Skip to content

居家辦公弱點曝,駭客詐騙趁虛入 – BEC 詐騙如何防範?

近日傳出某家銀行的海外分行員工,在居家辦公期間接到駭客假冒客戶的詐騙郵件,依指示轉帳被詐騙數十萬美元的事件。據悉,駭客假冒變造的電子郵件地址,與正確的郵件僅有一個字母之差,順利矇騙了承辦人員;其次行員在匯款前,並未透過第二管道與客戶確認,因而造成鉅額財務損失。

要防止偽冒變造的郵件,除了承辦人員需有良好的教育訓練和並多加留意之外,企業也應妥善運用有效的郵件防禦機制,在第一時間將偽冒的郵件阻擋在外,或為疑似偽冒的郵件加以標記。中華數位科技 SPAM SQR 與ADM進階防禦機制,可針對寄信來源潛藏偽造特徵的郵件、BEC 詐騙郵件、冒名偽造網域社交郵件及各式詐騙來源郵件進行檢測,並加以攔截。當上述郵件不慎被重送放行到使用者端時,系統會自動在此類郵件主旨加以標註警示,提醒使用者提高警覺,以降低被詐騙的風險。另外,Mail SQR Expert 的特定郵件外寄自動加密功能,可將內容含有匯款帳號,匯款金額關鍵字的外寄郵件,自動轉為 PDF 並加密,收件人必須透過第二管道取得原寄件人的密碼才能開啟郵件,避免企業的匯款資訊遭駭客攔截偽冒。

若不幸被騙,應立即採取行動向警方報案、聯繫匯款銀行申請退匯,越早察覺並處理,追回款項的機會就越高。此外,不論款項是否追回,也應尋求專業的鑑識夥伴。中華數位科技BEC鑑識服務團隊,協助清查鑑識受害電腦與關聯網路,改善資安問題並避免再度受駭。

BEC 詐騙是經過縝密計畫的針對型攻擊,同時混合了多種入侵與欺騙的手法。駭客在事前就開始鎖定詐騙目標,並且長期潛伏監控,以便在匯款的關鍵時刻介入偽冒。一旦被盯上後就有可能重複發生,背後的資安問題若未被正確地找到並解決,不論企業躲過幾次損失,未來還是有可能再次發生!

更多BEC 詐騙各階段補救與防禦重點,請參考 中華數位 BEC 詐騙解決方案

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於中華數位科技 Softnext Technologies Corp.
創立於2000年8月。
秉持著【We Secure Your Content】的服務理念,以提供企業資訊應用管理服務及打造資訊內容安全防護為宗旨。專精於提供網路應用服務技術,根據市場需求推出多款資訊內容安全的解決方案及應用服務,能夠協助企業透過符合資安管理規範並遵循法規的方式進行資訊內容安全管理,以維護員工的生產力、提升企業經營績效。

駭客運用映像檔躲避檢查關卡,對各產業發動攻擊

近期不少企業詢問關於附件檔夾帶 .ISO、.IMG 等映像檔的攻擊行為。事實上,ASRC 研究中心在「2019 年第三季電子郵件安全趨勢報告」中,便已揭露在 2019 年第三季觀察到不少駭客利用 UDF 映像檔附件做為攻擊工具的案例:UDF 映像檔原是用於光碟備份、燒錄前暫存、準備於大量複製光碟之用,其副檔名多為 .iso、.img… 等。由於這類映像檔有其特定用途,部分的防毒牆、防火牆、終端防毒軟體會忽略對這類格式檔案的大小限制或其內容的檢查,因此攻擊者就利用此缺口,將病毒嵌在標準合法的 UDF 映像檔格式內,以躲過各種檢查關卡。再次提醒管理者要意識到映像檔也可被運用於攻擊,並作為資安策略的考量。


這類型的攻擊主旨幾乎都與商業的交易行為有關,舉凡提及訂單、發票、詢價報價、交易通知,內容也十分在地化,亞洲區發現的樣本除了英文外,也可見到韓文、簡繁體中文。攻擊在 2019 年第四季達到高峰,2020 年第一季整體數量降至前一季的1/3,並且,除了 .ISO、.IMG 等常見的映像檔格式被利用之外,我們也觀察到有少量的.DAA 格式映像檔在外散播。


ASRC 與中華數位科技至今仍持續監控這類型的攻擊。事實上 .ISO、.IMG 夾帶惡意程式不是新聞,長期以來都是有的,可以把它想成是一種壓縮檔,類似 zip 中藏了惡意程式這樣的寄送方式。因此,以 .ISO 檔來說,有裝Winrar 的 Windows 會將他的圖示標為 Winrar 可支援的壓縮檔 (Winrar 預設關聯 .ISO 檔),對於收到這種 .ISO 檔的收件者來說,可能會自然的將它打開,並執行惡意程式。

ASRC 再度提醒企業小心留意,防禦映像檔攻擊可以這麼做:

    1. 取消隱藏副檔名,對映像檔附件多加留意。

 

    1. 加強人員安全意識,面對來路不明的郵件抱持高度懷疑的態度。

 

  1. 運用合適的郵件防禦設備,提供人員較安全的郵件使用環境。

    目前中華數位 SPAM SQR 已可防禦這類映像檔攻擊

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於中華數位科技 Softnext Technologies Corp.
創立於2000年8月。
秉持著【We Secure Your Content】的服務理念,以提供企業資訊應用管理服務及打造資訊內容安全防護為宗旨。專精於提供網路應用服務技術,根據市場需求推出多款資訊內容安全的解決方案及應用服務,能夠協助企業透過符合資安管理規範並遵循法規的方式進行資訊內容安全管理,以維護員工的生產力、提升企業經營績效。

【世界密碼日】這些年,大家一起用的弱密碼

您知道每個五月的第一個星期四是世界密碼日嗎?現代生活每天都過得十分繁忙,您有好好關心過您的密碼嗎?趁著世界密碼日,好好的了解一下關於密碼容易被忽視的問題。

根據 splashdata 的統計,2019 年的十大弱密碼仍是那幾個熟面孔,和 2018 年的榜單做個比較,上榜的密碼大同小異,雖然「sunshine」掉出 Top 10 榜外但也仍是第30名,新進榜的還是更弱的「123123」。並且毫無意外的,仍是「123456」奪下弱密碼冠軍寶座。


什麼是弱密碼呢?就是特別容易被猜中,或是許多人愛用的同一種邏輯所設定的密碼:例如,去年一位國外工程師曾在推特發問,為何 ji32k7au4a83 這個看似安全的密碼在 Have I been pwned 資料庫中出現上百次。然而,這個問題竟然只有台灣網友答得出來,對照注音鍵盤 ji32k7au4a83 = 我的密碼。不僅如此,網友還發現和password、iloveyou相同邏輯的 au4a83、ji394su3 密碼使用量遠超過 ji32k7au4a83。

根據最新美國標準與科技研究院(NIST)所提出的建議,高強度的密碼設定原則,最好包括15個字元以上,並由幾個不相干的名詞或數字組成:例如,VisonExamAttention2020YouLove,這樣超長的密詞可套用自己才知道的邏輯進行組合,比亂數形成的密碼方便記憶,也不容易被破解。另外,若無任何證據顯示密碼有外流的情況,頻率過高的更換密碼,為難的不是入侵者,而是密碼的使用者!

密碼的保護,除了應避免使用弱密碼外,也必須考慮外來的嘗試與破解!當系統遭遇錯誤率過高的外來的密碼嘗試時,應直接封鎖嘗試的來源,而非將該帳號封鎖,這樣才能在避免「暴力破解(Brute-force attack)」、「字典檔攻擊(Dictionary attack)」與「密碼噴灑(Password Spraying)」的時候,不至於困擾擁有正確密碼的主人。

最後,也是大家最容易疏忽的事:千萬不要在多個服務都使用同一組密碼!
一旦任一服務有密碼外洩事件發生時,使用相同密碼的其他服務也跟著一起曝險!

ASRC 研究中心的帳密安全提醒
1. 選擇使用者保護較嚴謹的系統服務,例如一定要有防密碼濫猜的機制
2. 切記,不要一套密碼走天下。不同的服務間使用相同的密碼,只要一個服務的帳密外洩,很容易牽連其他服務帳戶,尤其網路銀行登入密碼更要避免重覆使用。
3. 避免使用公開在外或社群網站可見的生日、姓名、手機等資料做為密碼
4. 雙因子驗證的搭配使用,比定期更換密碼的保護效益有用許多

驗證郵件密碼強度,SPAM SQR 密碼強度檢測模組
企業的電子郵件密碼安全,可透過中華數位科技 SPAM SQR 密碼強度檢測模組定期實施密碼稽核,確保密碼強健度,降低密碼被猜中的風險,避免員工的弱密碼成為資安破口。詳情請洽中華數位科技 02-25422526。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於中華數位科技 Softnext Technologies Corp.
創立於2000年8月。
秉持著【We Secure Your Content】的服務理念,以提供企業資訊應用管理服務及打造資訊內容安全防護為宗旨。專精於提供網路應用服務技術,根據市場需求推出多款資訊內容安全的解決方案及應用服務,能夠協助企業透過符合資安管理規範並遵循法規的方式進行資訊內容安全管理,以維護員工的生產力、提升企業經營績效。

關於 ASRC 垃圾訊息研究中心
ASRC 垃圾訊息研究中心 (Asia Spam-message Research Center),長期與中華數位科技合作,致力於全球垃圾郵件、惡意郵件、網路攻擊事件等相關研究事宜,並運用相關數據統計、調查、趨勢分析、學術研究、跨業交流、研討活動..等方式,促成產官學界共同致力於淨化網際網路之電子郵件使用環境。更多資訊請參考 www.asrc-global.com .

ESET upgrades security management for organizations running Microsoft Azure

Bratislava – ESET has upgraded its Security Management Center for Microsoft Azure, providing organizations with complete, real-time network visibility and allowing them to oversee thousands of servers, desktops and mobile devices via a single pane of glass.

ESET Security Management Center for Microsoft Azure is a cloud-based management solution that gives businesses the capability to deploy, update and manage all ESET security solutions from a single console. The upgraded management console is ideal for both small and large organizations already utilizing Microsoft Azure, and requires no additional hardware or license fees.

The comprehensive solution enables businesses to easily manage all physical and virtual desktops and servers running on Windows, macOS and Linux, as well as supporting full Mobile Device Management (MDM) of Android and iOS devices. ESET Security Management Center seamlessly combines the management of multiple endpoint products, including ESET Enterprise Inspector and ESET Dynamic Threat Defense in one easy-to-use hub, also accessible via browser. This means organizations are equipped with multilayered protection that addresses the key tenets of a strong cybersecurity strategy: threat prevention, detection, assessment and response.

In addition, the solution features a fully customizable notification system, allowing users to configure notifications with the exact information they wish to be notified about.

Igor Hula, Product Manager at ESET, commented: “We are dedicated to providing our users with the very best in IT security, and our wide range of product offerings for a variety of platforms and devices exemplifies this. We believe every business should be equipped with cutting-edge technology in order to keep both their employees and customers safe and secure, and we are continuously improving and adapting our solutions to ensure this. It is vital that businesses of all sizes are supported by a comprehensive cybersecurity strategy – advanced and easy-to-use solutions mean businesses can focus on their goals, knowing they are securely protected.”

For further information on ESET Security Management Center for Microsoft Azure, please click here.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Internews and ESET develop security partnership to protect human rights defenders

Bratislava – Global nonprofit Internews has partnered with cybersecurity company ESET to distribute antivirus software to civil society and at-risk groups worldwide. The pilot project will protect more than 1000 devices, reaching a network of journalists, human rights groups, and members of civil society who are highly vulnerable to digital threats.

“These licenses will fill a critical gap among the most at-risk communities around the globe,” said Megan DeBlois, Information Security Advisor at Internews. “The consequences of online attacks against human rights defenders can be life altering — leading to silencing, arrests, or worse. We’re grateful to partner with ESET for helping us provide stronger protections to human rights defenders at such a vital time for information provision.”

Internews supports media organizations and other information providers globally with resources, training, and funding so they can deliver trustworthy and accurate information to local communities. This includes providing direct technological support to those working in some of the most restrictive regimes worldwide.

“We’re thrilled to be working with Internews to help better protect those on the front lines, the people providing information at this time of crisis,” said Alexis Dorais-Joncas, Security Intelligence Team Lead at ESET. “First responders in human rights communities often operate with very limited resources while they face some of the most advanced and dedicated threat actors. It’s meaningful to all of us at ESET to be able to support these communities with high-quality tools and protections that might not be available to them otherwise.”

“This pilot project with ESET enables beneficiaries to access antivirus tools which are otherwise prohibitively expensive, limited to free-tier services, in short supply for NGO licenses, and/or reliant on advertising models,” said Jon Camfield, director of Global Technology Strategy at Internews. “While antivirus is not a cure-all or appropriate for all threat models, it is a critical tool for reducing risk.”

The Internews/ESET partnership is intended to strengthen connections between civil society and the private sector, enabling a greater exchange of ideas and needs from end users to tech developers. This connection is a core principle of Internews’ global technology efforts.

“Identifying and flagging malign actions helps improve security for everyone, not just the individual or group targeted,” said DeBlois. “As companies like ESET have greater visibility into the offensive tactics being deployed against civil society, they’re even better equipped to design effective defensive strategies to protect all users from these advanced threat actors.”

The initiative comes as cyberattacks are on the rise as more and more people move to operating online in response to the COVID-19 situation, and forms part of Internews’ broader work in ensuring vital information can reach all sectors of society at this crucial time. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×