CareerBuilder Phishing Attacks

Once again, another popular website is facing the consequences of a phishing attack, although this time it is a little different. Normally when you think of a phishing attack you come to the conclusion that some clueless individual clicked a link in an email and corrupted the system, or gave away important information to a phony account and cost their business millions of dollars. The blame isn’t as easily directed on certain individuals this time around.

For anyone who doesn’t know what careerbuilder.com is or has never heard of it, it is a popular job searching service website. Tons of companies post job advertisements on this website such as open positions, then users can browse these job postings by area or category and apply. Generally you are able to just apply right from the website and upload your resume and attach it as a word document. Whenever a job seeker uploads their resume to a job posting, careerbuilder then notifies the company of the uploaded document. The people behind these attacks just simply title the document things such as “resume.doc” or “cv.doc” and employers open them as if it was just another typical resume. The employees download these attachments which on the surface appear to be just another applicant, but the files then go on to exploit a memory corruption vulnerability in Word RTF. This causes the infected machine to download a payload, which downloads a .zip file containing an image file which then drops a rootkit, Sheldor, on the machine. An image file is used because anti-virus programs tend to look past image files as they are expected to be nothing more than that. This is a dangerous peace of malware working its way into the organizations seeking new employees. Although the methods behind these attacks require a lot more work from the attackers due to having to find job posting and actually apply to them manually with their documents, the benefit is that it is very likely the majority of their attempts will indeed be successful. Typically, these kind of phishing attacks are just attempted with fake email accounts trying to fool people and is much less likely to work.

Researchers from a firm known as Proofpoint uncovered the information behind these malware attacks stating that the malicious documents were created in a program called Microsoft Word Intruder (MWI), a FireEye tool that was created in April of this year. This tool is sold on underground forums and serves up CVE-weaponized docs and costs around $2000-$3500 to purchase. Proofpoint also claims that careerbuilder took swift action against these attacks, but didn’t state exactly how. The bigger issue here is the fact that these attacks are always going to be a risk on job search websites and other alike websites with file attachments for attackers to parse out malware.

careerbuilder_malware

Sources:

https://threatpost.com/attackers-peddling-malware-via-careerbuilder/112553

http://www.tripwire.com/state-of-security/latest-security-news/new-malware-campaign-on-careerbuilder-com-blends-phishing-with-social-engineering/

Additional Information:

http://www.esecurityplanet.com/network-security/careerbuilder.com-leveraged-to-launch-phishing-attacks.html

http://www.toptechnews.com/article/index.php?story_id=0020002934CO

-Liam Ellis

White House email service hacked.

White House officials this week publicly admitted that during October of last year, hackers were able to access Obama’s and the State Department’s unclassified emails. This resulted in system administrators shutting down the unclassified email system for a month. Although the hackers were unable to access the classified emails in Obama’s Blackberry, they did access the email archives of people inside the White House. It is because of this second breach that actual classified information may have been leaked. These e-mails include, among other things, schedules, e-mails with ambassadors and diplomats, talks about policy and legislation changes, and information about future personnel deployments.
The attack is believed to have originated from Russia. According to the New York Times, the hack “was far more intrusive and worrisome than has been publicly acknowledged,” partly because the hacker group is presumed to be linked to, or working for, the Russian government. Although the president’s email was not directly breached, it remains unclear just how many of his emails were accessed through the accounts of other staff.

According to online security company FIreEye,this latest attack follows the modus operandi of Russian state-sponsored cyber attacks. The compile times for the malware matches the normal working hours of major Russian cities, and there is a lack of focus on monetary gain. Instead, the attacks focus on acquiring military, government and security information. Previous targets of this particular group, known as “APT28″, include US defense and military contractors and NATO officials.

https://www.fireeye.com/content/dam/legacy/blog/2014/10/Table-for-APT28.jpg

-Luis Gonzalez.

Sources:
http://www.nytimes.com/2015/04/26/us/russian-hackers-read-obamas-unclassified-emails-officials-say.html

http://www.zdnet.com/article/russian-hackers-read-obama-emails-report/

Dyre Wolf

Dyre Wolf is an ongoing and complex attack that combines multiple types of attacks into one large scam that has managed to make the attackers millions of dollars from companies. The attack consists of an initial spear phishing attack on a company. Contained within the email is an installer that will install the program upatre that is commonly disguised as pdf or some other file type. Once installed the attacker is allowed access to the computer by the installed software. The attacker installs Dyre onto the victims computer which allows the attacker to modify information when he chooses. The attack really ramps up when the victim goes to log into the bank. Dyre allows the attacker to modify the page returned to show a fake phone number and a message telling the user to call the number to resolve the issues. At this point it is up to the attacker to use social engineering to coerce the proper banking information out of the user. Once this happens the attacker will go and transfer the money to an account that is offshore commonly. Then the attacker will run a DDoS attack against the company to try and throw the company off from what happened and slow the companies ability to figure out who the attacker was.

Some steps to help prevent this would include making sure that people know to report anything that seems suspicious. Run mock phishing attacks against your users to help train them to look for the suspicious emails.

Samuel Mosher

http://securityintelligence.com/dyre-wolf/#.VTVUByFVhBc

http://phishme.com/evolution-upatre-dyre/

IBM X-Force Exchange

The IBM X-Force Exchange is a database of current security information. It compiles found vulnerabilities, known exploits, and malicious IPs. I signed up for the service for free and interface is very sleek and clear looking. The main screen is just IP after IP popping up as dangerous. There is a counter of malicious IPs logged in the last hour and there are over 1,000. Of course 99.9% of them are in the spam category but it looks like every once in a while one is flagged with scanning, malware, or command & control. There are also interest feed like found vulnerabilities, security related blog posts, and recent big topics like China scanning IP’s, PoSeidon POS malware, and IRC botnets. There are options to  add things to “Collections” which let you save reports on IPs to look at later.

IBM claims that their service is “One of the largest and most complete catalogs of vulnerabilities in the world” and that they log 25 billion security events per day. Users have access to over 700 terabytes of raw data, the rate of which will continue to grow the more users there are. The platform is designed to foster communication between security teams at different companies so that everyone can be better protected from cybercrime.

This platform is a big deal in the security community and will help centralized the knowledge gained by professionals. It will thwart a lot of loss sophisticated cybercriminals but the problem is that it doesn’t help against targeted attacks. It is more of a band-aid than a set of armor that keeps companies from falling for the same attack twice.

Ryan Frank

Links:

http://finance.yahoo.com/news/ibm-opens-threat-intelligence-combat-100000781.html

https://exchange.xforce.ibmcloud.com/

Target: human weakness, not system weakness

In an interview with 60 Minutes, Jon Miller, former hacker who is currently serving as vice president of strategy at Cylance stated that given the current security levels for most companies, 90 percent of them would be vulnerable to such an attack which destroyed 3,000 computers and released sensitive information and proprietary content and he used the example of the cyber attack on Sony.

The Sony hack is one of the many recent security breaches that exposed a mass amount of caches of sensitive data belonging to individuals, corporations, and governments. The hacker group; Guardians of Peace leaked personal information ranging from social security numbers, over 47,000 celebrities, freelancers, and current and former Sony employees. Also, unreleased movies, embarrassing emails between Sony and internal documentation. Not only did Sony experience a data breach, but so did Home Depot, Target, Anthem (insurance provider), and a vast number of high profile businesses. Between the previously named businesses, the combined exposed information affected an estimated total of 246 million people.

Since 2014, the hacks on businesses and government agencies have grown nearly 50 percent from 2013 as there were more than 1,500 data breaches world wide.  http://www.cnet.com/news/in-shift-hackers-want-your-identity-not-just-your-credit-card/

With the outcome and predictability of what may be expected on hacks on systems within businesses and government agencies, professionals state that these hacks aren’t as remote as we’d like to believe and that security is not only about defending the systems, but being on the offensive side. To raise awareness of the security news and issues in today as well as what is expected, we ought to realize that the human weakness is what is targeted, not so much the system weakness. This weakness needs to be assessed and discussed as today’s amount of population is likely to be computer or tech savvy, curiously taking advantage of systems and the user.

Link to article: http://www.cnet.com/news/thousands-could-launch-sony-style-cyber-attack-says-ex-hacker/

Makaya Hicks