Friday, 3 July 2015

Trump Hotels Hacked

Was one of the businesses helmed by Donald Trump breached via a point-of-sale malware hack attack?

Trump is CEO of Trump Hotel Properties, which has confirmed that it is investigating reports that it suffered a data breach, leading to the theft and fraudulent use of its customers` payment card data.

The company`s executive vice president of development and acquisitions, Eric Trump - son of Donald - on July 1 confirmed the breach investigation.

`Like virtually every other company these days, we have been alerted to potential suspicious credit card activity and are in the midst of a thorough investigation to determine whether it involves any of our properties,` he said. `We are committed to safeguarding all guests` personal information and will continue to do so vigilantly.`

News of the potential data breach at Trump Hotel Properties was first reported by security blogger Brian Krebs. He reported that multiple banks had spotted a pattern of fraud beginning in February, suggesting that payment-card data for customers of Trump Hotel Properties in multiple locations - including Chicago, Honolulu, Las Vegas, Los Angeles, Miami and New York - had been stolen.

But according to Ken Westin, a senior security analyst at Tripwire, it`s possible that any such breach might not trace directly to the hotels, but instead involve a third-party, such as a payment processor.

POS Malware Epidemic

If the card-data breach at Trump Hotel Properties is confirmed, it would join a long list of businesses - including numerous other hotel chains, retailers and restaurants, ranging from P.F. Chang`s to Target - that have been breached by hackers and lost their customers` card data.

So far this year, businesses that have reported suffering card-data breaches include global luxury hotel chain Mandarin Oriental Hotel Group, organic and health food grocery chain Natural Grocers, hotel management company White Lodging Services Corp., and retailer Sally Beauty. All of those organizations - as well as many more before them - reported that the card fraud resulted from their point-of-sale systems being compromised.

Security experts say too many such POS malware attacks today succeed because retailers and other businesses are failing to change the default passwords in place on payment-card terminals, or to segment their networks, all of which would help to better defend against POS malware attacks (see Why POS Malware Still Works).

Follows Businesses `Firing` Trump

While no business wants to see its customers` card data get stolen, news of the Trump Hotel Properties breach investigation comes at an awkward time for Donald Trump, as it follows his June 16 announcement that he was seeking the 2016 Republican presidential nomination. During his campaign kickoff speech, furthermore, Trump made a number of comments that were widely viewed as being racist.

Reaction to the comments have seen Trump ending up at the receiving end of his famous `The Celebrity Apprentice` catchphrase - `You`re fired` - as numerous businesses, including NBC, Macy`s, Univision and Televisa, amongst others, said they would cease working with Trump. NBC also announced that it would no longer broadcast the Miss USA Pageant, which is half-owned by Trump.

Read original article

Thursday, 2 July 2015

PCI Update

PCI Update Paves Way For Expanding Point-to-Point Encryption

Move appears designed mainly for large organizations and big-box retailers looking to lock down payment card security.

The PCI Security Standards Council, which administers the payment card industry data security standard, has made it easier for large merchants to implement point-to-point encryption (P2PE) for protecting cardholder data.

The Council this week updated its requirements to give merchants more choice and flexibility in the components they use for point-to point encryption. One of the key features in the Council's new P2PE Version 2.0 is a provision that allows covered entities to implement and manage their own encryption tools at their point of sale systems so long as the tools are compliant with PCI requirements.

Another update gives encryption vendors and service providers more leeway in the components that they use to deploy P2PE at customer locations. Going forward, the Council will also list approved encryption components and services that organizations can use to encrypt their data.

The updates are deigned to help organizations better protect cardholder data against compromise at the point of sale, PCI Council chief technology officer Troy Leach in a statement announcing the update. `Malware that captures and steals data at the point-of-sale continues to threaten businesses and their ability to protect consumers' payment information,` Leach said. Encrypting the data makes it valueless for attackers, he said.

The goal with P2PE is to protect cardholder data from the instant it is swiped at a POS terminal all the way through to the card processing company's network. Unlike end-to-end encryption, P2PE works by encrypting data right at the point of acceptance. The goal is to make it harder for attackers to steal card data using POS malware tools like BlackPOS, Dexter, vSkimmer, and Backoff. Such tools typically work by capturing card data from the retail terminal, before it can be encrypted.

Version 2.0 of the PCI Council's P2PE requirements should simply the steps that large merchants need to work through to encrypt cardholder data at the POS terminals, says Jim Huguelet, principal at The Huguelet Group LLC.

`Many merchants have come to realize that the EMV standard does not involve encrypting cardholder data, leaving that data as much at risk to theft as it is today,` Huguelet said.

EMV cards, or cards that are based on the Europay MasterCard Visa standard, store cardholder data in a tiny microchip embedded in the card and not on magnetic stripes like most cards in the U.S. currently do. The major credit card associations require all organizations that accept credit card transactions to implement point of sale terminals that are capable of accepting EMV card transaction. The deadline for that migration is this October of this year, but many believe that a vast majority of companies won't be ready in time for the deadline.

With various reports now estimating that only 60 percent of US credit and debit cards will be reissued with EMV chips and less than 10 percent of merchants will be able to accept them by the October 2015 deadline, organizations are coming to terms with the fact that widespread EMV adoption will easily go into 2017 and perhaps longer, Huguelet says.

`With the many delays the US is encountering in deploying EMV, merchants are looking to make their payment processing environments more secure as quickly as they can and deploying encryption is the clear way to do so,` he says.

Gartner analyst Avivah Litan says the Council's move to update its encryption requirements appears designed mostly at very large organizations.

`My initial reaction is that this is intended to benefit large merchants who want to implement their own P2PE systems,` Litan says. `I'm guessing this update is a result of some special lobbying by a handful of large big box retailers who have their own in-house capabilities.`

Read original article

Researchers expose Dino

Security researchers at ESET in Bratislava, Slovakia have published an analysis of another apparently state-sponsored cyber-espionage tool used to target computers in Iran—and potentially elsewhere. The malware, also recently mentioned by Kaspersky researchers, was named `Dino` by its developers and has been described as a `full featured espionage platform.` And this advanced persistent threat malware, according to researchers, might as well come with a `fabriqué en France` stamp on it.

Based on analysis of Dino`s code from a sample that infected systems in Iran in 2013, `We believe this malicious software has been developed by the Animal Farm espionage group, who also created the infamous Casper, Bunny and Babar malware,` ESET`s Joan Calvet wrote in a blog post today. The Casper malware was part of a large-scale attack on Syrian computers last fall. `Dino contains interesting technical features, and also a few hints that the developers are French speaking,` Calvet noted.

Other members of the `Animal Farm` malware family have been attributed to French intelligence agencies by researchers—including a 2011 analysis by Canada`s Communications Security Establishment revealed by documents leaked by former National Security Agency contractor Edward Snowden. Dino shares attributes with the other members of the `Animal Farm` malware family and improves on many of the techniques of `Babar,` the previous generation intelligence-gathering software implant.

Napoleonic code

Dino`s role is to exfiltrate data—package it and ship it back through a command and control network infrastructure to the malware`s masters. Calvet described Dino as `an elaborate backdoor built in modular fashion.` It uses its own task-scheduling code similar to cron in Unix and a custom, encrypted in-memory file system called `ramFS` by its developers—a characteristic shared with other `Animal Farm` malware. The ramFS file system acts as a `protected container` for Dino`s executable files, allowing the malware to self-destruct and leave few traces in disk storage of the system that was infected.

To keep Dino persistent between shutdowns and restarts of a targeted system, Dino uses on-disk encrypted file storing modules and data stores in a serialized format. When the malware restarts after a system reboot or remote reset, a module in the malware called PSM decrypts the storage file and loads its contents back into the ramFS memory. `Funnily enough,` Calvet wrote, `the key serving to encrypt the file on disk is `PsmIsANiceM0du1eWith0SugarInside.``

The ESET researchers cataloged the commands that could be remotely executed through Dino and found that most of them were focused on searching through files and performing covert file transfers. The `search` command can perform very specific gathering tasks, Calvet noted. `For example, it can provide all files with a `.doc` extension, the size of which is bigger than 10 kilobytes, and that were modified in the last 3 days,` Calvet wrote. The search command packs all the files it finds into an archive, which is in turn scheduled for upload to the command and control servers.

The output returned from Dino`s `sysinfo` command bears a striking resemblance to the data format used by `beacon` malware discovered by the Canadian Communications Security Establishment`s analysts—data that led the CSE to discover the Babar malware. It sends back information on the infected system and its owner, as well as the version number for the malware itself. Additional signs of Dino`s connection to a French organization include resources in the compiled binary that bear the hexadecimal language code value of 1036—the code for `French (France).`

Also, Dino`s code is statically linked to the GNU Multiple Precision Arithmetic Library (GnuMP); the GnuMP code in Dino included path references to C libraries from the developer`s computer, which include a directory called `arithmetique` (French for arithmetic). And while the error logging code of Dino is in English, it does not appear to be the English of a native speaker.

ESET researchers would not definitively say that they believe French intelligence is behind Dino, but they did strongly connect Dino to the other malware already attributed to the Animal Farm group.

Target du jour

Dino was detected on multiple systems in Iran in 2013, according to Calvet. That is consistent with the focus of its predecessor, Babar, which was on Iran`s science and technology community, according to CSE analysts. But the Animal Farm group has also used malware to spy on a broad range of targets in Europe, Africa, and North America—including a possible infiltration of a French-language media company in Canada.

According to Kaspersky, Dino is distributed by a malware package called Tafacalou. The vast majority of Tafacalou victims have been in Syria, Iran, and Malaysia—with the US and China trailing far behind.

Other members of the Animal Farm malware family have been detected as far back as 2010, and researchers at Kaspersky believe the group behind Animal Farm has been active since at least 2009, `and there are signs that earlier malware was developed as far back as 2007,` a member of Kaspersky`s Global Research and Threat Analysis Team wrote in a March blog post.

Humanitarian organizations, activists, and businesses have been targeted, as well as government organizations and military contractors—indicating that economic espionage and national security issues are on the menu. For example, Babar was used to target the European Financial Association and targets in Greece, Norway, and Spain.

While Dino and its cohorts don`t offer direct evidence of cyber-espionage by a specific French intelligence organization, they do suggest that France`s government is attempting to play on the same stage as the NSA and its `Five Eyes` counterparts in the United Kingdom, Australia, Canada, and New Zealand.

Read original article

US spied on Germany

On Wednesday, WikiLeaks published two new top-secret National Security Agency briefs that detail American and British espionage conducted against German leaders as they were discussing responses to the Greek economic crisis in 2011.

The organization also published a redacted list of 69 German government telephone numbers that were targeted for snooping. That list includes Oskar Lafontaine, who served as German finance minister from 1998 to 1999, when the German government was still based in Bonn—suggesting that this kind of spying has been going on for over 15 years at least.

As with the recent documents concerning NSA spying against France, WikiLeaks did not explain how it obtained the documents. However, it did share them with Greek, French, and German-language media, which all published them simultaneously on Wednesday evening, Europe time.

The timing of the documents' release is curious: it comes just as Greek Prime Minister Alexis Tsipras changed his position and said that his country would in fact accept a deal by Greece's creditors over the weekend. Greece has already defaulted on loans provided by the International Monetary Fund, and the world has been watching to see whether it will go bankrupt or be kicked out of the eurozone, which could have deleterious worldwide effects.

With friends like this…

One of the documents specifically provides information between Chancellor Angela Merkel and an unnamed assistant. Assuming that the document is authentic, it would provide incontrovertible proof that the United States targeted her specifically.

Eurozone Crisis: Merkel Uncertain on Solution to Greek Problems, Would Press U.S. and UK (TS//SI-G//OC/REL TO USA, FVEY)

(TS//SI-G//OC/REL TO USA, FVEY) Discussing the Greek financial crisis with her personal assistant on 11 October, German Chancellor Angela Merkel professed to be at a loss as to which option--another haircut or a transfer union--would be best for addressing the situation. (The term `haircut` refers to the losses that private investors would incur on the current net value of their Greek bond holdings.) Merkel`s fear was that Athens would be unable to overcome its problems even with an additional haircut, since it would not be able to handle the remaining debt. Furthermore, she doubted that sending financial experts to Greece would be of much help in bringing the financial system there under control. Within the German cabinet, Finance Minister Wolfgang Schnaeuble sic alone continued to strongly back another haircut, despite Merkel`s efforts to rein him in, while France and European Commission President Jose Manuel Barroso were seen to be in favor of a gentler approach. European Central Bank President Jean-Claude Trichet was solidly opposed, with IMF Managing Director Christine Lagarde described as undecided on the issue. Finally, Merkel believed that action must be taken to enact a Financial Transaction Tax (FTT); doing so next year, she assessed, would be a major step toward achieving some balance in relief for banks. In that regard, the Germans thought that pressure could be brought to bear on the U.S. and British governments to help bring about an FTT.

Unconventional
German leadership
G/OO/526362-11, 181753Z

The second intelligence brief describes a German-supported plan involving the creation of a `special IMF fund into which the BRICS (Brazil, Russia, India, China, and South Africa) nations would pool funds for the purpose of bolstering eurozone bailout activities.` That fund was ultimately never created.

Last month, German Chief Prosecutor Harald Range said that there was insufficient evidence of criminal activity that would hold up in a German court and that the government's inquiry would end. But, he noted, `Should there be promising new investigative leads, the investigation will resume again.`

The German government accused the United States after the German magazine Der Spiegel first broke the story in October 2013.

Neither Range's office nor the National Security Council immediately responded to Ars' request for comment.

`We do not comment on information from allegedly leaked documents,` Katherine Pfaff, a State Department spokeswoman, told Ars.

Similarly, Ned Price, a spokesman with the National Security Council, told Ars last week that his agency would not `comment on specific intelligence allegations.`

`As a general matter, we do not conduct any foreign intelligence surveillance activities unless there is a specific and validated national security purpose,` he wrote by e-mail. `This applies to ordinary citizens and world leaders alike.`

Read original article

Wednesday, 1 July 2015

Click Fraud Campaigns

Security researchers are warning IT managers not to ignore innocuous looking click-fraud malware as it could be hiding something far more disruptive, like the notorious CryptoWall ransomware.

Damballa argued in its Q2 State of Infections report that any security technologies using just `one technique and/or prior knowledge of the threat` will not cut it in today's threat landscape.

By way of example, the vendor discovered new click-fraud malware it dubbed 'RuthlessTreeMafia', which is dropped by the Asprox botnet or exploit kits.

It explained:

`The RuthlessTreeMafia threat operators use a fast-flux infrastructure to deliver the Rerdom click-fraud malware to victims. This Trojan utilizes a combination of downloader, information stealer, rootkit and search redirector with pop-up adds to obtain additional revenue for the criminal command and control (C&C) organization.

Apsrox malware is frequently delivered via phishing emails. Once the system is infected, the Asprox malware will retrieve an update from the Asprox C&C that will also include a Zemot dropper which has the function of downloading two more pieces of malware. The first malware binary is Rovnix, which is a rootkit. The second malware binary is Rerdom, which is the click-fraud installer. It is possible for the Zemot downloader to also be installed via exploit kits. Once this threat is installed, the victim`s system is compromised.`

However, on running the malware in its labs, Damballa found that it did more than just click-fraud.

During the first 40 minutes, the vendor detected over 900 connections using multiple domain names and threat actor groups, but all resolving to a search engine's IP address as part of a click-fraud campaign.

However, as the campaign continued, Damballa then detected six instances of the same file being downloaded from a direct connection – identified as CryptoWall.

It encrypted all system files on the infected machine within seconds. The click-fraud continued for another hour even though the device was made inaccessible to its user.

Damballa claimed that understanding the entire malware infection lifecycle is vital to effectively combating advanced threats.

`As demonstrated by the RuthlessTreeMafia example, hidden threats can arrive in sheep's clothing,` it concluded. `While click-fraud related malware is usually seen as a low priority infection, it can quickly morph into something dangerous like CryptoWall. Once that happens, the infection kills the host and can move to other parts of the network.`

CryptoWall itself is one of the most prolific ransomware families around. Just last week the FBI warned that it had managed to generate over $18m for the group behind it since April 2014.

Read original article

Clever CryptoWall Spreading

Top ransomware doesn`t waste time jumping on the latest Flash zero-day, and hops rides on click fraud campaigns, too.

The CryptoWall ransomware operators continue to innovate -- not only improving the payload itself, but also expandings its methods of proliferation.

For example, within two hours, a device hijacked for relatively innocent click fraud attacks can become a conduit for far more serious kit -- including CryptoWall.

As researchers at Damballa explain in their latest State of Infections Report, operators of the RuthlessTreeMafia click fraud malware campaign infect client machines via the Asprox botnet. As a second revenue stream, they sell other attackers access to those bots.

The threat actors running the Rerdom and Rovnix Trojans had first dibs -- but through a chain of events that took only two hours, some victims were eventually infected with CryptoWall as well.

`The intricacies of advanced infections mean that a seemingly low risk threat – in this case click fraud – can serve as the entry point for far more serious threats,` said Damballa CTO Stephen Newman.

The ransomware also found its way into the Magnitude exploit kit. Over the weekend, French researcher Kafeine discovered that Magnitude had added exploits for the critical Flash zero-day vulnerability that Adobe released an emergency out-of-band patch for last week. (The vulnerability, CVE-2015-3113, was linked to Chinese advanced persisted threat group APT3, according to FireEye.) Kafeine also saw two samples that were installing Cryptowall against a Windows 7 machine running Internet Explorer 11.

These are just the latest in a variety of new infection vectors CryptoWall operators have begun using. CryptoWall added the ability to execute 64-bit code directly from a 32-bit dropper. It was found proliferating through spam with malicious .chm attachments. And it was dropping via the elusive HanJuan exploit kit as part of a malvertising campaign.

Last week, the FBI stated that between ransoms and recovery costs, CryptoWall had cost Americans over $18 million between April 2014 and June 2015. The Bureau called CryptoWall `the most current and significant ransomware threat targeting U.S. individuals and businesses.`

Read original article

Gas Stations In the Bullseye

White hats at Black Hat USA will release free honeypot tool for monitoring attacks against gas tank monitoring systems.

Researchers who earlier this year spotted potential hacktivist activity against popular gas tank monitoring systems at US gas stations say they`ve been studying some real-world attacks on these systems as well as on their own honeypot set up to study and gather intelligence on the attackers and their intentions.

Kyle Wilhoit and Stephen Hilt, both with Trend Micro, at the Black Hat USA conference in early August plan to release a free tool called Gaspot, which allows researchers as well as gas tank operators to set up their own virtual monitoring systems to track attack attempts and threats.

Although the pair of researchers won`t divulge all of their newest findings on attacks and attackers until their August presentation at Black Hat, they say they have confirmed attacks on the Guardian AST gas tank monitoring systems in several locations across the US, and found a number of these systems wide open to attack via the public Internet, vulnerable to manipulation and sabotage. In February, they reported finding one such Internet-facing tank monitoring system at a gas station in Holden, Maine, renamed `We_Are_Legion` from `Diesel,` suggesting either the handiwork of Anonymous or another attacker using the group`s slogan.

Wilhoit and Hilt`s research follows that of Rapid7 chief research officer HD Moore, who in January revealed his findings of some 5,800 Vedeer-Root automated tank gauges, which monitor for fuel leaks and other problems with the tanks as well as fuel levels, found sitting wide open on the Internet without password protection, leaving more than 5,000 gas stations in the US vulnerable to attackers who could remotely alter the alarm thresholds to simulate a leak, disrupt the fuel tank operations, and worst-case, wreak havoc by shutting down the gas stations altogether, researchers say.

Moore had gotten a heads up from Jack Chadowitz, president and CEO of Kachoolie and BostonBase Inc., who first detected the problem. Rapid7`s Moore then conducted an Internet scan of devices with TCP port 10001 open to the public Internet, and reported his findings publicly.

The Trend Micro researchers found similar issues with the Guardian AST, which is also sold by Vedeer-Root. The Guardian AST also provides inventory tracking of above-grand gas storage tanks, and according to Wilhoit, comes with more communications protocols -- including an RS-232 port -- than the Vedeer-Root fuel tank devices studied by Moore. The Guardian devices also are widely used on generators, Wilhoit notes.

`After we saw the possible Anonymous attack on the systems, we thought there was probably more here,` Wilhoit says.

Wilhoit says he and Hilt saw a number of systems at US gas stations being attacked, as well as some overseas. `The large majority were distributed throughout the US,` he says.

While he wouldn`t yet reveal the types of attacks, he says the types of attacks were across the board. `The obvious concerns were about nation-state attackers,` he says.

The Gaspot tool will allow researchers and organizations to basically deploy a script that gives them insight into whether their system is being targeted by attackers. `It will allow them to assess if attackers are interested in their environment,` Wilhoit says.

The vulnerable systems identified previously by Moore were only found in independent, small gas station dealer sites. Large chains affiliated with big-name petroleum companies generally aren`t vulnerable to the public-facing Net attacks because they`re secured via corporate networks, according to Kachoolie and BostonBase`s Chadowitz, whose company provides monitoring services for gas stations and other businesses. `There are only so many` Guardian AST systems out there, he says.

The attacks Chadowitz has seen mostly have been things like changing the product`s name. `That`s very simple to do. I haven`t seen any intelligent hack` yet, he says. `Their understanding is very primitive now` of these monitoring systems, he says of the attacks thus far.

Moore told Dark Reading earlier this year that the Vedeer-Root gas tank monitoring vulnerability issue stemmed from tank gauge vendors not instituting security by default -- namely a VPN gateway-based connection to the devices and authentication. \

Read original article