Skip to content

23.6.1 ‘Voyager’ released

Changes compared to 23.5.0

NOTICE: The “Run when PC Starts” option will now also apply to devices waking up from Sleep

New Features

  • Protected Items defined by Policy can now optionally remain linked for future changes
  • Added several new admin permissions to allow a global admin to help prevent a tenant admin from seeing the Comet service or storage provider types in use. The global admin can hide server history and server info widgets on the dashboard, prevent creation of storage via templates or custom storage, and can also filter the list of allowed cloud storage providers

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

SpaceCobra group goes after WhatsApp backups using Android spyware GravityRAT, ESET Research discovers

  • ESET Research discovered a new version of Android GravityRAT spyware being distributed as trojanized versions of the legitimate open-source OMEMO Instant Messenger Android app.
  • The trojanized BingeChat app is available for download from a website that presents it as a free messaging and file sharing service.
  • This version of GravityRAT is enhanced with two new capabilities: receiving commands to delete files and exfiltrating WhatsApp backup files.
  • The campaign is very likely highly targeted. Just as in previously documented SpaceCobra campaigns, the Chatico campaign targeted a user in India.

BRATISLAVA, KOŠICE — June 15, 2023 — ESET researchers have identified an updated version of the Android-based GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico. GravityRAT is a remote access tool previously used in targeted attacks against users in India. Windows, Android, and macOS versions are available. The actor behind GravityRAT remains unknown; ESET Research tracks the group known as SpaceCobra. Most likely active since August 2022, the BingeChat campaign is still ongoing. In the newly discovered campaign, GravityRAT can exfiltrate WhatsApp backups and receive commands to delete files. The malicious apps also provide legitimate chat functionality based on the open-source OMEMO Instant Messenger app.

Just as in previously documented SpaceCobra campaigns, the Chatico campaign targeted a user in India. The BingeChat app is distributed through a website that requires registration, likely open only when the attackers expect specific victims to visit, possibly with a particular IP address, geolocation, custom URL, or within a specific timeframe. In any case, the campaign is very likely highly targeted.

“We found a website that should provide the malicious app after tapping the DOWNLOAD APP button; however, it requires visitors to log in. We didn’t have credentials, and registrations were closed. It is most probable that the operators only open registration when they expect a specific victim to visit, possibly with a particular IP address, geolocation, custom URL, or within a specific timeframe,” says ESET researcher Lukáš Štefanko, who investigated the malicious apps. “Although we couldn’t download the BingeChat app via the website, we were able to find a distribution URL on VirusTotal,” he adds. The malicious app has never been made available in the Google Play store.

ESET Research does not know how potential victims were lured to, or otherwise discovered, the malicious website. Considering that downloading the app is conditional on having an account and new account registration was not possible during the investigation, ESET believes that potential victims were specifically targeted.

The group behind the malware remains unknown, even though Facebook researchers attribute GravityRAT to a group based in Pakistan, as previously speculated by Cisco Talos. ESET tracks the group under the name SpaceCobra, and attributes both the BingeChat and Chatico campaigns to this group.

As part of the app’s legitimate functionality, it provides options to create an account and log in. Before the user signs into the app, GravityRAT starts to interact with its C&C server, exfiltrating the device user’s data and waiting for commands to execute. GravityRAT is capable of exfiltrating call logs, contact list, SMS messages, device location, basic device information, and files with specific extensions for pictures, photos, and documents. This version of GravityRAT has two small updates compared to previous, publicly known versions of GravityRAT: exfiltrating WhatsApp backups and receiving commands to delete files.

For more technical information about SpaceCobra and the latest campaign with Android GravityRAT, check out the blogpost “Android GravityRAT goes after WhatsApp backups” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

GravityRAT distribution mechanism

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

辨別假冒手機應用程式的 7 個技巧

手機應用程式的普及已經成為我們生活中不可或缺的一部分。然而,隨著假冒應用程式的增加,我們需要學會如何識別真偽。這篇文章將分享 7 個有用的小技巧,幫助您辨識假冒的手機應用程式。

1) 下載應用程式前先閱讀評論和評分:當您找到一個新的應用程式時,請先閱讀其他用戶的評論和評分。這將幫助您對應用程式可信度有初步的了解。如果評論或評分看起來可疑或不正常,這可能是一個假冒的應用程式。

2) 確保應用程式來源可靠:在下載應用程式前,請確保它來自可靠的來源,如官方應用程式商店(Google Play Store 或 Apple App Store)。這些平台會對應用程式進行審查,以減少假冒應用程式的風險。

3) 查看應用程式的開發者:在應用程式商店中,您可以查看應用程式的開發者資訊。如果開發者名稱看起來不熟悉,或者與該應用程式的類別不匹配,那麼這可能是一個可疑的應用程式。

4) 注意應用程式的權限要求:在下載應用程式前,請仔細閱讀應用程式的權限要求。如果某個應用程式要求過多的權限,與其功能不符,這可能是一個假冒的應用程式。過多的權限要求可能意味著應用程式正在收集您的個人資訊。

5) 注意應用程式的圖標和名稱:假冒應用程式通常會模仿真實應用程式的圖標和名稱,以迷惑用戶。請仔細檢查應用程式的圖標和名稱,看看是否存在任何細微的差異或錯別字。這些差異可能是假冒應用程式的明顯標誌。

6) 注意應用程式的描述和功能:閱讀應用程式的描述和功能列表,並確保它們與您所期望的相符。假冒應用程式通常會提供虛假或過於誇張的功能描述,以吸引用戶下載。如果描述內容或功能列表看起來不實或不合理,這可能是一個假冒的應用程式。

7) 使用安全軟件檢測應用程式:安裝一個可信的安全軟件應用程式,可以幫助您檢測和識別假冒的應用程式。這些軟件通常具有實時保護和應用程式掃描功能,可以幫助您避免下載和安裝有害的應用程式。

綜上所述,辨識假冒的手機應用程式需要我們保持警覺並採取一些預防措施。通過閱讀評論和評分、確保應用程式來源可靠、查看開發者資訊、注意權限要求、檢查圖標和名稱、評估描述和功能,以及使用安全軟件檢測,我們可以提高識別假冒應用程式的能力,確保我們的手機安全。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

辨別假冒手機應用程式的 7 個技巧

手機應用程式的普及已經成為我們生活中不可或缺的一部分。然而,隨著假冒應用程式的增加,我們需要學會如何識別真偽。這篇文章將分享 7 個有用的小技巧,幫助您辨識假冒的手機應用程式。

1) 下載應用程式前先閱讀評論和評分:當您找到一個新的應用程式時,請先閱讀其他用戶的評論和評分。這將幫助您對應用程式可信度有初步的了解。如果評論或評分看起來可疑或不正常,這可能是一個假冒的應用程式。

2) 確保應用程式來源可靠:在下載應用程式前,請確保它來自可靠的來源,如官方應用程式商店(Google Play Store 或 Apple App Store)。這些平台會對應用程式進行審查,以減少假冒應用程式的風險。

3) 查看應用程式的開發者:在應用程式商店中,您可以查看應用程式的開發者資訊。如果開發者名稱看起來不熟悉,或者與該應用程式的類別不匹配,那麼這可能是一個可疑的應用程式。

4) 注意應用程式的權限要求:在下載應用程式前,請仔細閱讀應用程式的權限要求。如果某個應用程式要求過多的權限,與其功能不符,這可能是一個假冒的應用程式。過多的權限要求可能意味著應用程式正在收集您的個人資訊。

5) 注意應用程式的圖標和名稱:假冒應用程式通常會模仿真實應用程式的圖標和名稱,以迷惑用戶。請仔細檢查應用程式的圖標和名稱,看看是否存在任何細微的差異或錯別字。這些差異可能是假冒應用程式的明顯標誌。

6) 注意應用程式的描述和功能:閱讀應用程式的描述和功能列表,並確保它們與您所期望的相符。假冒應用程式通常會提供虛假或過於誇張的功能描述,以吸引用戶下載。如果描述內容或功能列表看起來不實或不合理,這可能是一個假冒的應用程式。

7) 使用安全軟件檢測應用程式:安裝一個可信的安全軟件應用程式,可以幫助您檢測和識別假冒的應用程式。這些軟件通常具有實時保護和應用程式掃描功能,可以幫助您避免下載和安裝有害的應用程式。

綜上所述,辨識假冒的手機應用程式需要我們保持警覺並採取一些預防措施。通過閱讀評論和評分、確保應用程式來源可靠、查看開發者資訊、注意權限要求、檢查圖標和名稱、評估描述和功能,以及使用安全軟件檢測,我們可以提高識別假冒應用程式的能力,確保我們的手機安全。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

The risks of using spreadsheets for cyber asset management

An accurate and comprehensive asset inventory is vital for an effective cybersecurity program. Relying on basic spreadsheets for asset management could introduce severe risks to your entire organization.

Read on as we explore the downsides of using spreadsheets for cyber asset management and highlight the clear advantages of using a dedicated cyber asset management tool to empower your security program, rather than hinder it.

Spreadsheets are simply inefficient for cyber asset management

A recent study found that a staggering 73% of cybersecurity and IT professionals use spreadsheets to manage security hygiene and posture.

There are two primary reasons why one might use spreadsheets for asset management:

  1. An asset inventory tool has never been used in your organization. 
  2. You need to work around your current asset inventory tools.

While spreadsheets can adapt to numerous use cases since they handle all sorts of data, this dexterity also makes them less than ideal for IT asset management. Furthermore, while Excel and Google Sheets can be an easy first step to track asset data for an IT environment, they fail entirely as an efficient cyber asset management solution.

7 disadvantages to spreadsheets asset management

  1. Manual data collection
    Spreadsheets require time-consuming manual updates. Without automation, they often become outdated. Reliance on tracking changes and identifying responsible parties manually introduces errors, hindering the detection and resolution of security incidents. This limitation makes it harder to monitor the integrity of the asset inventory and respond swiftly to cyber threats.
  2. Inconsistent attributes
    Different departments and individuals have discrepancies in what attributes they prioritize for data collection. Security teams may focus on listening ports, while IT may prioritize warranty expiration. This can lead to confusion and inconsistent data collection over time.
  3. Outdated information
    Asset records in spreadsheets can vary widely in age, ranging from a week to a year, depending on when someone bothered to update them. This significantly hampers effective incident response and security program management.
  4. Lack of detail
    Due to the aforementioned points, spreadsheets often lack sufficient detail. Humans dislike repetitive manual work, and the limitations of spreadsheets prevent them from containing comprehensive information.
  5. Incomplete inventory / managed-only devicesThe Achilles’ heel of any asset inventory program is unmanaged devices. Spreadsheets cannot be updated with assets that are unknown.

    According to a Deloitte research report, 32% of organizations believe that “Shadow IT” assets pose the greatest challenge for ITAM. Rogue devices installed by employees, third-party vendors, or through shadow IT lack standard security controls like EDR agents, making them easy targets for adversaries.

    The same report states that 18% of organizations are considering non-active or repurposed IT assets. With manual data entry, unmanaged devices can go unnoticed or neglected for extended periods, leading to uncertainty within teams regarding their significance or reluctance to invest effort in investigating them.

    Here are just some of the key problems unmanaged assets pose:

    • Audit violations
    • Cannot be patched
    • Cannot be upgraded
    • Cannot be automated
    • Cannot be turned off
  6. Hard to shareSharing is not built into Excel. Sharing Excel sheets linked to other dependencies also causes all sorts of problems. In the meantime, Google Sheets copies come with a touch of showmanship, flaunting a prepending “Copy of” like a magician demonstrating a trick. However, with it being so easy to duplicate documents, one sleight-of-hand from a nefarious user could go easily unnoticed.
  7. No version controlVersion control becomes a challenge as spreadsheets lack proper mechanisms to track changes and maintain data consistency. It is difficult and time-consuming to trace back who updated which asset in whose copy of which version of the spreadsheet.

    Multiple copies of the same spreadsheet create confusion and hinder the ability to have accurate and up-to-date information. This limitation affects data integrity and poses challenges in maintaining a reliable asset inventory. With Excel, sharing automatically creates a copy, and with Google Sheets, anyone with edit access can make a copy. These copies can take on a life of their own, resulting in various states of inaccuracy.

Spreadsheets are high-risk for sensitive information

As if the inefficiencies weren’t bad enough, spreadsheets lack sophisticated controls and are easily duplicated, increasing the risk of information exposure. In truth, using spreadsheets for any sensitive information is a liability. Storing asset details in a spreadsheet is perilous.

PeopleDAO, a group formed to buy a copy of the U.S. Constitution, lost 76.5 ETH ($120,000) after the accounting lead mistakenly shared a Google Sheet with edit access to a payout form on a public Discord channel.

Human error aside, hackers have a notorious history of exploiting enterprise products. In 2021, Microsoft fell victim to a malware attack spread through Excel spreadsheets, and in 2019, hackers bypassed Google filters to launch CSV malware via Google Sheets.

Both companies have continued to be victims of vulnerabilities and phishing campaigns over the years:

Access to just one spreadsheet could be the key to everything that a bad actor needs to compromise your entire network. The potential repercussions, including the costs associated with a data breach, loss of profits, expensive lawsuits, and customer and partner attrition, far exceed the investment required for a secure and comprehensive asset inventory solution.

Beyond spreadsheets – go CAASM

It is clear to see that there are significant downsides to using spreadsheets to manage cyber assets, yet organizations proceed to adopt this method with the support of other tools. However, EDRs, vulnerability scanners, CMDBs, NACs, and free asset management solutions all have asset management limitations. Not only do these tools lack comprehensive visibility into the asset landscape, but using spreadsheets to supplement or work around them only inherits the same limitations.

The manual process involved with spreadsheets introduces the risk of human error, especially as the number of assets and data sources increases. Managing access and enforcing the principle of least privilege, as well as restricting who can view, edit, or delete the inventory, becomes increasingly difficult. Without proper access controls, maintaining a secure environment and protecting sensitive information becomes a daunting task.

Correlating asset data from different sources poses challenges because each tool or data source uses its own format. It becomes arduous to accurately compare and analyze data when it is not normalized within the same time ranges. Without proper correlation and normalization, the ability to understand asset relationships, identify vulnerabilities or misconfigurations, and respond to security incidents in a timely manner is negatively impacted.

Although Google Sheets and Excel allow third-party plugins and extensions to enhance usability and functionality, granting this type of access is also high-risk. Third-parties gain access using an OAuth process. As part of this process applications can request specific scopes, gaining formidable privileges.

Example of an OAuth scope request
Example of an OAuth scope request from a third-party application for a Google product

The wrong plugin, developed with malicious intent, could wreak havoc by pilfering your sensitive information. Furthermore, once a third-party add-on has been granted access permissions, it will retain them until they are manually revoked. This means that forgotten add-ons, not used for several years, could still have access to your data. Managing this situation without a CASB or SSPM solution becomes a near-impossible task, adding yet another tool to your stack.

In contrast, a cyber asset attack surface management (CAASM) solution addresses all of these limitations, offering security, automation, integration, scalability, reporting, collaboration, and compliance support. One major benefit of CAASM is the ability to bring in data from multiple sources, allowing for automated data collection, correlation, and normalization. The best CAASM solutions also include active scan data. With a comprehensive view of all assets, organizations can prioritize security efforts, identify potential security gaps, and make informed decisions to protect their network. Correlation among different sources is not only a desirable feature but also a table stakes requirement for an effective cyber asset management solution. It enables organizations to have a holistic view of their assets, streamline workflows, and implement proactive security measures to effectively mitigate risks.

runZero is a cyber asset management solution that includes CAASM functionality, and can safely and securely integrate with other security tools and systems, such as vulnerability management platforms, Security Information and Event Management (SIEM) solutions, and Internet scanning services.

As a standalone solution, runZero performs unauthenticated active scans powered by high-fidelity fingerprinting to quickly and safely provide a complete and accurate asset inventory, even on fragile IoT and OT networks. As a whole, runZero is designed to effectively address the unique challenges and requirements of cybersecurity asset management, which a spreadsheet could never achieve.

Learn how Presidio eliminated spreadsheets for greater visibility across their internal and client networks with runZero

Read the case study

Spreadsheets vs runZero

As a whole, runZero is designed to address the unique challenges and requirements of cybersecurity asset management effectively, which a spreadsheet comparatively could never do. Below are the notable ways runZero far surpasses spreadsheets for cyber asset management:

Automation

Unlike spreadsheets, runZero automates the entire asset discovery, inventory and tracking process; offering real-time updates, accurate data synchronization, and a holistic view of an organization’s assets and network.

Scalability

Spreadsheets struggle to handle large-scale asset inventories, leading to performance issues and decreased efficiency. runZero is built to handle vast amounts of data, and millions of assets, providing a scalable solution to accommodate growing asset portfolios, from small business to large enterprise.

Advanced Security

Spreadsheets lack robust security features, making it easier for unauthorized individuals to access and manipulate them. runZero prioritizes security and provides robust features, offering advanced role-based access control (RBAC) and organizational hierarchies to ensure that only authorized individuals can access and modify the asset inventory. Our SSO and RBAC features are available in all editions. Our commitment to helping the world be more secure means we don’t gate security features in the higher tiers.

Reporting and Analytics

runZero has robust reporting and analytics capabilities, allowing organizations to generate detailed reports on asset inventory, services running on the network, current vulnerabilities, and more. This is essential when needing to provide insights and metrics that can assist in decision-making, resource allocation, and risk mitigation strategies.

Collaboration and Workflow

Spreadsheets make it difficult to collaborate and streamline workflows. runZero enables IT and security teams to work together more efficiently, share insights, and coordinate response efforts through asset ownership, alerts, third-party integrations, and canned queries for rapid zero-day response.

Compliance and Audit Support

It is near impossible to maintain an up-to-date asset inventory with spreadsheets. runZero helps organizations maintain exemplary cyber hygiene through automatic asset tracking, documenting information, changes, and security controls, making it easy to demonstrate compliance with industry regulations and standards.

Try runZero free

Upgrade your asset management.

Find out what’s connected to your network in less than 20 minutes with a 21-day trial, after which, downgrade to our free tier for personal use or for organizations with fewer than 256 devices.

Start trial

Join our team

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.