Showing posts with label FireEye. Show all posts
Showing posts with label FireEye. Show all posts

Tuesday, December 15, 2020

Hackers breach US agencies, Homeland Security a reported target

NEW YORK - The US Department of Homeland Security was the third federal department to be targeted in a major cyberattack, US media reported Monday, a day after Washington revealed the hack which may have been coordinated by a foreign government.

The Washington Post cited unnamed officials who said that the DHS -- which is in charge of protecting the country from attacks both online and off -- had been added to a growing list of targets in the attack, including the Treasury and Commerce departments.

A statement from DHS Monday did not confirm the report, saying only that it was "aware of cyber breaches across the federal government and working closely with our partners in the public and private sector on the federal response."

The Cybersecurity and Infrastructure Security Agency (CISA), which is attached to the DHS, on Sunday said it had ordered federal agencies to immediately stop using SolarWinds Orion IT products following reports that hackers had used a recent update to gain access to internal communications. 

"We urge all our partners -- in the public and private sectors -- to assess their exposure to this compromise and to secure their networks," said CISA Acting Director Brandon Wales.

SolarWinds over the weekend admitted that hackers had exploited a backdoor in an update of some of its software released between March and June.

The hacks are part of a wider campaign that also hit major cybersecurity firm FireEye, which said its own defenses had been breached by sophisticated attackers who stole tools used to test customers' computer systems.

FireEye said it suspected the attack was state-sponsored, and warned it could have affected numerous high profile targets across the globe.

"This campaign may have begun as early as Spring 2020 and is currently ongoing," FireEye said in a blog post.

RUSSIA INVOLVED?

The content the hackers have sought to steal -- and how successful they have been -- is not known at this time. 

"We believe this is nation-state activity at significant scale, aimed at both the government and private sector," said IT giant Microsoft, which is also investigating, in a blog post. 

While Microsoft refrained from naming a country, several US media pointed the finger at the Russian group "APT29", also known as "Cozy Bear." 

According to the Washington Post, the group is part of Moscow's intelligence services, and hacked servers at the State Department and the White House during the Obama administration.

The Russian Embassy in the United States categorically denied the accusations in a statement on Facebook.

Both the public and private sectors must be increasingly on guard against such hacks, warned Hank Schless, senior manager at Lookout, a California-based mobile security company. 

"Adversarial nation-states have recognized the value in targeting both sectors, which means neither is safe from the types of attacks that have government resources behind them," he said.

Matt Walmsley of Vectra, which provides cyberattack detection services from its base in California, agreed.

"Security teams need to drastically reduce the overall risk of a breach by gaining instant visibility and understanding of who and what is accessing data or changing configurations, regardless of how they are doing it, and from where," he said.

Agence France-Presse

Wednesday, December 9, 2020

US-based hacker fighter FireEye says breached by elite attackers

SAN FRANCISCO - Hacker fighting firm FireEye on Tuesday said its own defenses were breached by sophisticated attackers who stole "Red Team" tools used to test customers' computer systems.

While the hackers had yet to be identified, their tactics and targets led FireEye to believe it was a state-sponsored attack "by a nation with top-tier offensive capabilities."

"The hack of a premier cybersecurity firm demonstrates that even the most sophisticated companies are vulnerable to cyber-attacks," said US Senator Mark Warner, a Democrat who is vice chairman of the

 senate Select Committee on Intelligence.

"We have come to expect and demand that companies take real steps to secure their systems, but this case also shows the difficulty of stopping determined nation-state hackers."

It did not appear any customer data was stolen from FireEye, or that the taken tools have been used in other attacks, according to the Silicon Valley-based firm.

"The attackers tailored their world-class capabilities specifically to target and attack FireEye," FireEye chief executive Kevin Mandia said in a blog post revealing the breach.

"They used a novel combination of techniques not witnessed by us or our partners in the past."

FireEye shares were down more than 7 percent in after-market trades that followed released of news about the hack.

RELENTLESS ATTACKS

FireEye said it is investigating the attack with help from the FBI and industry partners, including technology colossus Microsoft.

"Their initial analysis supports our conclusion that this was the work of a highly sophisticated state-sponsored attacker utilizing novel techniques," Mandia said.

The hackers primarily sought information related to government customers which is consistent with nation-state cyberespionage, according to FireEye.

Also targeted in the attack were "Red Team" tools that help diagnose the security of customers' networks by mimicking the behavior of hackers, Mandia said.

FireEye was making available countermeasures to defend against someone using the tools.

The US Department of Homeland Security said it was aware of the attack but that it had no information indicating the stolen cyber tools were being "maliciously used" so far.

US spy agencies have been asked to brief the House Permanent Select Committee on Intelligence about the cyber attack in the coming days, according to chairman Adam Schiff, a Democrat from California.

"Foreign actors have not stopped attacking our country and its critical and cybersecurity infrastructure since 2016," Schiff said.

Schiff found it troubling that the hackers stole from FireEye tools that could be used in future attacks.

OIL-BANKS-POLITICS

The FireEye hack came less than two months after the US Treasury announced sanctions against a Russian research institute which it said was tied to the powerful malware Triton, used to damage a Saudi petrochemical plant in 2017.

FireEye tied Triton to the Moscow-based research institute and a specific, unnamed person with close ties to the institute.

It was not determined whether Russia was linked to the FireEye hack.

"The Russian government continues to engage in dangerous cyber activities aimed at the United States and our allies," Treasury Secretary Steven Mnuchin said in a statement at the time.

FireEye's track record includes identifying an Iran-based social media campaign to sway public opinion by impersonating reporters, politicians and others, as well as identifying North Korean hackers implicated in of a wave of cyberattacks on global banks that netted "hundreds of millions" of dollars.

Agence France-Presse

Tuesday, April 26, 2016

SWIFT network says aware of multiple cyber fraud incidents


SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.

The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of $81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.

Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.

"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.

The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.

SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is a cooperative owned by 3,000 financial institutions.

Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.

BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.

BAE said it could not explain how the fraudulent orders were created and pushed through the system.

But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.

It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.

FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.

"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.

FireEye declined to go into detail.

Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.

But he urged banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.

“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said

FOLLOWING THE MONEY

Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.

Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.

"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."

Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.

"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.

SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.

"Customers should do their utmost to protect against this," she said in an email to Reuters.

SWIFT told customers that the security update must be installed by May 12.

"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.

source: www.abs-cbnnews.com