the world, its devices and its systems become increasingly connected, the need to have the right cybersecurity defences in place is clear and increasingly understood.

Businesses are certainly aware of how much damage a successful data breach can cause, so much so that it’s become a major boardroom issue, with employee education and their role in preventing cybersecurity incidents key in the thinking of directors and executives.

In Europe, firms also have new laws to think about in the coming years, particularly with new legislation coming in from the EU. The Network and Information Security (NIS) Directive and the General Data Protection Regulation (GDPR) come into force in May 2018.

So the question is, how prepared is Europe for breach prevention and the ability to apply the “state of the art”, as well as for the notification of authorities in the event of a breach, be that aligned to the protection of EU residents’ personal data or the broader requirements to notify around certain security incidents set out in the NIS Directive for operators of essential services and the lighter requirements for digital service providers?

Results from our research, “Clearing the Path: Preventing the Blocks to Cybersecurity in the Business”, are encouraging. The research showed that European businesses certainly understand what’s at stake, with 96 percent of business decision-makers acknowledging that cybersecurity should be a priority.

Cybersecurity is not yet everybody’s business

But it’s not all good news. Cybersecurity should be everybody’s business, but it seems that this isn’t always true in practice – one in five management-level employees don’t feel they have a role to play in cybersecurity, while 40 percent believe that IT alone would be held to blame in the event of a breach. The upcoming pieces of legislation mean that such a legacy view will no longer survive.

By now we should all understand that cybersecurity isn’t just an IT issue but a business practice that needs to involve all employees and all departments. Our research indicates that this isn’t easy, as some cybersecurity policies have a negative effect on productivity – one in five respondents feel policies are frustrating and can prevent access to tools they need to do their job well.

On the other hand, our research indicated that 61 percent of respondents would make sure that they spoke with IT before introducing a device onto a corporate network. While that is an overwhelmingly positive figure, it leaves 39 percent of employees not engaging with IT before connecting – a high margin for risk. There was also some concern around temporary employees, such as contractors; 16 percent of respondents said they had observed that a temporary employee had circumvented policies.

It seems that, even though the bring-your-own-device (BYOD) model has been around for a long time, many companies still have trouble managing both personal and business access, especially with the boundaries between consumer and corporate cloud services becoming increasingly less clear.

Viewing cybersecurity as an integral part of the business

So there is still work to do, but progress is being made. Cybersecurity is becoming a boardroom topic and an integral part of the business. To continue along this path, organisations must understand that cybersecurity education, empowerment and implementation are all ongoing processes. This will mean continuing with education efforts and ensuring employees, both in full-time and non-permanent positions, have all the skills and training needed to identify and prevent threats.

The immediate challenge is to adapt to the cybersecurity requirements laid out by GDPR and the NIS Directive, which create a compelling case to prevent cybersecurity breaches. Looking at the bigger picture, organisations need to prepare for a period in which the number of devices is expected to grow exponentially as more data flows between businesses. Gartner says that 25 percent of identified attacks will involve the internet of things (IoT) by 2020.

Future cybersecurity strategies also need to keep in mind that employees will demand choice over the devices and services that they use. Organisations must enable this, rather than dictate, and that may well mean looking at next-generation security tools designed for a modern computing environment.

[Palo Alto Networks Research Center]

English
Exit mobile version