Σάββατο 21 Φεβρουαρίου 2015

Desert Falcons


The action group Desert Falcons, a digital espionage network that targeted many organizations and high-profile individuals from the Middle East, was revealed during the Kaspersky Lab Security Analyst Summit in Mexico. Analysts consider this unit as the first known Arab group of "digital mercenaries" who have developed and executed integrated digital espionage operations against companies.

The list of victims includes military and governmental organizations, in particular, officers responsible for tackling money laundering. Also, the attack targeted executives from the fields of health and economy, leading media, research and educational institutions, energy providers and utilities, activists and political leaders, private security companies and other individuals that hold considerable geopolitical information.

The group is active for at least two years. Team Desert Falcons began to develop and consolidate the operation in 2011. However, the start of the key action of the group and infections through malware mounted in 2013. The peak of activity recorded in early 2015.

The vast majority of targets located in Egypt, Palestine, Israel and Jordan.

Apart from the Middle East, which were the original objectives, the team Desert Falcons operates outside this range. Overall, its members have been able to attack more than 3000 victims in more than 50 countries worldwide, having stolen more than one million records.

Attackers use malicious tools they have developed themselves, to launch attacks on Windows computers and Android devices. The Kaspersky Lab specialists have many reasons to believe that the mother tongue of the Desert Falcons is Arabic.

While the attack vector appears to act in countries such as Egypt, Palestine, Israel and Jordan, many victims were also found in Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, Russia and other countries.

The main method used by the group Desert Falcons for transferring malicious payload was spearphishing via email, messaging and social media messages in chat. The phishing messages contained malicious files (or link leading to malware), which imitated legal documents or applications.

The Desert Falcons team uses various techniques to lure victims and forced them to carry out malicious files. One of the most typical techniques used by the group is the so-called «Right-to-Left Override». This technique takes advantage of a special character in Unicode, to reverse the order of characters in the name of a file, hiding a dangerous extension in the middle of the name and putting a false file extension, which looks harmless, near the end of the file name. Using this technique, malicious files (.exe, .scr) look like an innocuous document or file PDF, and even careful users with good technical knowledge can be dragged and "run" these files. For example, a file with extension ".fdp.scr" will be presented as ".rcs.pdf".

After successful "infection" of the victim, team members Desert Falcons use one of two different backdoors, either their main Trojan or DHS Backdoor, which seems to have been developed from the beginning and is in constant development. The Kaspersky Lab experts managed to identify more than 100 samples of malware used for attacks.

Malicious tools used have fully backdoor functionality. So they can take screenshots, steal keystrokes, make upload or download files to collect information about all files on hard disk or USB connected devices of a victim, stealing passwords stored in the system registry (Internet Explorer and Live Messenger) and make recordings. The Kaspersky Lab experts were also able to detect traces of the activity of a malicious software, which seems to be a backdoor for Android, with call interception capabilities and SMS logs.

Δευτέρα 24 Νοεμβρίου 2014

Security Impediments the Use of Electronic Transactions

European consumers show wary regarding online shopping and online transactions, despite the fact that, in recent years, both specific transaction categories indicate significant growth. Therefore according to research by Kaspersky Lab and B2B International, 44% of European Internet users feel vulnerable during online shopping and online transactions. Meanwhile, 38%, users stated they would use electronic payment systems frequently if they felt protected by digital scams. Given these attitudes, it seems that there is a lack of trust towards the security measures taken by providers of electronic payment.

Research shows that 62% of Europeans are afraid of financial fraud on the Internet, while showing many cases where users do not feel comfortable. For example, 34% of Europeans who make online payments feel that even the official mobile application of financial companies needs more protection measures to provide real security. Moreover, 44% said they stopped a process electronic payment in the middle, as they doubted the safety of the transaction.

The level of protection against digital fraud is an important criterion for users when choosing an online store or a financial service. 61% of Europeans surveyed, said that they would prefer companies that offer additional security measures to protect their financial data. Furthermore, 71% expect from banks, electronic payment systems and electronic stores to protect their computers and portable consumer devices by financial fraud.

At the same time, many users know they need to implement their own security measures, in addition to measures that provide payment service providers. While 22% of users gives full responsibility for the security of financial transactions to banks and 14% believe that the users themselves are solely responsible for their protection, the majority (59%) of respondents believe that the economic data should be the responsibility of both. This demonstrates that users are willing to accept new tools by financial institutions that will help them deal with online fraud, as they understand their own share of responsibility.

According to analysts at Kaspersky, this reluctance hinders the development of the electronics transactions industry. To encourage the active use of electronic payments, banks, online stores and e-payment systems are required to assure users that it is safe towards digital criminals. A solution for the payment service providers is to provide additional levels of protection against financial fraud attempts, which are specially designed for safety of online or mobile banking and payments. The presence of this additional protection, reassures users directly, giving them confidence that their money are safe.

Παρασκευή 19 Σεπτεμβρίου 2014

E-Payment: Vulnerable Terminal Devices

Serious safety issues faced by financial companies and companies engaged in e-commerce showed the survey conducted by Kaspersky Lab and B2B International. You can find the full report in pdf here. Specifically, only 52% of financial companies and 46% of businesses engaged in electronic commerce believes that they should take enhanced measures to protect financial transactions. Even fewer companies in this area provide protection for the devices of their customers.

The e-commerce companies are those that focus less on the protection of economic activities. 16% of companies in the industry declare they are not interested to proceed with the installation of specific security solutions against online fraud, while only 38% are willing to invest in such tools.
Overall, 30% of companies that work with online cash flows, is not planning to offer protection to the devices of the customer during a transaction, although it is the weakest point in the security chain, with potential impact the loss of money for customers, but also a blow to earnings and reputation of the company itself. 28% of businesses are not interested in installing anti-fraud software to mobile devices of customers, while 30% of businesses are not trying to protect its own information infrastructure from potential online fraud.

This attitude to protection payments can lead to negative comments from customers. According to the survey, three-quarters (3/4) of the users expect financial companies to take responsibility for the safeguarding of their devices. Also, 40% of respondents feel confident that the company will offer compensation for any money lost.

However, the statistics of Kaspersky Lab show that the number of digital threats targeting financial data of individual users increases constantly. For example, according to the Kaspersky Security Network, the attacks that used malicious software targeting the banking touched 1.4 million during the period May 19-June 19, an increase of 15% compared with the period April 19-May 19.