Palo Alto Networks Joins Forces with the White House and Industry Partners to Support Veterans and their Families

Last Thursday I had the distinct honor to attend a special White House event celebrating the 5th anniversary of Joining Forces, an initiative that First Lady Michelle Obama and Dr. Jill Biden launched in 2011 in order to support service members, veterans, and their families through wellness, education, and employment opportunities.  Joining Forces works closely with both the public and private sectors to ensure that service members, veterans and their families have the tools they need to succeed throughout their lives.

The primary objectives of Joining Forces include:

  • Bringing attention to the unique experiences and strengths of America’s service members, veterans and their families.
  • Inspiring, educating, and sparking action from all sectors of society —citizens, communities, businesses, nonprofits faith-based institutions, philanthropic organizations, and government — to ensure service members, veterans and their families have the opportunities, resources and support they have earned.
  • Showcasing the skills, experience and dedication of America’s service members, veterans and their families to strengthen our nation’s communities.
  • Creating greater connections between the American public and the military.

You can find more information about this important and effective initiative here:https://www.whitehouse.gov/joiningforces.

I attended the event as a representative of Palo Alto Networks along with Chuck Konrad, who is our Director of Recruiting, Sales and Engineering at Palo Alto Networks and leads our veteran-focused initiatives.

This event was indeed special for one very important reason. During the ceremony in the White House State Dining Room, First Lady Michelle Obama and Dr. Jill Biden announced a new private sector hiring and training initiative where more than 40 companies have committed to hiring 110,000 veterans and military spouses. In addition, 15 companies and organizations have also committed to lead training programs, sponsor scholarships and support certification courses for nearly 60,000 veterans and military spouses over the next five years, primarily in the fields of aerospace, telecommunications and technology.  You can read the First Lady’s remarks from the event here:  https://www.whitehouse.gov/the-press-office/2016/05/05/remarks-first-lady-joining-forces-fifth-anniversary-employment-event.

As a retired Major General in the U.S. Army with more than 35 years of service, let me tell you that you’re going to want to read the First Lady’s remarks at the website above.  I was deeply moved during Michelle Obama’s remarks, and I can tell you that she spoke from her heart and showed her deep commitment to this effort. Dr. Biden, a proud Blue Star mom, emphasized the importance of supporting our veterans when they return home and how hiring veterans and military spouses is good for both companies and the morale of our military.  It does this old Soldier’s heart good to see such deep respect and support for the welfare, educational and employment opportunities of our current and former military and their families coming from the top, and the First Lady and Dr. Biden set the example magnificently!  I was truly humbled by their leadership.

As a strong supporter of this program, we’re doing our part. Along with our Education Services Team and our Veterans Programs team, we conducted a pilot training program for veterans in February 2016, where we trained 16 veterans in a one-week course for our ACE Accreditation. We’re proud to report that each veteran that took the final accreditation exam passed it, which helped prove to us that the program was successful and scalable.

As a result, we’ve committed to Joining Forces to train 400 veterans and transitioning service members over the next five years through the Palo Alto Networks Academy program. After completion of the coursework and successfully passing the accreditation exam, candidates will receive their Palo Alto Networks ACE (Accredited Configuration Engineer) Accreditation and career guidance on entering the cybersecurity workforce.  More information can be found at: www.paloaltonetworks.com/veterans.

[Palo Alto Networks Research Center]

Ransomware Is Not a “Malware Problem” – It’s a Criminal Business Model

Today Unit 42 published our latest paper on ransomware, which has quickly become one of the greatest cyberthreats facing organizations around the world. As a business model, ransomware has proven to be highly effective in generating revenue for cybercriminals in addition to causing significant operational impact to affected organizations. It is largely victim agnostic, spanning the globe and affecting all major industry verticals. Small organizations, large enterprises, individual home users – all are potential targets.

Ransomware has existed in various forms for decades; but, in the last three years, criminals have perfected the key components of these attacks. This has led to an explosion of new malware families, which make the technique work, and drawn new actors into participating in these lucrative schemes.

To execute a successful ransomware attack, an adversary must be able to do the following:

  1. Take control of a system or device.
  2. Prevent the owner of the controlled device from accessing it, either partially or completely.
  3. Alert the owner that the device has been held for ransom, indicating the method and amount to be paid.
  4. Accept payment from the device owner.
  5. Return full access to the device owner after payment has been received.

If the attacker fails in any of these steps, the scheme will be unsuccessful. While the concept of ransomware has existed for decades, the technology and techniques required to complete all five of these steps at a wide scale were not available until just a few years ago. The resulting wave of attacks using this scheme has impacted organizations all over the world, many of whom were not prepared to prevent these attacks from being successful.

The paper we released today details the history of ransomware and how attackers have spent many years trying to get this business model right. We also delve into what we can expect from future ransomware attacks, which includes the trends that follow.

1. More Platforms

Ransomware has already moved from Windows to Android devices and, in one case, targeted Mac OS X. No system is immune to attack, and any device that an attacker can hold for ransom will be a target in the future.

This concept will become even more applicable with the growth of the “Internet of Things” (IoT). While an attacker may be able to compromise an Internet-connected refrigerator, it would be challenging to turn that infection into a revenue stream. But the ransomware business model can be applied in this or any other case where the attacker can achieve all five steps for a successful ransomware attack. After infecting the refrigerator, the attacker could remotely disable the cooling system and only re-enable it after the victim has made a small payment. 

2. Higher Ransoms

The majority of single-system ransomware attacks charge a ransom between $200 and $500, but the values can be much higher. If attackers are able to determine that they have compromised a system which stores valuable information, and that infected organization has a higher ability to pay, they will increase their ransoms accordingly. We have already seen this in a number of high-profile ransomware attacks against hospitals in 2016, where the ransoms paid were well over $10,000. 

3. Targeted Ransom Attacks

A targeted intrusion into a network is valuable to an attacker in many ways. Selling or acting on stolen information is a common technique, but it often requires additional “back-end” infrastructure and planning to turn that information into cash. Targeted ransomware attacks are an alternative for attackers who may not know how else to monetize their intrusion. Once inside a network, attackers can identify high-value files, databases, and backup systems and then encrypt all of the data at one time. These attacks, using the SamSa malware, have already been identified in the wild and proven lucrative for the adversaries conducting them.

Download your copy of the “Ransomware: Unlocking the Lucrative Criminal Business Model” paper and learn techniques for preventing ransomware attacks.

[Palo Alto Networks Research Center]

VirusTotal Policy Changes Have No Impact On Palo Alto Networks Customers

What’s happened?

On Wednesday, May 4, VirusTotal cut off unlimited ratings access to companies that do not share their own evaluations of submitted research samples.

How does this impact Palo Alto Networks customers?

There is no impact to Palo Alto Networks customers or the protections our customers receive from us. VirusTotal will continue to provide subscribers, including Palo Alto Networks, access to all file samples. There is no change to the way we work with VirusTotal. Palo Alto Networks collects files samples from as many sources as possible. VirusTotal is one of many sources we use, but we do not rely on VirusTotal or any other third-party service to provide file verdict.

Palo Alto Networks relies on our WildFire cloud-based malware analysis environment to determine if a file is malware, greyware or benign based on static and dynamic analysis.

To learn more about WildFire, visit:  https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/wildfire

[Palo Alto Networks Research Center]

KRBanker Targets South Korea Through Adware and Exploit Kits

Online banking services have been a prime target of cyber criminals for many years and attacks continue to grow. Targeting online banking users and stealing their credentials has yielded huge profits for the criminals behind these campaigns. Unit 42 has been tracking “KRBanker” AKA ‘Blackmoon’, since late last year. This campaign specifically targets banks of the Republic of Korea. On April 23, researchers at Fortinet published a blog describing the functionalities of the recent ‘Blackmoon’ campaign. Our objective in this blog is to share additional details on the distribution of the KRBanker or Blackmoon malware campaign and indicators of KRBanker samples.

Early variants of this campaign started surfacing in late September 2015. Though the number of KRBanker infection attempts was relatively low in 2015, we have noticed a gradual increase in the number of sessions since the start of 2016, and identified close to 2,000 unique samples of KRBanker and 200+ pharming server addresses in the last 6 months.

Figure 1 KRBanker download sessions on Autofocus

Malware Distribution

Our analysis shows that KRBanker has been distributed through web exploit kits (EK) and a malicious Adware campaign. The exploit kit used for installing KRBanker is known as KaiXin and the Adware which distributes it is called NEWSPOT.

In March 2016, Unit 42’s Brad Duncan wrote two articles for SANS and Malware-Traffic-Analysis.Net, noting that the KaiXin EK is observed in Republic of Korea. In those cases, malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker.

Another distribution channel is a malicious Adware program, called NEWSPOT. According to the marketing document of the product, NEWSPOT guarantees 300% revenue growth for online shopping sites . NEWSPOT is a basic adware program that displays advertisements in browsers, but since at least November 2015 has started installing malware.When visiting some Korean websites, a user may notice a pop-up of a browser add-on requesting installation for NEWSPOT.

Figure 2 Installing NEWSPOT tool

If installed, the adware is executed on the computer and starts getting configuration from the following URL:

http://www.newspot[.]kr/config.php?sUID=%5Bweb site name]

It downloads a file from URL described in the <update> section within the configuration data returned by the server.

Figure 3 Configuration file contains download link to malware

This might have originally been used to update the NEWSPOT software, but we have confirmed that Banking Trojans like KRBanker and Venik has been installed through this update channel. Figure 4 shows the URLs:

Figure 4 Downloading Banking Trojans from NEWSPOT update channel

Execution

KRBanker uses Process Hollowing to execute its main code in a clean (non-suspicious) executable. The process is as follows:

  1. KRBanker executes a clean PE file in System directory.
  2. Windows loads the PE file into memory.
  3. KRBanker overwrites the whole clean process with its own (malicious) main module.
  4. Overwritten process starts malicious activity.

Figure 5 Execution Steps

Figure 6 Execution Steps (cont.)

After a successful execution the Windows Firewall alerts the user on the process attempting to access the Internet. Many users may allow this activity because the process originally involved a clean Microsoft file.

Figure 7 Windows Firewall Alert

Pharming

Banking trojans like Dridex or Vawtrak mainly employ Man-in-the-browser(MitB) techniques to steal credentials from targeted victims. However, KRBanker uses a different technique known as “pharming.” This technique involves redirecting traffic to a forged website when a user attempts to access one of the banking sites being targeted by the cyber criminals. The fake server masquerades the original site and urges visitors to submit their information and credentials.

Set Up

The IP address of the fraudulent server is not hard-coded in the malware. KRBanker obtains the server address by accessing Chinese SNS, Qzone through a Web API. The API provides basic user information by sending QQ number to the following URL.

users.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg?uins=[QQ ID Number]

The server then responds with the QQ ID Number, link to picture, nick name and some other information from SNS profile identified by the QQ ID Number. The author of the trojan put the Pharming server address in the “nickname” field.

Following is an example response that contains the IP address, 23.107.204[.]38 which is then extracted by KRBanker for Pharming.

Figure 8 Receiving IP address for Pharming from QZone

Next, KRBanker gets the MAC Address using an embedded VBScript and code page by executing GetOEMCP() API on the compromised system. It then registers the compromised system with the C2 server by sending the following HTTP GET request:

http://[IP address]/ca.php?m=[encoded MAC Address]&h=[code page]

Proxy Auto-Config

Researchers at ALYac had reported previously, on KRBanker employing hosts file modificationand local DNS proxy techniques to redirect HTTP traffic. The latest version of the threat employs Proxy Auto-Config(PAC), a legitimate function on Windows and Network administrators that can define an appropriate proxy address for each URL by writing JavaScript, and was also mentioned by Fortinet on their blog post. The adversaries abuse this feature for Pharming.

To configure this, the Trojan starts a local proxy server and creates the following registry entry.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:%5Brandom%5D/%5Brandom%5D

The local proxy hosts encrypted JavaScript.

Figure 9 Malicious JavaScript for Proxy Auto-Config

After decrypting the JavaScript we can see the function for PAC, FindProxyForURL() which is used to check for a list of targeted sites.

Figure 10 Decrypted malicious JavaScript

When the browser attempts to connect to a web server, the traffic goes to the local proxy. The malicious JavaScript on the Proxy PAC checks the domain with the list of targets using the FindProxyForURL() function. If the domain being accessed matches with any of the targets from the list, the traffic goes to a fraudulent server. If not, it goes to the legitimate domain being requested.

Figure 11 Redirecting traffic by Proxy Auto-Config

Current, KRBanker is targeting a large list of Korean financial institutions using this Pharming attack.

When a compromised user visits one of the targeted websites, the user will see a page like the one shown in Figure 12 below. It appears to look like a legitimate webpage with a valid URL displayed on the address bar of the browser. However, this is a fake website for stealing the credentials and account information of the victims.

Figure 12 Fake Authorized Certification Center for renewal

KRBanker is also capable of taking the following actions:

  • Stealing certification from NPKI directory in order to access online bankingaccounts
  • Terminating Ahnlab’s V3 security software

Conclusion

Profit is the primary motivator for attackers who use banking Trojans. The adversary behind KRBanker has been developing new distribution channels, evolving the pharming techniques multiple times, and releasing new variants on a daily basis to maximize the revenue from victims.

As described in this article, the threat is distributed through Exploit Kits that exploit old vulnerabilities and Adware that needs to be manually installed. It is essential to understand the infection vectors of such campaigns to minimize the impact. Palo Alto Networks Autofocus users can track this threat using the ‘KRBanker’ Autofocus tag.

Indicators

The indicators on KRBanker can be found on Unit 42’s github page below

https://github.com/pan-unit42/iocs/blob/master/krbanker/hashes.txt

and

[Palo Alto Networks Research Center]

Don’t Put Off Till Tomorrow What You Should Start Today (Part 1)

For some, the upcoming EU legislative changes (the General Data Protection Regulation, referred to as GDPR, and the Network and Information Security Directive, referred to as the NIS Directive) may have seemed like they are a long time in coming, since early discussions started back in 2013. Yet as is often the case with such processes, it becomes all too easy to keep holding off from preparing, especially when details are still to be finalized. From current speculation, it seems that both will be documented in the Official Journal of the EU shortly, which – for those who haven’t already started preparing – should be the final call to action, and implementation will officially start.

The question for many now becomes: Are they at the right place on the journey? Human nature drives us to want to compare ourselves with our neighbors to ensure we are doing the right things, and where there are time deadlines, that we are on track to achieve them.

From a recent webinar run with the industry group ISACA, I took the chance to poll the attendees to gather more insight on organizations’ state of preparation in terms of their cyber security strategies.

With any legislative requirements, the first objective is to be clear on what needs to be done. In this instance both pieces of legislation use the term “State of the Art”, which aligns to the requirement to have security by design and default. Specifically with the GDPR, that requires regard for this to be relevant to the risk.

In the last 12 months, exactly what “State of the Art” means has seemed to be one of the most common questions, as many security practitioners and leaders are typically more confident with granular requirements. But in polling the 1400+ people who registered for the recent webinar, it was found that 64 percent of those who responded now claimed to know what “State of the Art” is.   Unlike some other industry regulatory requirements, GDPR and the NIS Directive will likely remain in force for a while. As such, it would be virtually impossible to define detailed requirements; the term is more a placeholder requiring organizations to ensure they keep educated on cutting-edge cybersecurity capabilities and processes.

I have found myself having numerous discussions with other industry experts around how we would be sure that each of our interpretations of “State of the Art” would stand up to an auditor or another company. As such, my guidance would be that whilst we often look at the technical aspects of legislation, it’s important to engage with the business and legal teams in your company to ensure there is consensus on your interpretation of the requirement. Whether we like it or not, we should be prepared to qualify our adherence, be that to an auditor or to an authority, when responding to an incident.

Although it’s great to see that many are comfortable with the concept, there are others who are still getting their heads around the additional responsibility. I suspect more broadly that while the first goal will be to validate and achieve the relevant regard for “State of the Art”, very quickly cyber security leaders will also need to qualify just how long the current interpretation remains the case, as (it’s not a one-off goal, but an iterative requirement). As such, processes that continue to validate and subsequently apply ”State of the Art” must become part of the normal cyber strategy.

The challenge for many is that while we look to prepare for these legislative changes, we still have a day job. Therefore the question becomes: Where does it sit in the priority stack? Here the poll showed that there was a split in views. Thirty-six percent had this in their top 10, and an additional 21percent had it in their top three. Yet 20 percent were only planning to look at these legislative requirements in 2017, and a further 16 percent were planning to wait until the requirements come into effect in 2018. It would be interesting to see the industry breakdowns here, as I could speculate that those that are already more heavily regulated may be more proactive, as they are used to the process. But from my own experiences, I also have seen regional perceptions of legislation enforcements, especially when the historical variance in enforcement of data protection requirements could be a factor. The goal of harmonization, which was one of the key drivers of GDPR reform, aims to ensure we all abide by the same rules and enforcement guidelines.

My personal guidance here would be that if you haven’t already started to prepare, you should do so now. It takes time to validate the gap analysis (again for those that are already heavily regulated, this may be much smaller than those that are not today), but agreeing on a budget, validating solutions and deploying and testing capabilities all take time.

At an executive level, the natural first question when discussing the proposed new legislation is: What impact does that have on our business? Here the replies to the poll were very broad. Many were still unclear, while others focused on either the brand damage concerns that would likely come from public disclosure of an incident, or concerns around the new penalties for data breaches that have been defined in the GDPR. The very broad scope of responses, I would suggest, should be our biggest concern. If the impact to businesses cannot be clearly defined, how can they be expected to support their cybersecurity teams in investing time and resources to achieve compliance? As such, while it seems confidence is growing when it comes to some of the terminology, such as “State of the Art”, there is still a need to be clearer on the impact of these new regulations. For me this highlights why many are still holding off in terms of making it a priority for 2016.

[Palo Alto Networks Research Center]

English
Exit mobile version