Software company accused of illegally profiling millions of mobile phone users

0
[ad_1]

A digital rights and privacy organization has filed a complaint against software company TeleSign for gathering and selling information on millions of mobile phone users.

A digital rights and privacy organization has filed a complaint against software company TeleSign for gathering and selling information on millions of mobile phone users.

The organization that filed the complaint is nyob. nyob is an Austrian based digital right organization that focusses on commercial privacy issues on a European level. After the General Data Protection Regulation (GDPR) came into force on May 25, 2018, commercial privacy violations can now be enforced on a European level, which allows for much more effective procedures and strategic litigation.

The complaint targets BICS, TeleSign, and Proximus. BICS is a Belgium-based communications service that enables phone calls, roaming, and data flows between different communications networks and services all over the world (500 mobile operators in more than 200 countries). Instead of having direct agreements with each other, hundreds of mobile phone providers can connect their networks through the interconnection service of BICS.

TeleSign is a US-based company that provides Application Programming Interfaces (APIs) that deliver user verification, digital identity, and omnichannel communications, to help other brands with secure onboarding, maintain account integrity, prevent fraud, and streamline omnichannel engagement. Among its customers are Ubisoft, ByteDance (TikTok), Skype, and Salesforce. 

Proximus is the Belgium based parent company of both BICS and TeleSign.

The problem

When processing phone customer data, BICS gets detailed information like the regularity of completed calls, call duration, long-term inactivity, range activity, and successful incoming traffic. And it receives these data for about half of the worldwide mobile phone users.

In 2022, Belgian newspaper Le Soir published an article about BICS sharing these data with TeleSign. Based on these data, TeleSign gave every mobile phone user a “trust score” between 0 and 300 points. This trust score helps their customers decide whether to allow users to sign up to a platform or, for example, require an SMS verification first.

According to Telesign’s website, it verifies over five billion unique phone numbers a month, representing half of the world’s mobile users, and provides critical insight into the remaining billions.

The data BICS shares includes information such as the type of technology used to make calls or texts, the frequency of activity, and the duration of calls.

nyob co-founder Max Schrems said:

“Your phone provider likely forwards data to BICS who then forwards it to TeleSign. TeleSign generates a ‘trust score’ about you and sells phone data to third parties like Microsoft, Salesforce or TikTok  – without anyone being informed or giving consent.”

While GDPR allows for sharing data for the purposes of taking appropriate, proportionate, preventive and curative measure and in order to detect fraud and malicious use of networks and services, nyob feels that this is not the case here.

From Max Schrems:

“The responses received by BICS and TeleSign suggest that this business model is not complying with EU privacy laws. We have therefore filed a complaint with the Belgian Data Protection Authority, who is competent for Proximus,  BICS and TeleSign.”

The lawsuit could end up to be very costly. The Belgian Data Protection Authority (DPA) can issue a fine up to 4% of the global turnover of Proximus, which is roughly $250 million.

EU citizens that want to know whether TeleSign has data on them, and has assigned them a score like the complainants, nyob has developed a template that you can use to send an access request to TeleSign. Companies holding data about you have the obligation under GDPR to tell you not just whether they process information about you, but also where they received the data, for which purpose they use it, and with whom they shared it.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Main Pixel Fold display & camera performance praised by DXOMARK

0
[ad_1]

DXOMARK has finished testing Google’s very first foldable phone, the Pixel Fold. As per usual, the company tested the display, camera, and audio performance of the device, and the Pixel Fold did really well.

The Pixel Fold display, camera, and audio performance got tested by DXOMARK

Let’s talk about the display first, shall we. In this category, the Pixel Fold shone the brightest. It actually managed to earn 151 points, which means it now takes up a joint top position in DXOMARK’s display rankings.

DXOMARK says that the display has “good, adapted brightness and contrast for HDR10 video content”. It also praised “good color management”, as colors seem to remain faithful for both still and dynamic content. Do note that the company is talking about the main display.

The company also said that the display offered “smooth interactions” in most use cases. You may notice stutters when browsing the web, with a slight jello effect. Things are not nearly as bad as on some other foldables, though.

The phone has the brightest display of any foldable DXOMARK tested

DXOMARK says that the Pixel Fold has the brightest display out of the foldables the company tested. The company tested max brightness of around 1,430 nits, making it rather easy to use in most environments. The crease is easily visible outdoors, though. Direct sunlight can also make things a bit difficult to read.

There was no mention of the cover display, though.

The phone’s camera performance was also good

The Pixel Fold cameras scored 133 points in DXOMARK’s test, which puts it in the 28th position. That doesn’t sound great, but do note that there are a lot of great camera smartphones out there that DXOMARK tested.

In the main category, the photo category, the phone did really well. The bokeh and zoom portions didn’t really shine all that much, but overall, the Pixel Fold has good camera performance.

DXOMARK notes that the phone’s cameras shine in the autofocus, exposure, and dynamic range departments, as expected. The company did not appreciate the noise that crept in low light environments, or the phone’s bokeh performance.

The company also noted that the phone did show some “instabilities in exposure and white balance” when it comes to video performance. The autofocus and video stabilization worked great.

The audio performance is also nothing to scoff at

DXOMARK also tested the audio aspect of the device. With a score of 133, the Pixel Fold ended up being placed in the 38th position. It is claimed that the Pixel Fold has the best audio performance of any foldable device DXOMARK tested.

The Pixel Fold offers a “pleasant sound signature” with its speakers. It seemingly performed best when music playback is concerned. It also did well with movie content and games, though.

DXOMARK says that the phone offers an “overall nice tonal balance”, which ends up resulting in good clarity. That goes for most musical content that DXOMARK tried. Dynamic performance is also good, notes the company. The speakers are also loud enough, but strong compression and significant distortion can be noticed at the highest volumes.

The best recording audio performance can be reached when using a selfie camera in the device’s folded state. The sound has an “accurate envelope, a sharp attack, and excellent signal-to-noise ratio”.

If you’d like to check out the full report by DXOMARK, click here.


[ad_2]
Source link

Things to consider before buying a smartphone in 2023

0
[ad_1]

The 21st century has witnessed a tremendous evolution in mobile phone development. Each year, big brands like Samsung, Apple, Xiaomi, and Oppo release flagship phones. The competition is fierce and each brand tries to outperform the other with every new release.

Smartphones have become so interactive that they play a significant role in everyday life. Therefore, in deciding which one to buy, many individual factors must be considered. Many stick to a specific brand for their excellent camera, while others consider features like performance, battery life, processor, durability, and, more importantly, cost.

In this current dispensation where mobile phones have become more than just call devices, we take you on a journey of the fantastic features that define the best brands.

Connectivity

Regarding connectivity, many things come to mind. 5G connectivity, Bluetooth, and Wi-Fi are the major connection features in modern phones. Particularly 5G connectivity is crucial as the world has moved past the era of Edge, 3G, and 4G networks. On average, 5G connections are theoretically 20 times faster than 4G LTE. With this speed, users can connect seamlessly and share data at unprecedented rates.

Many gamers can stream their favorite esports games like Call of Duty, GTA, and Need for Speed without issues. Likewise, if you fancy live dealer games like the ones on AustraliaOnlineCasinoSites, you need a stable 5G network to stream events from live studios worldwide. Hence, if you deal with a lot of media for uploads, you need a phone with 5G connectivity.

Screen and Display

The size of a screen is not a reflection of its quality. Instead, many people make their choices based on personal preference. However, the quality of that screen is what counts, and this is undoubtedly something to consider. There used to be IPS and LCD monitors, which are standard on mid-range and low-price phones. Biggest brands like Samsung and Apple now use AMOLED, OLED, and Super AMOLED panels.

Lately, some smartphones use a 2K display with high pixel resolution for a more realistic, balanced contrast and accurate color display. Thus, if you like watching videos on YouTube or Netflix.com or playing video games, you must get a smartphone with an exemplary screen display.

Cameras

Unless you are a professional photographer, the world has evolved past people going about with big cameras and a tripod to take pictures or film short videos. Mobile phones have become sophisticated in that they come with high-megapixel sensors that are comparable with professional cameras. For example, the Samsung Galaxy S22 launched with a 108 MP primary camera, and that was only just the beginning.

The most recent S23 has a massive 200 MP primary sensor with additional dedicated cameras that take excellent shots. Likewise, the iPhone is another smartphone with one of the best cameras. Unlike Samsung and other smartphones, they do not use high sensors but rely heavily on their software for processing excellent images and videos.

Therefore, if you take many photos for business or fun, you want a smartphone with an excellent camera setup.

RAM and Processor

Get all the good screen resolution, best camera sensors, and fast connectivity, if the processor and RAM aren’t up to the task, then it’s all for nothing. One of the many things that position the iPhone as the best camera is not the high sensors they use. Until the iPhone 14 Pro had the highest 45 MP sensor, previous versions only had a 13 MP triple camera setup. Even the Google Pixel maintained a single camera and still took some of the best shots on a smartphone, and it all comes down to the processor.

As for the RAM, it is what makes the entire phone operation seamless. Your ability to multitask, take great photos, transfer files, and enjoy fast uploads and downloads using the 5G connectivity depends on it.

Internal Storage

One of the popular trends with recent smartphones is that they do not allow for additional storage space. Before now, users could use SSD cards to boost the default internal storage. But, we can all agree that was the good old days when the internal storage was relatively small. Most high-end smartphones have internal storage of up to 1 TB, which is more than enough to handle any work.

With the quality of cameras and phone screen resolutions, a typical photo takes up to 10 MB. An average one-minute 4K video takes over 1 GB of storage, and some devices now support 8K. The best part is that these devices are available in different storage sizes, so you can choose one that suits your needs.

Battery

Before now, most phones could barely last a few hours of heavy usage. However, each phone manufacturer strives to improve battery performance with every new launch. From boosting the battery size to software optimization, most flagship smartphones can last several days which is excellent.

The best part is that they also consider the charging speed of these devices. Imagine charging your device from 0% to 100 in less than 30 minutes. Therefore, as you think about getting a phone with high screen resolution, good connectivity, an excellent camera, and all the other stuff, remember that you need the device running to enjoy these features.

Conclusion

Before buying a smartphone, first, you must have a budget. These high-end phones with massive specs do not come cheap. Based on your preference, you can make a list in order of your priority. Moreover, you can get more tips from androidheadlines.com for the latest trend in mobile technology.


[ad_2]
Source link

Cisco AsyncOS Flaw Let Remote Hackers Launch XSS Attack

0
[ad_1]

Cisco AsyncOS Software, used by Cisco Secure Email and Web Manager, Cisco Secure Email Gateway (previously Cisco Email Security Appliance; ESA), and Cisco Secure Web Appliance (WSA), has multiple flaws in its web-based management interface.

The vulnerabilities could allow a remote attacker to launch cross-site scripting (XSS) attack against a user of the interface.

What is XSS Attack?

Cross-site scripting (XSS) is an attack that lets hackers inject malicious javascript into the application or the website code.

When user input is not properly sanitized before being used in the generated output, a web page or web app becomes vulnerable to cross-site scripting attacks.

Cisco AsyncOS Software Flaw

Cisco said that “the vulnerabilities are independent of one another, exploiting one of the vulnerabilities is unnecessary before attempting to exploit another. “

Also, “a software release that is vulnerable to one of the vulnerabilities may not be vulnerable to the others,” Cisco added.

Products Affected

CVE-2023-20119: Cisco Secure Email and Web Manager – Reflected XSS

CVE-2023-20120: Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20028: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20119: Cisco Secure Email and Web Manager

An unauthenticated, remote attacker could execute an XSS attack against a user of the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager due to a vulnerability.

Insufficient user input validation is the cause of this vulnerability. A user of a vulnerable interface could be tricked into clicking a forged link by an attacker.

 A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVE-2023-20120: Cisco Secure Email, Web Manager & Web Appliance

This vulnerability could allow an authenticated remote attacker to conduct an XSS attack against a user of the interface.

It is also an insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link.

If the exploit is effective, the attacker may be able to access private browser-based data or run arbitrary script code in the context of the exploited interface.

CVE-2023-20028: Cisco Secure Email, Web Manager, & Web Appliance

This vulnerability could also be able to allow an authenticated remote attacker to conduct an XSS attack against a user of the interface due to insufficient user input validation.

A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Updates & Workarounds

Cisco said there are no workarounds available to address these vulnerabilities, and users are recommended to consider software updates. According to PSIRT, there is no active exploitation of the vulnerability recorded.

Patches Released

Cisco released patches to fix the vulnerability;

Secure Email and Web Manager

Secure Email Gateway

Secure Web Appliance

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link

Company finds lost SSD—and confidential data—for sale on eBay

0
[ad_1]

Major software company SAP is putting the pieces of a story involving missing SSD disks back together.

Major software company SAP is putting the pieces of a story involving missing SSD disks back together.

Four SSD disks are alleged to have gone on an adventure last November, making their way out of a Walldorf, Germany, datacenter with one of them ending up on eBay. An investigation revealed that despite the disks being located in a building referred to as a “secure location”, it was anything but for the disks in question.

According to The Register’s sources, the disks were transported to an “unsecured building” somewhere in the HQ complex. Eventually, the disks were taken without permission. Some time later, an SAP employee saw one of the missing disks on eBay and purchased it, identifying it as one of their own.

It seems highly unlikely that the individual in question bought a random SSD disk on eBay and it randomly turned out to be one of the missing disks. This was presumably part of a “hope it turns up somewhere” investigation and they managed to hit the jackpot.

The Register says that the disk contained “personal records” of 100 or so SAP employees though there is no word as to what specifically was on there. At the time of writing, the three other disks remain unaccounted for. We don’t know what’s on them but considering the content of the recovered disk, but SAP seems to think no customer data has been lost:

SAP takes data security very seriously. Please understand that while we don’t comment on internal investigations, we can confirm we currently have no evidence suggesting that confidential customer data or PII has been taken from the company via these disks or otherwise.

The Register claims that this is the fifth incident along these lines affecting European datacenters in a two year time frame. That’s probably not surprising, lots of bits and pieces go missing from workplaces all the time. And it’s not necessarily done deliberately or as an act of theft. Sometimes people wander into accidents, and that’s how you end up with all of those “USB stick left on the bus” stories. Sadly, the end result is often the same: Data exposure and confidential information going public.

How to keep your removable devices in the right place

  • Inventory management. Keeping a close eye on what you have can be tricky, but it’s essential to make sure assets don’t go wandering off. As Chron puts it, identification, number, location, and description will go a long way tied to a few spreadsheets or even dedicated software. Regular audits will ensure nothing is missing. Employees should have a set number of days to return items when leaving the business. Laptops should have remote location tracking which can’t be turned off.
  • Encrypt your drives. Encrypting your drive essentially scrambles all of the data in a way which means that anyone picking it up will have a hard time accessing the contents. Without a password or some other way to verify that accessing the drive is allowed, no data will be forthcoming. Many off-the-shelf drives come with encryption built in and ready to set up. Others will automatically wipe all data if the password is entered incorrectly too many times. You can even encrypt USB flash drives, and if your main drives don’t come with encryption, plenty of third-party options exist to take up the security reigns.
  • Hard to move hardware. It’s unlikely someone will walk out the door with a PC workstation, but you should think about everything plugged into it. Cables and peripherals can all be secured or even locked into the device. Some locking kits will allow you to secure multiple peripherals with one carbon steel cable. Others will block USB ports and prevent access without making lots of obvious damage to the device.
  • Secure that space. Sensitive data areas may require CCTV, and scannable employee cards allowed for use in specific locations. Add printing funds to cards, deploy locks on your printer tray, and restrict access to paper used for billing and expense claims. You may not have considered your printer as a rogue element of your office, but in the right hands it could be.
  • On the road observations. As TechRadar notes, items can be stolen from employees when travelling. Don’t leave work items in your car, and consider using bags for laptops which don’t look like expensive laptop bag carriers. If you’re in a cafe, don’t leave your devices unattended. There are many locks designed for laptops which can help secure a device when in public.
  • When all else fails, browse the for sale sites. On the off chance that a piece of equipment has gone missing, it’s time to check out eBay and similar portals. You probably won’t find it listed as “[Company Name] Missing hard drive”, but you may get good results if you search for specific makes and models of hardware.

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Galaxy A33, A03, M33 & more devices bag Samsung’s June update

0
[ad_1]

Samsung is rolling out the June security update to a bunch of Galaxy devices. The Galaxy A33 5G, Galaxy A03, Galaxy M33 5G, and Galaxy M62 are all getting the latest security patch. This month’s SMR (Security Maintenance Release) patches more than 60 vulnerabilities.

The latest update for the Galaxy A33 5G is widely available in Europe with the firmware build number A336BXXU6CWF2. Users in South Korea are getting the same update with the build number A336NKSU4CWE1, while that for users in Hong Kong is A3360ZHU6CWF2. Interestingly, Samsung’s official changelog also varies in these regions. The Korean changelog mentions updates for the Emergency SOS feature. The company is removing the ability to turn off this feature, a change it also pushed to the Galaxy S23 series and many other devices.

However, the changelog for Europe doesn’t mention anything as such. It only says that the device is getting the latest security fixes. But the presence of “U” in the build number (the sixth character from the last) suggests there’s something more. It’s the same for Hong Kong as well. Samsung’s changelogs often don’t tell the full story, anyways. The June update for the Galaxy A33 5G should soon reach other markets, including Latin America, Africa, and the rest of Asia. Samsung didn’t launch this mid-range phone in the US.

It’s a similar story for the Galaxy M33 5G as well. This phone is getting the same changelog in South Korea, where it’s called the Galaxy Jump 2. The June update comes with the build number M336KKSU5CWE1 in Samsung’s homeland. The same update in Latin America (currently only available in Panama) brings firmware version M336BXXU5CWF2. The Galaxy A03, meanwhile, is widely picking up the June SMR in Latin America. The new firmware build number for this budget handset is A035MUBS3CWF2. Unlike the Galaxy A33 5G, it doesn’t seem to be getting anything else.

The Galaxy M62 is also getting Samsung’s June update

The Galaxy M62 is another Samsung phone that recently started receiving the June update. Rolling out with the firmware build number M625FXXU4CWF1, the device is getting system stability improvements along with the latest security fixes. This mid-range phone wasn’t sold globally, so the company should soon cover all eligible units with the June SMR. As usual, you can check for OTA (over the air) updates manually from the Settings app. Go to the Software update menu and tap on Download and install.


[ad_2]
Source link

Nanoleaf’s 4D camera transforms games into an immersive lightshow

0
[ad_1]

Nanoleaf is launching a few new products today, one of which is called the Nanoleaf 4D, a screen mirroring camera and smart lighting strip combo that turns your gaming, TV, and movies into an immersive light show.

Alongside the Nanoleaf 4D, the company is also launching the Ultra Black Shapes Hexagons light panels, and a new gaming integration software in collaboration with Overwolf. While you don’t need all three for a complete setup, they do all work together. And the more of Nanoleaf’s lighting products you have, the more immersive things will be. If that’s what you’re going for. Nanoleaf says 4D also works with and supports all of its older panels, except for Elements as those don’t do RGB.

The Nanoleaf 4D screen mirroring camera and the Ultra Black Hexagons are both available for pre-order starting today. You can pick up the 4D at either Best Buy or direct from Nanoleaf. The kit comes in 65-inch and 85-inch lengths and retails for $99.99 and $119.99 respectively. The light strip that comes in the kit can also be cut to fit your TV or monitor. The Ultra Black Hexagons meanwhile will retail for $219.99 for a 9-pack Smarter Kit. And if you need more the 3-pack Expansion Pack retails for $69.99.

Both are set to begin shipping next month with the 4D arriving mid-July and the Ultra Black Hexagons in late-July.

The Nanoleaf 4D camera brings screen mirroring to the TV

The 4D camera will work with any TV or monitor it’s set up with. For gamers who play on Xbox Series X|S or PS5, or someone who just wants an immersive viewing experience for movies, Nanoleaf 4D provides new smart lighting experiences that simply weren’t available before with Nanoleaf products unless you were on PC.

For PC users, the 4D camera’s capabilities have been available via the PC software for a while. As there’s a screen mirroring feature in the software that lets you extend the colors of your PC games and other entertainment to the lights.

Nanoleaf 4D brings that to the TV so you can use it for all of your entertainment. Not just PC. The 4D camera also comes with a magnetic sensor cover for privacy when you don’t want to mirror your screen.

Level up your best gaming moments with Overwolf

The best way to describe this new software feature is that it works similarly to Razer Chroma profiles. With Overwolf, important moments or events in your games like kills, assists, and more are synced to your devices. This now includes Nanoleaf lighting products.

Overwolf is already available for the PC app today, and existing Nanoleaf users can check it out after a quick app update.


[ad_2]
Source link

Meta’s latest project is so dangerous that even it doesn’t want to release it

0
[ad_1]
Welcome to 2023, also known as “The Age of AI”. Well, in all honesty, we’ve been in an age of AI for awhile now, as some of the best phones rock AI-fueled features. What we’re currently defining as “growth” is likely to be just the start of a super-boom, but still: the hype is real.

As it turns out, everyone has an AI project nowadays. ChatGPT showed its superior capabilities to immensely entertain the minds of several generations and it can even boost your productivity if you use it right! And that’s how the fad became fact. 

So it basically took no time at all for Microsoft and Google to rush out AI platforms of their own. Shocking, Samsung won’t be doing that — outside of its internal tool, but that drama was slightly different. But someone is missing.

Where’s Meta in all of this? Well, you asked just in time. The company unveiled its latest AI-fueled project and… refused to release it to the public? Like, not make a profit? 

Huh. Wow.

Okay, before we all continue with this series of shocked gasps, let’s elaborate on what the AI even does. Meta’s take differs from the text-based platforms we’ve become witness to thus far, as “Voicebox” is basically capable of generating speech.

Alright, cool, it does text-to-speech. Where’s the scary part? Well, according to Meta’s own research, the platform vastly outperforms other tools from the category. In fact, it is capable of going beyond what it has been trained to accomplish.

Whew, sounds like Meta saved us from an early AI-pocalypse.

But since it’s really fun to see how that might’ve turned out, let’s check on what Voicebox can do anyway. Currently, it is capable of reproducing accurate text-to-speech replication of a person’s voice in six European languages.

So, this may sound pretty harmless. But then the accuracy, precision and detail with which the AI platform executes the task become apparent. And it starts getting Goosebumps-y.

But still, the real surprise here doesn’t come from the fact that Voicebox is outperforming its programming. This was bound to happen sooner or later and Meta is part of Big Tech, so no shocks there. But the company’s choice to effectively not earn money from this platform is absolutely inspiring.

And while this won’t stop existing voice machines from almost-perfectly creating voice clips that sound eerily similar to prolific public figures and political actors, it still raises our faith in humanity just a bit. Before the eventual AI-pocalypse sequel comes, at least.


[ad_2]
Source link

Understanding ransomware reinfection: An MDR case study

0
[ad_1]

Ransomware is like that stubborn cold that you thought you kicked, but creeps back up determined to run amok again.

Ransomware is like that stubborn cold that you thought you kicked, but creeps back up determined to run amok again. The question is what medicine is available to kick this nasty infection for good.

In this post, we’ll break down the idea of ransomware reinfection and share a real-life episode where Malwarebytes Managed Detection and Response (MDR) mitigated a resilient ransomware reinfection from the Royal ransomware gang.

What is ransomware reinfection?

Imagine this scenario: You’ve recently battled a vicious ransomware attack, finally restoring your systems to their normal functionality. You breathe a sigh of relief, secure in the knowledge that your data is safe and operations are running smoothly.

Alas, it’s not the end of the story.

The ransomware attack you just countered was actually just the final act of a long-drawn series of malicious activities. In other words, many ransomware attacks aren’t the start of the problem; they’re often the result of an unresolved network compromise.

The true culprit is how the threat actor is gaining access to begin with. Once inside, they steal login credentials, deploy malware, or establish a backdoor—a secret gateway into the network that can be exploited later. This is like them leaving a hidden door unlocked for future visits.

Even after successfully mitigating the immediate ransomware attack, these hidden doors may remain unnoticed, enabling the attackers to infiltrate your network stealthily once more. This is the essence of ransomware reinfection.

Having clarified the terminology, let’s delve into a real-world instance of a ransomware reinfection in action.

Initial Ransomware Attack – November 23, 2022

Prior to their engagement with Malwarebytes, our customer experienced a ransomware attack on their AWS environment. They chose not to pay the ransom.

The subsequent countermeasure involved a complete system rebuild from backup to recover their operations.

Onboarding with Malwarebytes MDR and Detection of Reinfection – December 9, 2022

In response to the initial compromise, the customer onboarded with our Managed Detection and Response (MDR) service and Endpoint Detection and Response (EDR) product. Immediately after installing the EDR on the endpoint, detections for additional ransomware were identified.

Our MDR analyst spotted file detections linked to the previous ransomware attack, attempted outbound communications to a known malicious site (a Cobalt Strike C2 server), and remote inbound RDP connection attempts. The MDR analyst promptly contacted the customer, recommending to block the C2 server and the source of the RDP connections, which the customer promptly implemented.

New Threat Emerges – December 11, 2022

Only two days later, a new set of remote host RDP connection attempts were detected. Again, the MDR team advised the customer to block the connection source to prevent further infiltration.

Critical Incident and Response – December 13, 2022

A new wave of local host file detections indicated a return of the previously encountered ransomware. An unencountered persistent mechanism was also identified, suggesting that the threat was not completely eliminated. As part of our response, we raised a critical incident to the customer, carried out an extensive threat hunt, and identified two compromised domain admin accounts, a domain controller (DC), and an SQL server.

A Potentially Unwanted Modification (PUM) detection of a disabled Windows system restore setting.

The customers’ C:Program Files directory showed peculiar files like ‘desktop.ici.royal.w’, ‘PackageManagement’, ‘README.TXT’, and ‘Uninstall Information’.

This new detection, “Ransomware.Royal”, suggests that the attackers were either still present in the network or had gained access again.

Our MDR team promptly reached out to the customer’s Security team and initiated a strategic consultation via a Zoom call. Detailed insights were shared on the Indicators of Compromise (IoCs) encountered, and we advised the customer to change the passwords of the affected domain admin accounts.

In response, the customer implemented an enterprise-wide password change and blocked the newly identified C2 server. Additionally, the decision was made to rebuild the compromised DC.

Lessons from the Incident

This episode underscores the relentless threat of ransomware reinfection in today’s threat landscape, as well as the critical role that 24x7x365 diligence of trained cybersecurity experts, swift responses, and collaborative efforts play in cyber defense.

Without having a similar level of expertise in-house, the reality is that many organizations will see reinfections that could lead to catastrophic results.

In this case, our customer had assumed full recovery from the initial ransomware attack, and if not for the MDR service, they may never had realized that the attack was still ongoing. Fortunately, the collaborative efforts of Malwarebytes MDR, EDR, and the customer successfully mitigated the threat and safeguarded the customer’s digital space.

For more information of our EDR and MDR products and services, please visit https://try.malwarebytes.com/mdr-consultation-new/

Read more:


[ad_2]
Source link