Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

Wednesday, May 31, 2023

Cracking the Connected Floor

Analytics and Cybersecurity 


By Dominic Alvieri
May 23rd, 2023



This KPI Isn't Pointing in the Right Direction

Fortune 500 companies are expanding their attack surfaces in a new data analytics push.

Cybersecurity takes a back seat for data analytics in a manufacturing executives dream which is turning out to be a security nightmare. It's called the connected shop floor and in this current version isn't going to end well. Corporate executives are unintentionally and unnecessarily exposing themselves to unnecessary risks. 

"This is largely driven by connecting machines using IoT and enabling Ai to digitize the results"

Apple iPads and Microsoft Bi along with several outsourced apps and technologies are involved.




100's of new endpoints and unrestricted devices 


All employees who have access to these new IoT devices running the backbone of this technological shop floor had open browser access and email capabilities. Personal emails as well as corporate and a host of new apps and software.

Oops, an employee just clicked on one of their personal emails and got phished.

Before drilling deeper into the technologies and possible exploits available for a starter there are hundreds of new IoT devices with an unrestricted browser able to view porn, YouTube or TikTok videos. A small time phisherman with a low grade infostealer may unknowingly get access to a Fortune 500 company employee and not even know it. 





The good news

Executives are starting to learn about cybersecurity. The bad news? They are slow and stubborn.

Here is a no brainer-restricting employee browser access.



App Avalanche


Once again executives are slow in embracing cybersecurity. They need the numbers to crunch to squeeze every last ounce of shareholder value that you can. Security often takes a back seat.

"Cybersecurity does not add revenue" one executive told me on the condition of anonymity. 






Exploitable


Querying one of the apps being used in one version of the connected floor returned an interesting response resulting in an error in my SQL syntax. Input sanitation issues are red flags indicating injection flaw exploits. 

Obviously I am unable to mention the firm or app until the issue is resolved. 

There are other exploitable alleys in this project.


The Deeper I Drill...

I have not received  any responses to my questions regarding the above mentioned security issues along with an uncovered topic. 


I am offensive in nature even in a defensive posture.
...

There are more holes in the floor.




Friday, February 3, 2023

I Can Name That Exploit in One Note

 Another New Day and Another New Way...


By Dominic Alvieri
February 3rd, 2023

The Cyber Show, by Dominic Alvieri.


Do your steganographic skills suck? Never fear 2023 is here. I guess I wasted years practicing the dark art of stego now with so many new ways to discretely infect, compromise and take over your target. 

How? Hiding your malicious file in an empty element is one way recently disclosed by researchers. Needless to say there are several other ways to play around with elements.





Another popular choice... embedding a malicious file within One Note. 


One Note.

You can't hard code all of your website. It's just not practical. Now that Microsoft has disabled macros threat actors are finding new ways to infiltrate networks. One Note has taken center stage and Microsoft Visual Studio just joined the fray. 

Here is a short list of files to closely examine or block that are being abused by TAs

.msha
.htm
.lnk
.js

You can do this with many different files and ways.

Ill leave you with this partial...

c:\ encrypt files
\"what?"\ attrib -h (?) -r  ("nice-try")

Redacted



 

Thursday, October 13, 2022

New Chinese Misinformation Campaign

Fake Campaign Attempts to Attribute Chinese Advanced Persistent Threat Group APT 41 to the NSA


By Dominic Alvieri 

@AlvieriD

October 12th, 2022


New Chinese misinformation campaign


A new Chinese misinformation campaign has been spreading this past week attempting to attribute the Chinese APT 41 to the National Security Agency. Many are using the Intrusion Truth name. 


Global Times Chinese domain article tweet.





Several new accounts tweeted in Chinese Mandarin for the local media in Asia while others have been created in English for a wider audience. All accounts use the APT 41 hashtag. 


Kimberly Allen Fake FireEye Attribution in Mandarin





The above tweet translates to FireEye attributing Chinese APT 41 to the NSA.


The tweet above has been removed but the account remains.





The FBI reports concludes what we all know while some are trying to create confusion in typical APT 41 style.



Dominic Alvieri, @AlvieriD Twitter

This is a new and current campaign with all accounts still currently open. No new activity has been spotted since the initial report this week with fake attribution tweets.


Blog will be updated as needed. Stay safe.





Thursday, September 8, 2022

Los Angeles School District Claimed by Vice Society

 Ransomware Roundup 


By Dominic Alvieri
9/9/22

Ransomware group logos.



We all know DDoS attacks are illegal. The rules seemed to have changed, entrust me.
Earlier this week several ransomware gangs leak sites including LV, Everest and Ragnar Locker appeared to be under the same "high load" stress that caused LockBit and ALPHV Black Cat ransomware to make some adjustments.

Everest v Brazil?


The Everest Ransomware Team leak site has been unavailable since leaking access to the Brazilian Government and still offline as of this article. It is still offline now.


Everest Ransom Team.
photo courtesy @darktracer_int  Twitter

Ragnar v Air Portugal?


Ragnar Locker has been wrestling with TAP Air Portugal regaining site control after an alleged DDoS attack. Raagnar Locker teased Air Portugal and the site neatly went unavailable again. The site is currently back online as of 7:45pm EST but no new posts or leaks were added.

TAP Air Portugal logo.

Ragnar Locker has been offline again since after their post. 






Ragnar Locker Air Portugal alleged customer data.
Alleged TAP Air Portugal customer leak.


Going Backwards, the LockBit Tattoo


LockBit is back in the news besides the obsessive post rate to offer $1,000 to anyone who gets a LockBit tattoo. 



ALPHV Black Cat ransomware has removed the Italian Energy Agency, GSE-Gestore Servizi Energetici from its leak site. When a ransomware group flashed a victim like ALPHV did with Unisys several weeks back for an hour or so that is a message or a taunt. WHen a post is deleted after nearly a week that usually indicates a payment. Black Cat like most ransomware groupsd does not do charity work.

The only other reasonable reason for removal could be the fear of NATO action due to the cyber attacks on Albania and Montenegro. Creos of Luxembourg remains on their leak site so that theory doesn't hold up well either.

Vice Society

New Logo, Same Lowlife Double Extortion Group.


New Vice Society ransomware group logo.

New Vice Society alt logo.
New Vice Society alternate logo. You're welcome.

Vice Society has just claimed the Los Angeles School District via Jeremy Kirk at 7:50pm EST while I am still waiting for a response this is from Vice.

The last 6 posts for Vice Society are:

The Los Angeles School District, California
Elmbrook School, Wisconsin
Moon Area School Distric, Pennsylvania 
The Francis King School of English, United Kingdom
Lampton School, United Kingdom
BSV Hospice

Vice Society is believed to be an English speaking group.

Vice Society has also added a timer on most of their new posts.




Yanluowang is thought to be a Chinese group.

Is Cl0P Brazilian? Cl0P is thought to be Russian but for some reason Brazil and Portuguese keeps coming up. More to come.

Cl0P


Cl0P added a captcha again to help against those high loads after an attack on a British water utility.



Dominic Alvieri, @AlvieriD Twitter


Tuesday, February 22, 2022

Banking and Crypto Stealing 2FA Bots on Telegram

Telegram Channels are Behind Evil New Ways to Separate You From Your Money


By Dominic Alvieri


2-22-2022



Telegram has had a history of security breaches, bad actors and security issues for several years. More and more malicious actors are using the platform along with 300 million others. Recent examples during the Russian invasion of Ukraine are showing an accelerating trend of cyber activities on the platform including the SberBank breach disclosed below.


SberBank breach files.

Other recent troubling requests




The Telegram mobile protocol MTProto protocol is proprietary and has had security questions for years. Cryptographic issues aside the desktop version does not use the protocol and storers all data in plain text. Plain text is also an issue with the mobile virtual cloud set up. 

In simplistic terms all data is stored on Telegram servers and not end to end encrypted (e2ee) by default. There is a secret chat option that does but that is another story. No e2ee by default leaves millions at risk from an advanced attacker. 

The current state of the gram


Underground forums and marketplaces are nothing new for a bad actor looking to score some low grade malware, stolen credit cards or a phishing kit. No need to fire up the TOR browser now because these items are becoming more mainstream available on the web and malicious Telegram channels.

OTP 2FA password stealing bots are being packaged with hand selected robocall features like foreign language accents to target customers of specific countries. Two if these bot services have been verified as working account stealing bots and recent reports of usage and abuse has been reported.

New set language feature   /setlang   



Set language /setlang


Bank of America, Chase and Wells Fargo are among the banks that these bots works with stealing your one time password or 2FA login. Several cryptocurrency platforms are also being marketed with automated bots and classes.





Several channels are selling various One Time Password (OTP) and 2FA stealing bots. Having verified two of the products here is a breakdown of some of the malicious capabilities.

Packages are readily available for Apple Pay, banks, crypto....



OTP 2FA Password stealing bots


Vendor P above has been active in advancing the bots attack capabilities in the past week adding Bank of America and Chase to their hackable list. Security support teams at Bank of America, Chase and Telegram have been notified. 




Here is what the bot can do. The ability to go after anyone with just the minimum information that would be needed to carry out this attack is worrisome. Basic OSINT research. 

As simple and annoying as this scam is the technology behind the maliciousness does work.

Enter target data, select a few options and assets to acquire and the nightmare scenario begins. Like most malicious activities they do require at least one action from the target, barring a zero-day, zero click exploit.

Video snapshot of working bot in action





Robocalls blanket the target with messages of an account breach and that verification is needed. An extreme sense of urgency is created and conveyed in the robocall accent of your choice. The artificially curated voices of the bot repeatedly mention your account is at risk and require you to verify your account via an OTP or your 2FA verification.

Partially redacted for security.

Everything is the same as before...





We have come along way from just unlocking iPhones.



What else can this bot do?


New functions which have just been posted and untested include bypassing:
-Authy
-Google Authenticator
-Microsoft Authenticator

Several variations of the original bot are online and to no surprise many claims are stretched and many are just outright frauds.






Relentless requests are the first step and if entered, the near-instant theft takes place. When a verification code is entered the bot executes the code, enters the account and transfers all of the cash or cryptocurrencies out of the account within minutes. In this live research example a crypto account was used and emptied within 2 minutes of the final string of data obtained by the bot. Crypto firm name withheld. 

Several other options are available if the first level attempt via robocalls fail to capture the required codes. These are actual working multifaceted bots able to spear or whale nearly anyone.

What can you do? DO NOT INTERACT

Do not interact with any SMS, email, link or call regarding your breached accounts. Always go directly to your real account through and official site or representative.

Go directly to any account in question and the official site and or contacts and avoid any "urgent need" to give your information to anyone. Chances are you haven't been hacked but someone sure is trying.



The Cyber Show
by Dominic Alvieri

Twitter @AlvieriD

Thursday, April 8, 2021

The Masters of Spoof

 Can anyone compete with Chinese spoofs?




The Cyber Show on Blogger

What makes a good spoof?


The Cyber Show on Blogger


Chinese imported counterfeit goods have been around as long as time itself. Reproducing an item as close to the original as possible. Logo color and style. 

For the cyber criminal the goal is the same, just replicate and add urgency.


Amazon spoofs



Amazon is a global target.
The links are difficult to replicate but they they try.



The Chinese gangs use the same MO: NameCheap registers, Alibaba hosts and anything that can be will be spoofed. Amazon, Apple, Hulu, Netflix, USPS. The online version of the knock off brand.

NameCheap often surfaces with these new short link scam domains. The Chinese aren't the only ones playing this game but with years of experience they are ahead of the pack.

Often targeting the largest companies Amazon, Apple and Netflix to name a few.


Often rerunning the same campaigns with great success.


The Netflix scam
2020 Netflix scam resurfaces again.

The devil is in the details. Examine all links with great care. Or you can just not answer any email, text or call. Warranty anyone? 

Some are easier to spot. Best Buy and spot gold.






You can always go back to a landline, otherwise examine all links and go directly to the company.
The above spoofs are all pedestrian, at best. The better spoofs have been withheld to avoid duplication.

The email spoof is still the number one entry for a cyber criminal to gain access to your system.
Stay safe online and off.



The Cyber Show
by Dominic Alvieri
Twitter, @AlvieriD



Tuesday, March 16, 2021

What the Spoof

All Spoofs All the Time. 

By Dominic Alvieri, @AlvieriD
March 10th 2021



The Cyber Show by Dominic Alvieri



Everyone wants something for free.



Free Netflix and Hulu for a year?


Free Netflix and Hulu for a year to help us stay home? 

Forget about that the BMW lottery came in, and some alert in France? 







All of the following offers are coming from China. 



Spoofed SMS texts


Fake USPS delivery notices continue.




Fake USPS delivery notice.

Fake USPS SMS spoofs coming from China.


------.py


Free Netflix for a year to help you stay home.



This is a Netflix spoof.


Free Hulu for a year to help you stay home?

Is it Netflix or Hulu?





The new short domain attack continues.



                                  DO NOT

                               [click here] 









Spoofed emails have been around since the beginning of the internet. Spoofed SMS texts have been proliferating in the past few years. Knowing the domain endings is critical. Newly created short domains have been popping up with the same group. 

Technological reverse psychology if you will by tracking the bad guys back. The building below is from a Google Earth trace address of the malicious links geolocation. 



Geolocation of malicious SMS texts.
Geolocation of malicious SMS text links.


Time to harden your network security. Use VPNs and encrypted communication like Signal to minimize your surface. Use MFA and tokenized apps like Google or Microsoft Authenticator over SMS. Incognito mode is not optimal security for your browser. Tor is acceptable but slow. Nothing is full proof. Check your home network and make sure to disable port forwarding and also disable the plug n play otherwise you are leaving a back door open.

IoT devices should be secured. Check for open standards, basic passwords and check for any and all updates and patches. Patch often and early. Do not hesitate. Within 12 hours of the server exchange hack Russian bad actors were scanning for the vulnerability according to Bad Packets, a malicious scanning alert firm. 

Security minimums are no longer effective. Update to longer more difficult passwords and do not click on any suspicious link. Or avoid all links. Not realistic but you get the point. 

This IP with "no site" is the USPS spoofed SMS malicious text link above in this report.



IP address of SMS text malicious links.
Courtesy of DomainTools.



The enemies are at the gates, computers, networks, phones...








The Cyber Show on Google Blogger
by Dominic Alvieri


Twitter @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...