Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, August 16, 2017

Ransomware Attack Costs World Biggest Container Ship Company Over $200M

Ransomware Attack Costs World Biggest Container Ship Company Over $200M

Maersk, the world's biggest container shipping company
The June cyberattack that paralyzed the computer systems in companies around the world is estimated to have cost Maersk, the world's biggest container shipping line between $200 million and $300 million US, A.P. Moller-Maersk said Wednesday.

The Copenhagen-based group, which was particularly severely affected by the attack, says the impact will first be reflected in its third-quarter results as revenue was mainly lost in July.

The company says the June 27 malware attack was distributed through Ukrainian accounting software with back doors into the networks of users. It was contained the following day.

"In the last week of the quarter, we were hit by a cyberattack, which mainly impacted Maersk Line, APM Terminals and Damco. Business volumes were negatively affected for a couple of weeks in July," CEO Soeren Skou said. The businesses "were significantly affected," but there was "no data breach or data loss."

It said it made a loss of $264 million in the second quarter, against a profit of $118 million a year earlier. Revenue rose to $9.6 billion from $8.7 billion.

Its full-year forecast for an underlying profit above the 2016 figure, which was $711 million, "is unchanged despite expected negative impact from the June cyber-attack," the group said. It added the gross capital expenditure for 2017 is still expected to be around $5 billion.

It said the guidance for 2017 excludes the acquisition of Hamburg Sud, the German container shipping company and the world's seventh largest container line, which the Danish conglomerate bought last year.

Maersk shares increased nearly 0.8 per cent to the equivalent of $2,074 in morning trading in Copenhagen.

Thursday, August 10, 2017

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Hacker in Action
A Russian man accused of infecting tens of thousands of computer servers worldwide to generate millions in fraudulent payments has been imprisoned for 46 months (nearly four years) in a United States' federal prison.

41-year-old Maxim Senakh, of Velikii Novgorod, was arrested by Finnish police in August 2015 for his role in the development and maintenance of the infamous Linux botnet called Ebury that siphoned millions of dollars from victims worldwide.

Senakh was extradited to the United States in February 2016 to face charges and pleaded guilty in late March this year after admitting of creating a massive Ebury botnet and personally being profited from the scheme.

First spotted in 2011, Ebury is an SSH backdoor Trojan for Linux and Unix-style operating systems, such as FreeBSD or Solaris, which gives attackers full shell control of an infected machine remotely even if the password for affected user account is changed regularly.

Senakh and his associates used the malware to build an Ebury botnet network of thousands of compromised Linux systems, which had the capacity of sending over 35 million spam messages and redirecting more than 500,000 online visitors to exploit kits every day.

Senakh fraudulently generated millions of dollars in revenue running spam campaigns and committing advertising click frauds.

Working within a massive criminal enterprise, Maxim Senakh helped create a sophisticated infrastructure that victimized thousands of Internet users across the world," said Acting U.S. Attorney Brooker.
"As society becomes more reliant on computers, cyber criminals like Senakh pose a serious threat. This Office, along with our law enforcement partners, is committed to detecting and prosecuting cyber criminals no matter where they reside.


Ebury first came into headlines in 2011 after Donald Ryan Austin, 27, of El Portal, Florida, installed the Trojan on multiple servers owned by kernel.org and the Linux Foundation, which maintain and distribute the Linux operating system kernel.

Austin, with no connection to the Ebury criminal gang, was arrested in September last year and was charged with 4 counts of intentional transmission causing damage to a protected computer.

Senakh was facing up to a combined 30 years in prison, after pleading guilty to conspiracy to commit wire fraud as well as violate the Computer Fraud and Abuse Act.

However, a US judge on Thursday sentenced Senakh to 46 months in prison, the Department of Justice announced on Thursday. The case was investigated by the Federal Bureau of Investigation's field office in Minneapolis.

Senakh will be deported back to Russia following his release from the U.S. prison

Monday, July 31, 2017

Defcon Hackers Penetrate US Election Machines In 90 Minutes To Show Electronic Voting Loopholes

Defcon Hackers Penetrate US Election Machines In 90 Minutes To Show Electronic Voting Loopholes

Hacker on mask
Hackers attending the flagship cybersecurity conference Defcon this year were able to break into a wide variety of voter legislation and ballot machines in roughly 90 minutes, leading to fears that the outcomes of presidential elections could be influenced by cybercriminals in the near future.

Ever since the 2016 US presidential poll, when hackers linked to Russia were accused of tampering with voting machines in a slew of States, so-called "election hacking" has hit the headlines. To test for flaws, Defcon officials brought in 30 separate voting machines.

US election voting machine
One "WinVote" machine, from a now-defunct US company called Advanced Voting Solutions, had a hardcoded password of "ABCDE", Cnet reported .

Another machine could be hacked via its Wi-Fi connection using a known Windows XP exploit that was more than four years old, but left unpatched.

The old machines, used for registrations, were purchased on eBay or bought from government auctions. Shockingly, reports suggested that some were still storing hundreds of thousands of records.

In one case 600,000 records linked to citizens living in Tennessee were allegedly discovered.

"Our voting systems are weak and susceptible," Jake Braun, a former White House advisor and now-cybersecurity lecturer at the University of Chicago, told The Register. "Thanks to the contributions of the hacker community today, we've uncovered even more about exactly how."

He continued: "The scary thing is we also know that our foreign adversaries – including Russia, North Korea, and Iran – possess the capabilities to hack them too, in the process undermining principles of democracy and threatening our national security."

In one instance, a hacker was able to crack the WinVote machine's operating system, Windows XP, and install Windows Media Player to then blast Rick Astley's "Never Gonna Give You Up" from the built-in speakers. That was certainly in line with the playful ethos of Defcon.

Some hackers were able to crack the machines within an hour-and-a-half, with many more sitting for hours tinkering with the hardware and software to locate vulnerabilities.

There remains little independent research into the digital protections of such machines.

While each US state will have its own system (meaning it is highly-unlikely an entire presidential election could be hijacked on a national scale) experts fear that cybercriminals could target key battleground states to swing the results. To date, this remains largely hypothetical.

TJ Horner, an Android developer and student, tampered with the ExpressPoll 5000 voting machine during Defcon and found that he was able to exfiltrate data and even falsify voter information. "Your imagination is the limit," he noted in a blog post published on 30 July after the event.

According to Cnet, a security firm called Synack was able to exploit one machine via its USB ports. Without needing any type of authentication, the white-hat hackers plugged in a mouse and keyboard and took over the operating system by pressing "control-alt-delete".

"The exposure of those devices to the people who do bug bounties or actually look at these kind of devices has been fairly limited," Brian Knopf, an internet of things (IoT) researcher with cybersecurity firm Neustar told the publication, which attended the event.

He added: "Defcon is a great opportunity for those of us who hack hardware and firmware to look to these kind of devices and really answer that question: 'Are they hackable?'"

Source: ibtimes
WikiLeaks Releases 71,800 Hacked Emails Linked To President Emmanuel Macron

WikiLeaks Releases 71,800 Hacked Emails Linked To President Emmanuel Macron

Wikileaks founder Julian Assange
WikiLeaks has released an archive of 21,075 "verified" emails linked to the election campaign of French president Emmanuel Macron, previously leaked by unknown hackers on 5 May earlier this year, 48 hours before citizens Wikileaks founder Julian Assange to the polls.

The emails range from 20 March 2009 to 24 April 2017, WikiLeaks said in a statement sent via email on Monday 31 July. The controversial anti-secrecy website said that a full archive of "71,848 emails with 26,506 attachments from 4,493 unique senders" had been provided for context.

They are now published online in a searchable format.

WikiLeaks said it had managed to verify 21,075 emails but said that "based on statistical sampling the overwheling (sic) majority of the rest of the emails" were authentic. On 1 June, the French government said that, upon analysis, it had found no links to Russian hackers.

"[The hack] was so generic and simple that it could have been practically anyone," said cybersecurity chief Guillaume Poupard, while speaking to the Associated Press (AP) .

Declassified US intelligence – the assessment of the NSA, FBI and CIA warned in January 2017 that Moscow-linked hackers would continue to conduct "influence efforts worldwide" in the future following a slew of successful cyberattacks across the US, France and Germany.
How Hackers Cash Out Massive Bitcoins Received From Ransomware Attacks

How Hackers Cash Out Massive Bitcoins Received From Ransomware Attacks

Hacker in action
Digital currencies have emerged as a favourite tool for hackers and cyber criminals, as digital currency transactions are nearly anonymous, allowing cyber criminals to use it in underground markets for illegal trading, and to receive thousands of dollars in ransomware attacks—WannaCry, Petya, LeakerLocker, Locky and Cerber to name a few.

Also, every other day we hear about some incidents of hacking of crypto currency exchange or digital wallets, in which hackers stole millions of dollars in Bitcoin or Ethereum.

The latest back-to-back series of thefts of Ethereum—one of the most popular and increasingly valuable cryptocurrencies—in which around half a billion dollars in total were stolen is the recent example of how much hackers are after crypto currencies.

It's obvious that after ripping off hundreds of thousands of cryptocurrencies from exchanges, wallets and ransomware victims, cyber criminals would not hold them in just digital form—the next step is to cash them out into real-world money.

But how do they cash out without getting caught by law enforcement?

If you are unaware, there are some crypto currency exchanges involved in money laundering, who are illegally-operating to help hackers and cyber criminals easily cash out their digital currencies without identifying them, i.e. anonymously.

According to a recent research paper presented by three Google researchers, more than 95% of all Bitcoin payments collected from ransomware victims have been cashed out via a Russian cryptocurrency exchange, called BTC-e, since 2014.

Interestingly, just two days before Google presentation, one of the founders of BTC-e exchange, Alexander Vinnik, was arrested by Greek police on charges of laundering over $4 Billion in Bitcoin for culprits.

We uncover the cash-out points, tracking how the money exits the Bitcoin network, enabling the authorities to pick up the money trail using conventional financial tracing means,

the trio researchers, Luca Invernizzi, Kylie McRoberts and Elie Bursztein said.

Key Points — Tracking Ransomware Payments

The researchers followed the step-by-step money trail and got a look at the evolving ecosystem of ransomware families, which already helped make cyber-thieves at least $25 Million in the last two years.

✔ Most Damaging Ransomware Families: According to the research, two families of ransomware strain helped hackers made most of the money — Locky and Cerber — while other variants are also starting to emerge.

✔ Criminals looted In Millions: Locky has been the overall biggest earner for hackers at $7.8 Million and was the first ransomware infection to earn above $1 million a month to date, while Cerber has made $6.9 million to date with consistently making more than $200,000 a month.

✔ Victim's Favorite Places to Buy Bitcoins : Obviously, victims also need BTC to pay out criminals, and most victims choose LocalBitcoins, Bithumb, and CoinBase to buy BTC, where 90% victims pay in a single transaction.

✔ How Criminals Cash Out Cryptocurrency : According to the research, more than 95% of all Bitcoin payments for ransomware were cashed out via BTC-e, a service operational since 2011.

✔ Criminals Renting Out Botnets: Cybercriminal gangs behind Dridex, Locky and Cerber have taken Necurs botnet—army of compromised machines—on rent to distribute their ransomware infections on a massive scale.

Google conducted the research in collaboration with the researchers from New York University, University of California San Diego and blockchain analyst firm Chainalysis.

When talking about BTC-e, the cryptocurrency exchange is believed to have been involved in cashing out Bitcoins stolen from the once-very popular Japanese bitcoin exchange Mt. Gox, which was shut down in 2014 following a massive series of mysterious robberies.

Source: thehackersnew.com