Security

New 'FontOnLake' Malware Family Can Target Linux Systems (securityweek.com) 26

Security Week reports: A previously unknown, modular malware family that targets Linux systems has been used in targeted attacks to collect credentials and gain access to victim systems, ESET reported on Thursday. Dubbed FontOnLake, the malware family employs a rootkit to conceal its presence and uses different command and control servers for each sample, which shows how careful its operators are to maintain a low profile.

What's more, the malware developers are constantly modifying the FontOnLake modules, and use three categories of components that have been designed to work together, namely trojanized applications, backdoors, and rootkits.

Evidence suggests that FontOnLake has been used in attacks aimed at organizations in Southeast Asia. The first malware samples related to this family emerged last May. The malware was previously described by Avast and Lacework as the HCRootkit / Sutersu Linux rootkit, as well as by Tencent Security Response Center in a February report.

The various trojanized applications that ESET's researchers have identified during their investigation are used to load custom backdoor or rootkit modules, but also to collect sensitive data when needed. Posing as standard Linux utilities, these files were also designed to achieve persistence on the compromised systems. What the researchers haven't figured out yet is the manner in which the trojanized applications are delivered to the victims. ESET's analysis of FontOnLake has revealed the use of three different backdoors, all written in C++, all using the same Asio library from Boost, and all capable of exfiltrating sshd credentials and bash command history.

The simplest of the three was designed to launch and mediate access to a local SSH server, update itself, and transmit collected credentials. The malware appears to be under development.

The second backdoor was also capable of file manipulation, updating itself, and uploading and downloading files, according to the article, while the third backdoor "accepts remote connections, serves as a proxy and can download and run Python scripts, in addition to exfiltrating credentials."
IT

New Data: Tech Companies Expand Hiring From 'Tech Hubs' to 'All Over The Place' (nytimes.com) 28

"Just two years ago the metropolitan areas that serve as the nation's technology hubs seemed to be sucking tech jobs away from other parts of the country," remembers business writer Peter Coy in the New York Times. "A Brookings Institution report in December 2019 noted that just five cities — Boston, San Diego, San Francisco, Seattle and San Jose, Calif. — accounted for more than 90 percent of employment growth in the innovation sector from 2005 to 2017.

"The trend is now in the other direction: The tech hubs' share of employment is falling." This development was already starting in 2019, and the Covid-19 pandemic has accelerated it. Newspapers are full of stories about Silicon Valley tech workers moving to parts of the country where the housing is cheaper and the fishing is better... Employers seem to be benefiting from the trend: Mark Muro, a Brookings senior fellow, told The Wall Street Journal in July that tech companies, by letting people work outside their home offices, can "truly access lost Einsteins all across the country."

The evidence for this shift used to be mostly anecdotal. Now there's hard data. It comes from the Conference Board, a business-supported research organization. Gad Levanon, the founder of the board's Labor Market Institute, gave me a preview of data he has collected using software that tracks almost all the online want ads in the United States. He focused on ads placed by tech employers based in five tech hubs — the same five as those surveyed by Brookings in 2019, except with Los Angeles in place of Boston. His findings? "West Coast tech companies are dramatically shifting their hiring to other parts of the U.S.," Levanon wrote to me in an email. "Not just for tech jobs, but also engineers, scientists, managers, business and financial professionals."

Levanon also analyzed the data according to where new jobs are being offered. "They are moving to all over the place," he wrote me. Some of the jobs, he explained, are in metropolitan areas where the employers were already established — such as New York, Washington, Boston and Austin, Texas. "But some of the shift," he said, "is to areas where they barely hired before" — like Boise, Idaho, and Des Moines, Iowa. Because of the pandemic, employers have gotten more comfortable with hiring people who don't work at their companies' headquarters, Levanon says. Some new hires may be working at home while others are in satellite offices. Casting the net wider gives companies access to more talent — including people who may work for lower salaries because their living costs are cheaper elsewhere.

Google

Google Warns 14,000 Gmail Users Targeted By Russian Hackers (bleepingcomputer.com) 13

Google has warned about 14,000 of its users about being targeted in a state-sponsored phishing campaign from APT28, a threat group that has been linked to Russia. BleepingComputer reports: Shane Huntley, who is at the helm of Google's Threat Analysis Group (TAG) that responds to government-backed hacking, notes that the higher-than-usual number of alerts this month comes from "from a small number of widely targeted campaigns which were blocked." The campaign from APT28, also known as Fancy Bear, lead to a larger number of warnings for Gmail users across various industries. In a statement sent by a Google spokesperson, Huntley says that Fancy Bear's phishing campaign accounts for 86% of all the batch warnings delivered this month. He explains that these notifications indicate targeting of the recipient, not a compromise of their Gmail account: "So why do we do these government warnings then? The warning really mostly tells people you are a potential target for the next attack so, now may be a good time to take some security actions."

Huntley says that these warnings are normal for individuals such as activists, journalists, government officials, or people that work national security structures because that's who government-backed entities are targeting. All the phishing emails from the Fancy Bear campaign were blocked by Gmail and did not land in the users' inboxes as they were automatically classified as spam. "As we've previously explained, we intentionally send these notices in batches, rather than at the moment we detect the threat itself, so that attackers cannot track some of our defense strategies," Huntley said.

Beer

BrewDog Exposes Data of 200,000 Customers and Shareholders (techradar.com) 13

An anonymous reader quotes a report from TechRadar: BrewDog, one of the world's largest craft beer brewers, has exposed personally identifiable information (PII) belonging to more than 200,000 of its shareholders and customers, according to cybersecurity researchers. Cybersecurity consulting firm PenTest Partners discovered that a flaw in the official BrewDog app, which persisted for more than 18 months, made it easy for anyone to access the PII of other users. In its detailed report, PenTest Partners notes that the mobile app doled out the same hard coded API Bearer Token, which effectively rendered request authorization useless. The researchers say that, thanks to the flaw, any user could append the customerID of another user to the API endpoint URL to extract their PII and other details. In addition to being damaging to the user, the flaw could've also been used to adversely affect the company since the leaked details could've been used to generate QR codes to get discounted and even free beers. BrewDog started using hard-coded tokens with v2.5.5 of its app, launched in March 2020, before finally patching the flaw in v2.5.13 release in September 2021.
Facebook

Facebook Says Some of Its Services Are Having Issues Again (theverge.com) 32

Instagram has been experiencing issues for many of us here at The Verge, but it turns out that the problem might be broader than that, according to a statement from Facebook. From a report: "We're aware that some people are having trouble accessing our apps and products," Facebook said in a tweet. "We're working to get things back to normal as quickly as possible and we apologize for any inconvenience."
Google

Google To Give Security Keys To 'High Risk' Users Targeted by Government Hackers (techcrunch.com) 23

Google has said it will provide 10,000 "high-risk" users with free hardware security keys, days after the company warned thousands of Gmail users that they were targeted by state-sponsored hackers. From a report: The warning, sent by Google's Threat Analysis Group (TAG), alerted more than 14,000 Gmail users that they had been targeted in a state-sponsored phishing campaign from APT28, also known as Fancy Bear, said to be made up of operatives of Russia's GRU intelligence agency. Fancy Bear has been active for more than a decade but it's widely known for hacking into the Democratic National Committee and its disinformation and election influencing campaign in the run-up to the 2016 U.S. presidential election. "These warnings indicate targeting not compromise. If we are warning you there's a very high chance we blocked," Google's TAG director Shane Huntley wrote in a Twitter thread on Thursday. "The increased numbers this month come from a small number of widely targeted campaigns which were blocked."
Security

Twitch Defaced With Pictures of Jeff Bezos (theverge.com) 18

Hackers have managed to deface Twitch for a few hours this morning, replacing a number of background game images with photos of Amazon CEO Jeff Bezos. From a report: Users reported seeing images of Bezos in the listings for GTA V, Dota 2, Smite, Minecraft, Apex Legends, and many more on the Amazon-owned service. It's not clear how the background images were changed or whether this latest incident was aided by a huge security breach at Twitch earlier this week. Hackers were able to exploit a server misconfiguration and steal hundreds of gigabytes of information. Twitch is still investigating the breach, and so far a wealth of information pertaining to the website's source code, unreleased projects, and even how much the top streamers make has been released.
Crime

Car Thieves Arrested After Using $27,000 Game Boy Device (bbc.com) 104

An anonymous reader quotes a report from the BBC: A gang of car thieves used a handheld device disguised as a Nintendo Game Boy to steal vehicles worth $245,000. Dylan Armer, Christopher Bowes and Thomas Poulson stole five Mitsubishi Outlanders by using the gadget to bypass the cars' security systems. West Yorkshire Police said the device, worth $27,000 could unlock and start a car "in a matter of seconds." The trio, all from Yorkshire, were jailed at Leeds Crown Court after pleading guilty to conspiracy to steal. CCTV footage of the theft showed them unplug the car from its charging point before using the device to unlock and start it. When officers stopped the three men they found the Game Boy-style gadget hidden in a secret compartment of their car. Police said footage recovered from Poulson's phone showed him demonstrating "how quickly and easily the gadget gave them full access to the vehicles, accompanied by a commentary in mocking tones." The force added that the "significant investment required to buy one of the sophisticated devices suggested the thefts were planned and orchestrated crimes."
Security

Hackers of SolarWinds Stole Data On US Sanctions Policy, Intelligence Probes (reuters.com) 12

An anonymous reader writes: The suspected Russian hackers who used SolarWinds and Microsoft software to burrow into U.S. federal agencies emerged with information about counter-intelligence investigations, policy on sanctioning Russian individuals and the country's response to COVID-19, people involved in the investigation told Reuters. The hacks were widely publicized after their discovery late last year, and American officials have blamed Russia's SVR foreign intelligence service, which denies the activity. But little has been disclosed about the spies' aims and successes. [...] It has been previously reported that the hackers breached unclassified Justice Department networks and read emails at the departments of treasury, commerce and homeland security. Nine federal agencies were breached. The hackers also stole digital certificates used to convince computers that software is authorized to run on them and source code from Microsoft(MSFT.O) and other tech companies. One of the people involved said that the exposure of counter-intelligence matters being pursued against Russia was the worst of the losses.

In an annual threat-review paper released on Thursday, Microsoft said the Russian spies were ultimately looking for government material on sanctions and other Russia-related policies, along with U.S. methods for catching Russian hackers. Cristin Goodwin, general manager of Microsoft's Digital Security Unit, said the company drew its conclusions from the types of customers and accounts it saw being targeted. In such cases, she told Reuters, "You can infer the operational aims from that." Others who worked on the government's investigation went further, saying they could see the terms that the Russians used in their searches of U.S. digital files, including "sanctions."

Chris Krebs, the former head of U.S. cyber-defense agency CISA and now an adviser to SolarWinds and other companies, said the combined descriptions of the attackers' goals were logical. "If I'm a threat actor in an environment, I've got a clear set of objectives. First, I want to get valuable intelligence on government decision-making. Sanctions policy makes a ton of sense," Krebs said. The second thing is to learn how the target responds to attacks, or "counter-incident response," he said: "I want to know what they know about me so I can improve my tradecraft and avoid detection."

Microsoft

Microsoft: Russia Behind 58% of Detected State-backed Hacks (apnews.com) 33

Russia accounted for most state-sponsored hacking detected by Microsoft over the past year, with a 58% share, mostly targeting government agencies and think tanks in the United States, followed by Ukraine, Britain and European NATO members, the company said. From a report: The devastating effectiveness of the long-undetected SolarWinds hack -- it mainly breached information technology businesses including Microsoft -- also boosted Russian state-backed hackers' success rate to 32% in the year ending June 30, compared with 21% in the preceding 12 months. China, meanwhile, accounted for fewer than 1 in 10 of the state-backed hacking attempts Microsoft detected but was successful 44% of the time in breaking into targeted networks, Microsoft said in its second annual Digital Defense Report, which covers July 2020 through June 2021.

While Russia's prolific state-sponsored hacking is well known, Microsoft's report offers unusually specific detail on how it stacks up against that by other U.S. adversaries. The report also cited ransomware attacks as a serious and growing plague, with the United States by far the most targeted country, hit by more than triple the attacks of the next most targeted nation. Ransomware attacks are criminal and financially motivated. By contrast, state-backed hacking is chiefly about intelligence gathering -- whether for national security or commercial or strategic advantage -- and thus generally tolerated by governments, with U.S. cyber operators among the most skilled. The report by Microsoft, which works closely with Washington government agencies, does not address U.S. government hacking.

Microsoft

Microsoft Makes a Mouse From Recycled Ocean Plastic (microsoft.com) 49

New submitter myinnerbanjo writes: With plastics in oceans becoming more and more of a global disaster, Microsoft uses recycled ocean plastic to create a new computer mouse:

"We wanted to do something that's different," said Corinne Holmes, director of environmental compliance, Windows & Devices. "I don't want the clean stuff. We wanted to push the bar. This plastic wasn't from a collection bin sitting on the beach. It was recovered out of a river. It's dirty. It was sitting there for six months, not three weeks."


Security

Twitch's Security Problems Started Long Before This Week's Hack (theverge.com) 19

A massive security breach at Twitch has exposed a wealth of information pertaining to the website's source code, unreleased projects, and even how much the top streamers make. As data analysts and journalists work to decipher what exactly is contained in the hundreds of gigabytes of information, others are still wondering how this happened. From a report: Such a breach seemed like it was increasingly likely to some. The Verge has spoken to multiple sources who claim that during their time at Twitch, the company valued speed and profit over the safety of its users and security of its data. This data breach, which Twitch blames on an error to a server configuration, is the latest in a series of security and moderation problems that have plagued the Amazon-owned streaming platform. In August, hate raids in which marginalized streamers were subjected to uncontrollable numbers of bots spamming hate speech erupted across Twitch. Streamers banded together to create the #twitchdobetter hashtag and organized a walkout on September 1st to bring attention to the problem and spur Twitch to deploy safety measures to stem the hate tide. In response, Twitch acknowledged streamers' complaints, urged patience, and promised it was working on tools that would help to better protect streamers and their communities.
Security

US To Tell Critical Rail, Air Companies To Report Hacks, Name Cyber Chiefs (reuters.com) 23

The Transportation Security Administration will introduce new regulations that compel the most important U.S. railroad and airport operators to improve their cybersecurity procedures, Homeland Security Secretary Alejandro Mayorkas said on Wednesday. From a report: The upcoming changes will make it mandatory for "higher-risk" rail transit companies and "critical" U.S. airport and aircraft operators to do three things: name a chief cyber official, disclose hacks to the government and draft recovery plans for if an attack were to occur. The planned regulations come after cybercriminals attacked a major U.S. pipeline operator here, causing localized gas shortages along the U.S. East Coast in May. The incident led to new cybersecurity rules for pipeline owners in July.

"Whether by air, land, or sea, our transportation systems are of utmost strategic importance to our national and economic security," Mayorkas said. "The last year and a half has powerfully demonstrated what's at stake." A key concern motivating the new policies comes from a growth in ransomware attacks against critical infrastructure companies.

Security

Navy Facebook Account Hacked To Stream 'Age of Empires' (vice.com) 37

An anonymous reader quotes a report from Motherboard: The U.S. Navy has lost control of the official Facebook page for its destroyer-class warship, the USS Kidd. Someone has hacked the page and, for the past two days, done nothing but stream Age of Empires. The first stream went on for four hours. As first reported by Task & Purpose, the USS Kidd lost control of its Facebook account at 10:26 p.m. on October 3. The destroyer class warship then streamed Age of Empires for four hours under the headline "Hahahahaha." It's since streamed Age of Empires five more times, each time for at least an hour. Whoever is playing sucks, because they never make it past the Stone Age. As of this writing, the six videos are still up and watchable. The Navy confirmed to Task & Purpose that it had been hacked, adding: "We are currently working with Facebook technical support to resolve the issue."
IT

How Downdetector Has Become Go-To Site for Online Disruptions (bloomberg.com) 26

An anonymous reader shares a report: When Facebook's platforms went down early on Oct. 4, the online tracker Downdetector was among the first places users looked to find out what was happening. Downdetector, which uses crowdsourcing to track outages, recognized Facebook's problems were dramatically different than a typical outage. Its system automatically released a notification, including a tweet, informing the internet of the disruption. The outage was among the biggest ever declared by Downdetector, said Luke Deryckx, chief technology officer at closely held Ookla LLC, the Seattle-based company that owns it. "Downdetector is a vehicle for users to report their experience," he said, adding that the company crowdsources "users' relationship with the internet." "In this case, we'd received a clear and almost instantaneous signal that there was a Facebook-related outage."

The idea of Downdetector was born over drinks at a bar in Haarlem, a city in the Netherlands, in February 2012. Tom Sanders and Sander van de Graaf were both working at IDG Communications Inc., the media publisher of magazines including CIO and Computerworld. Van de Graaf was a developer, and Sanders was the editor in chief. Readers would often call the newsroom to report an online outage at a company or service provider, but the reporters would often get no response -- or have to wait hours -- when they called to ask about the disruption. "We thought, wouldn't there be ways to automate this so we didn't have to check with the press office and we could get the data directly ourselves?" Van de Graaf said.

Privacy

Twitch Source Code and Business Data Leaked (therecord.media) 66

An unknown individual has leaked the source code and business data of video streaming platform Twitch via a torrent file posted on the 4chan discussion board earlier today. From a report: The leaker said they shared the data as a response to the recent "hate raids" --coordinated bot attacks posting hateful and abusive content in Twitch chats -- that have plagued the platform's top streamers over the summer. "Their community is [...] a disgusting toxic cesspool, so to foster more disruption and competition in the online video streaming space, we have completely pwned them, and in part one, are releasing the source code from almost 6,000 internal Git repositories," the leaker said earlier today. The leaker claims that the leak contains the "entirety of twitch.tv, with commit history going back to its early beginnings, mobile, desktop and video game console Twitch clients, various proprietary SDKs and internal AWS services used by Twitch, every other property that Twitch owns including IGDB and CurseForge, an unreleased Steam competitor from Amazon Game Studios, and Twitch SOC internal red teaming tools."

Twitch has confirmed the breach. In a tweet it said, "We can confirm a breach has taken place. Our teams are working with urgency to understand the extent of this. We will update the community as soon as additional information is available."
Google

Google Is About To Turn On Two-Factor Authentication By Default For Millions of Users (theverge.com) 108

Google is reminding us that it will enable two-factor authentication for 150 million more accounts by the end of this year. The Verge reports: In 2018, Google said that only 10 percent of its active accounts were using two-factor authentication. It has been pushing, prodding, and encouraging people to enable the setting ever since. Another prong of the effort will require more than 2 million YouTube creators to turn on two-factor authentication to protect their channels from takeover. Google says it has partnered with organizations to give away more than 10,000 hardware security keys every year. Its push for two-factor has made the technology readily available on your phone whether you use Android or iPhone.

A tool that also helps users keep their accounts secure is using a password manager, and Google now says that it checks over a billion passwords a day via its built-in manager for Chrome, Android, and the Google app. The password manager is also available on iOS, where Chrome can autofill logins for other apps. Google says that soon it will help you generate passwords for other apps, making things even more straightforward. Also coming soon is the ability to see all of your saved passwords directly from the Google app menu. Last but not least, Google is highlighting its Inactive Account Manager. This is a set of decisions to make about what happens to your account if you decide to stop using it or are no longer around and able to make those decisions.

Encryption

Telegram Founder Says Over 70 Million New Users Joined During Facebook Outage (reuters.com) 50

Messaging app Telegram gained over 70 million new users during Monday's Facebook outage, its founder Pavel Durov said on Tuesday, as people worldwide were left without key messaging services for nearly six hours. Reuters reports: Facebook blamed its outage, which kept its 3.5 billion users from accessing services such as WhatsApp, Instagram and Messenger, on a faulty configuration change. "The daily growth rate of Telegram exceeded the norm by an order of magnitude, and we welcomed over 70 million refugees from other platforms in one day," Durov wrote on his Telegram channel. Durov said some users in the Americas may have experienced slower speeds as millions rushed to sign up at the same time, but that the service worked as usual for the majority.
Government

Ransomware Bill Would Give Victims 48 Hours To Report Payments (bloomberg.com) 89

Victims of ransomware attacks would be required to report payments to their hackers within 48 hours under a proposal from Democratic Senator Elizabeth Warren and Democratic Representative Deborah Ross. From a report: The Ransom Disclosure Act would give the Department of Homeland Security data on ransomware payments, including the amount of money demanded and paid, and the type of currency used. The lawmakers say this is essential to bolster the U.S. government's understanding of how hackers operate and the extent of the ransomware threat. "Ransomware attacks are skyrocketing, yet we lack critical data to go after cybercriminals," Warren said in a statement on Tuesday.
Security

Apache Fixes Actively Exploited Web Server Zero-day (therecord.media) 34

The Apache Software Foundation has released a security patch to address a vulnerability in its HTTP Web Server project that has been actively exploited in the wild. From a report: Tracked as CVE-2021-41773, the vulnerability affects only Apache web servers running version 2.4.49 and occurs because of a bug in how the Apache server converts between different URL path schemes (a process called path or URI normalization). "An attacker could use a path traversal attack to map URLs to files outside the expected document root," the ASF team said in the Apache HTTP Server 2.4.50 changelog. "If files outside of the document root are not protected by 'require all denied' these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts," Apache engineers added. More than 120,000 servers currently exposed online to attacks.

Slashdot Top Deals