Tag: attacks

  • Over 100 Financial Firms Hit by DDoS Attacks

    Over 100 Financial Firms Hit by DDoS Attacks

    More than 100 financial firms were victims of distributed denial-of-service attacks by the same threat actor with North America and Europe overwhelmingly making up the dominant share, according to a recent report.

    Cyber intelligence sharing group FS-ISAC said that over 100 financial services firms were targets of a wave of distributed denial-of-service (DDoS) attacks – a method of overloading a web system with requests in order to prevent it from functioning properly.

    Interestingly, the report claims that the attacks were conducted by the same threat actor within a short period of time.

    The criminals sent extortion notes threatening to disrupt the firms’ websites and digital services, the report said. The threat actor methodically moved across jurisdictions in Europe, North America, Latin America, and Asia Pacific, hitting dozens of institutions within weeks.

    According to the report, North America and Europe made up an overwhelming share of the DDoS attacks with 43 percent and 38 percent, respectively. Asia (15 percent) and Latin America (3 percent) made up less than one-fifth.

    By sub-sectors, retail banking dominated the list, accounting for 41 percent of the DDoS attacks. This is followed by exchange (15 percent), payments (13 percent) and, securities and investment (10 percent).

    In 2021, we have already seen new cyber threats in the form of supply chain attacks, which we can expect to proliferate and evolve quickly, said FS-ISAC’s chairman of the board Jerry Perullo  «The only way to stay ahead of these ever more sophisticated threat actors is to collaborate. Now more than ever, we need global leaders to model what effective sharing looks like to the rest of our community as well as the industry at large.

  • Singapore among top five destinations for IoT attacks

    Singapore among top five destinations for IoT attacks

    Singapore is in the top five destinations globally for IoT attacks, the latest installment of F5 Networks’ The Hunt for IoT series shows.

    The report, The Growth and Evolution of Thingbots Ensures Chaos, suggests the island nation has a sizable and vulnerable IoT deployment.

    The other destinations in the top five are United States, Spain, Italy, and Hungary. However, the top 5 destinations collectively only received 27% of China’s attacks; the other 73% were globally dispersed to countries that didn’t even account for more than 1% of the total attack volume.

    With 8.4 billion devices currently in use, and over 30 billion devices projected to be deployed by 2020, unprotected devices are a goldmine for hackers, as they find new ways to exploit numerous protocols beyond telnet (an underlying TCP/IP protocol for accessing remote computers) to ensure they capture as many vulnerable IoT devices as possible.

    Thingbots are botnets compromising of infected IoT devices which are typically unmanaged, providing a low likelihood of being discovered by their owner and remediated.

    Thingbots are capable of globally destructive attacks, and the worrying fact is that the security industry has only started discovering them with increasing frequency. Massive, well known thingbots such as Mirai and Persirai have been wreaking havoc around the world, and show no signs of slowing down.

    A new variant of the notorious Mirai malware is exploiting kit with ARC processors. Dubbed the Okiru, is the first capable of infecting devices powered by ARC CPUs which is responsible for running a variety of internet-connected products including cars, mobiles, TVs, cameras and more.

    In fact, despite broad awareness of their existence and threat, it is reported that Persirai infected IP cameras still exist all across Asia with the heaviest concentrations in Thailand, China, South Korea, Japan, Taiwan and Malaysia. There is even a website that collects the streaming footage from over 73,000 hacked IP cameras worldwide. These live feeds range from parking lots and store surveillance to the bedrooms of unknown individuals.

    While China, the US and Russia are clearly the top three attacking countries, the report suggests that because vulnerable IoT devices are deployed globally without bias, there is no standout IoT attack destination.

  • APAC battered by cyber attacks in 1H17

    APAC battered by cyber attacks in 1H17

    Asia Pacific was heavily hit by cyber attacks during the first six months of the year, taking more attacks than other regions in most threat categories, according to Trend Micro.

    Globally, Trend Micro detected 82 million ransomware threats and found that on average, 28 new ransomware families were created every month. The company also blocked more than 3,000 BEC attempts; and discovered and disclosed 382 new vulnerabilities.

    In the meantime, a new trend of cyberpropaganda reared its head in 2017 – cybercriminals started selling tools and services that helped create fake content, boost social media reach, and buy votes that can directly influence elections.

    Connected devices continue to be a problem too. In April, Trend Micro discovered the Persirai botnet targeting more than 1,000 Internet Protocol (IP) camera models. The company also found more than 83,000 exposed industrial routers and 28 exposed industrial robots.

    Out of the 82 million ransomware threats blocked, those targeting APAC entities accounted for 35.7% of all, the highest of all regions. This is followed by EMEA (25.24%), Latin America (22.66%), and North America (15.71%).

    The successive successes of WannaCry and Petya attacks reinforced the need for consistent patching for enterprises across all industries. Despite Microsoft releasing a patch in March for the vulnerability CVE-2017-0144 or EternalBlue, which WannaCry and Petya exploited, the attacks still infected thousands of computers in April and in June.

    Other noteworthy ransomware families that surfaced in the first half of the year included new variants of Cerber, an infamous ransomware now armed with anti-machine-learning capabilities; Patcher, which affected the MacOS; and the mobile ransomware SLocker.

    In the first six months of the year, more than 436 million malware detections were observed in the APAC region, surpassing the numbers in all other regions by a huge margin. APAC is followed by North America (324 million) and EMEA (169 million). The top three malware found in the region are DocDrop, DOWNAD, and WannaCry. The most hit countries in the region are Japan, Australia, and Taiwan.

    As industrial IoT devices continue to mushroom in APAC, the number of supervisory control and data acquisition (SCADA) system vulnerabilities is also increasing, providing fodder for malware attacks. Based on the findings from the Trend Micro’s Zero Day Initiative program, there exist malware specially made to target these connected systems.

    APAC also leads in the number of detections for online banking malware in the first half of the year, culminating in more than 118,193 malware discovered and blocked, four times more than EMEA (24,798) and five times more than North America (20,888). Japan, China, and Vietnam encountered most of the attacks.

    Trend Micro also found that more than 47 million malicious mobile apps were downloaded by users in APAC, much more than those from other regions. For instance, EMEA users downloaded 30 million such apps; the numbers are even lower in North America (eight million) and Latin America (six million).

    Exploit kits are another prominent threat in the APAC region, with a total of 556,542 detected within the six months, more than quadrupling the second place – North America (120,470).

    The most distributed exploit kits for the first six months in APAC are Rig, Magnitude, Sundown, and Nebula. Exploit kits normally target popular software such as AdobeFlash, Java, and Microsoft Silverlight. In 2017, connected industrial systems became a popular target for exploit kits too. Some of them can be used to deliver ransomware, such as Rig, Magnitude, and Sundown.

  • IoT devices drive DDoS attack traffic in Q4

    IoT devices drive DDoS attack traffic in Q4

    Unsecured IoT devices continued to drive significant DDoS attack traffic in the fourth quarter of 2016, according to Akamai’s latest State of the Internet / Security Report.

    The fourth quarter report also revealed that attacks greater than 100 Gbps increased to 12 during the quarter, a 40% year-over-year increase.

    Seven of the 12 Q4 2016 mega attacks, those with traffic greater than 100 Gbps, can be directly attributed to the Mirai IoT botnet.

    But the largest DDoS attack in Q4 2016, which peaked at 517 Gbps, came from Spike, a non-IoT botnet that has been around for more than two years.

    The number of IP addresses involved in DDoS attacks grew significantly this quarter, despite DDoS attack totals dropping overall. The United States sourced the most IP addresses participating in DDoS attacks – more than 180,000.

    “With the predicted exponential proliferation of these devices, threat agents will have an expanding pool of resources to carry out attacks, validating the need for companies to increase their security investments,” said Martin McKeay, senior security advocate and senior editor of the report.

    “Additional emerging system vulnerabilities are expected before devices become more secure.”

    Of the 25 DDoS attack vectors tracked in Q4 2016, the top three were UDP fragment (27%), DNS (21%), and NTP (15%), while overall DDoS attacks decreased by 16 percent.

    Akamai started tracking a new reflection DDoS attack vector this quarter, Connectionless Lightweight Directory Access Protocol (CLDAP), which attackers abuse to amplify DDoS traffic.

    “If anything, our analysis of Q4 2016 proves the old axiom ‘expect the unexpected’ to be true for the world of web security,” continued McKeay.

    “For example, perhaps the attackers in control of Spike felt challenged by Mirai and wanted to be more competitive. If that’s the case, the industry should be prepared to see other botnet operators testing the limits of their attack engines, generating ever larger attacks.”

  • Global Threat Index shows rise in malware attacks

    Global Threat Index shows rise in malware attacks

    The number of malware attacks increased in October, according to Check Point Software’s monthly Global Threat Index.

    Check Point’s Threat Intelligence Research Team found that both the number of active malware families and number of attacks increased by 5% during the period, pushing the number of attacks on business networks to near peak levels, as seen earlier this year.

    Locky ransomware attacks continued to rise, moving it up from third to second place, while the Zeus banking trojan moved up two spots, returning it to the top three.

    The reason for Locky’s continued growth is the constant variation and expansion of its distribution mechanism, which is primarily through spams emails. Its creators are continually changing the type of files used for downloading the ransomware, including doc, xls and wsf files, as well as making significant structural changes to the spam emails.

    The actual ransomware itself is nothing exceptional, but cyber criminals are investing a lot of time into maximizing the number of machines that become infected by it.

    For the seventh consecutive month, HummingBad, an android malware that establishes a persistent rootkit to carry out an array of malicious purposes, remained the most common malware used to attack mobile devices.

    Once again Conficker retained its first place position as the world’s most prevalent malware, responsible for 17% of recognized attacks. Both second placed Locky, which only started its distribution in February of this year, and third placed Zeus, were responsible for 5% of known attacks.

    “With the number of attacks and malware families increasing, the scale of the challenge organizations face in ensuring their networks remain secure is tremendous,” Check Point head of threat protection Nathan Shuchami said.

    “It is particularly concerning that a malware family as established and well known as Conficker is so effective, suggesting that organizations aren’t using the latest, multi-layered defenses.”

  • DDoS attacks caused StarHub broadband outages

    DDoS attacks caused StarHub broadband outages

    Singapore’s StarHub has blamed DDoS attacks originating from its customers’ own infected devices for two broadband outages over the past few days.

    At a press conference yesterday, StarHub announced the latest findings of an investigation into the outages on October 22 and 24.

    Both outages lasted for around two hours, leaving many home broadband customers unable to surf the web due to a spike in DNS traffic originating from infected machines.

    Because the traffic originated from StarHub’s own subscribers, it appeared legitimate. But when the attack was detected, StarHub manually filtered out the traffic from the infected devices to restore services for its other customers.

    StarHub announced it plans to send technicians to help customers clean up any infected devices at their homes.

    Singapore’s Cyber Security Agency and the Infocomm Media Development Authority have urged operators to strengthen their defense against DDoS attacks, and noted that this marks the first time Singapore has experienced such and attack on its network infrastructure.

    Darktrace managing director for APAC Sanjay Aurora said operators and ISPs are likely to find themselves increasing targets of attack.

    “The core infrastructure of telecommunications companies is a very desirable target for cybercriminals [but] gaining access is extremely difficult and requires deep expertise in specialist architecture,” he said.

    “What ISPs should be wary of, is the possibility of similar DNS amplification attacks on a more regular basis, given that they require relatively little skill and effort but can cause a large amount of damage. This makes them increasingly popular among hackers.”

    He said DNS-based DDoS attacks can impact networks by saturating bandwidth with malicious traffic, while also increasing volumes of support calls and negatively impacting  the customer experience and ultimately revenue.

    Aurora added that there is a possibility that the DDoS attack was caused by Mirai, the IoT botnet responsible for the recent DDoS attack against US-based DNS service provider Dyn. This attack used infected IoT devices.