Skip to content

ESET Research dissects Evilnum Group as its malware targets online trading

BRATISLAVA, MONTREAL – ESET researchers are releasing their in-depth analysis into the operations of Evilnum, the APT group behind the Evilnum malware. According to ESET’s telemetry, the targets are financial technology companies – for example, platforms and tools for online trading. Although most of the targets are located in EU countries and the UK, ESET has also seen attacks in countries such as Australia and Canada. The main goal of the Evilnum group is to spy on its targets and obtain financial information from both the targeted companies and their customers.

“While this malware has been seen in the wild since at least 2018 and documented previously, little has been published about the group behind it and how it operates,” says Matias Porolli, the ESET researcher leading the investigation into Evilnum. “Its toolset and infrastructure have evolved and now consist of a mix of custom, homemade malware combined with tools purchased from Golden Chickens, a Malware-as-a-Service provider whose infamous customers include FIN6 and Cobalt Group,” he adds.

Evilnum steals sensitive information, including customer credit card information and proof of address/identity documents; spreadsheets and documents with customer lists, investments and trading operations; software licenses and credentials for trading software/platforms; email credentials; and other data. The group has also gained access to IT-related information, such as VPN configurations.

“Targets are approached with spearphishing emails that contain a link to a ZIP file hosted on Google Drive. That archive contains several shortcut files that extract and execute a malicious component, while displaying a decoy document,” elaborates Porolli. These decoy documents seem genuine, and they are continuously and actively collected in the group’s current operations as they try to compromise new  victims. It targets technical support representatives and account managers, who regularly receive identity documents or credit cards from their customers.

As with many malicious codes, commands can be sent to Evilnum malware. Among those are commands to collect and send Google Chrome saved passwords; take screenshots; stop the malware and remove persistence; and collect and send Google Chrome cookies to a command and control server.

“Evilnum leverages large infrastructure for its operations, with several different servers for different types of communication,” concludes Porolli.

For more technical details about the Evilnum malware and the APT group, read the full blog post “More evil: a deep look at Evilnum and its toolset” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.


About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

As with many malicious codes, commands can be sent to Evilnum malware. Among those are commands to collect and send Google Chrome saved passwords; take screenshots; stop the malware and remove persistence; and collect and send Google Chrome cookies to a command and control server.

“Evilnum leverages large infrastructure for its operations, with several different servers for different types of communication,” concludes Porolli.

For more technical details about the Evilnum malware and the APT group, read the full blog post “More evil: a deep look at Evilnum and its toolset” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.


About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

強化遠距教學,訊連科技U會議和U簡報推出6.0版更新 支援分組討論、會議主持人及PDF檔匯入等全新功能

20200619日,台北訊】多媒體創作軟體及AI人工智慧領導廠商訊連科技(5203.TW)宣布推出「U會議」及「U簡報」之6.0版更新。於此版更新中,U會議大幅強化針對遠距教學設計之多項功能,如分組討論及會議主持人。U簡報則是新增Windows或Mac版本匯入PowerPoint或PDF簡報檔案的功能,讓企業用戶和教育用戶皆可輕鬆發起簡報直播及遠距教學課程。

於防疫期間,教育機構採用遠距教學機會大幅增加,U會議6.0版著重於提升遠距教學之易用性,包括會議主持人和分組討論功能。用戶可於預約會議時指定會議主持人,在會議進行中開啟分組討論功能,與會者可加入討論室進行分組討論。以教育場景舉例,教師可在視訊授課中,將學生分成多個小組進行線上討論,並可至各分組討論室中進行指導。會議主持人也擁有進階管理權,如要求指定的與會者離開會議,進一步保障視訊會議安全。

 此外,U會議6.0版亦提供多項介面優化,如:改善桌面分享流程、與會者視訊攝影機關閉時顯示其圖像及名稱,及會議前的音訊測試功能,皆可使會議進行更加流暢便利。

為了提供高教機構Mac用戶更好的服務,U簡報6.0版本進一步提升Mac OS版本功能,講師可匯入PowerPoint及PDF檔案格式之簡報進行線上教學;Windows版則是新增了PDF檔案的支援,可大幅提升使用U簡報進行直播及遠距教學的方便性。

「訊連科技自2020年2月啟動『U校園防疫專案』後,全台已獲超過100所大專院校採用,廣泛應用在校園遠距教學與行政會議等場景。」訊連科技黃肇雄執行長表示:「訊連持續收集用戶反饋,進行產品優化。本次『U會議』及『U簡報』大幅更新多種互動工具,教育單位和公民營機構可更彈性地應用在遠距教學、視訊會議及線上行銷活動中。」

用戶可於即日起至U官方網站下載最新「U會議」「U簡報」6.0版,或透過程式內建的升級功能取得6.0版更新,體驗最新功能

U會議6.0版新增功能

  • 新增會議主持人功能。主持人可於會議中發起分組討論,開啟數個分組討論室讓與會者加入,主持人亦可加入分組討論室中進行指導。
  • 會議主持人可使指定與會者離開會議,管理與會者名單,保障會議安全。
  • 優化視訊會議介面。與會者未開啟視訊鏡頭時,可顯示使用者圖像與名稱,方便識別。
  • 優化桌面分享之介面及流程,使用更便利。
  • 音訊裝置測試功能,可於會議前測試喇叭及麥克風之設定。

U簡報6.0版新增功能

  • Mac版全面升級,可匯入PDF或PowerPoint檔案,進行遠距簡報直播。
  • Windows版新增支援PDF匯入功能。

U會議產品資訊

訊連科技「U會議」,即日起可於U官方網站下載,並內建繁體中文、簡體中文、英文、法文、德文、義大利文、西班牙文、日文及韓文等九國語系。

您可根據與會人數及直播時間需求,選擇不同的 U 會議訂閱方案。即日起至7月31日止,免費版本最多可支援25名與會者及60分鐘會議長度。

關於訊連科技U整合通訊服務

訊連科技「U 簡報」、「U 會議」及「U 通訊」整合了遠距直播、視訊會議及即時通訊等功能,為企業及教育機構打造即時、跨國界、跨平台、行動優先、高影音品質之新世代視訊溝通服務。

 

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

ESET removes Social Media Scanner from product portfolio due to restrictions on third-party API applications

BRATISLAVA – ESET, a global leader in cybersecurity, has removed the ESET Social Media Scanner from its product portfolio. The API-based application was initially designed to protect users from malicious content distributed through Facebook, Twitter and VKontakte and sat alongside ESET’s software solutions. Due to increased restrictions on third-party API applications, the removal of Facebook protection and the strengthening of Twitter’s built-in security, the application will be from August 4, 2020 no longer available.

User security and safety when accessing social media platforms is paramount. During its existence, ESET Social Media Scanner secured more than 135 billion links and identified over 12 million threats in social media content, including malicious links and downloads. ESET is dedicated to providing consumers with the highest level of protection and is constantly adapting its solutions to the current cybersecurity and threat landscape.

Now, ESET Internet Security offers cutting-edge internet protection that steps in to addresses threats vectoring from social media. The solution provides users with advanced protection against internet threats using ESET’s renowned multilayered antivirus technology and privacy protection. This multiplatform protection is delivered under one license to ensure comprehensive protection.

In addition to robust cybersecurity solutions, ESET provides a wealth of online resources in order to educate users on cybersecurity best practices and how to stay safe online. While ESET Internet Security continues to protect users from malicious content online, it is vital that people are vigilant with their social media safety. If you are concerned that your Twitter account has been compromised, head to We Live Security to follow our expert’s advice on Twitter safety.

Marek Demín, Product Manager at ESET, commented, “At ESET, we are consistently evaluating our product offering to ensure consumers are equipped with the highest levels of protection. Central to our core mission in helping users enjoy safer technology is staying one step ahead of the latest threats and offering modern, cutting-edge solutions. This is why we have renewed our focus on our Internet Security offering, which provides users with comprehensive internet protection through one secure solution. Whether you’re browsing the web, doing online banking or using social media, we are dedicated to providing a safe and secure online experience for all.”

Learn more about ESET Internet Security here.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

SCADAfence Researchers Discover a Vulnerability in Mitsubishi Electric MELSEC iQ-R Series CPU DoS

As part of our mission to secure the world’s OT, IoT and Cyber Physical infrastructures, we invest resources into offensive research of vulnerabilities and attack techniques.

CVE-2020-13238 is a remote CPU DoS vulnerability in Mitsubishi Electric iQ-R Series that has been discovered by SCADAfence researcher Yossi Reuven.

Mitsubishi Electric is one of the world’s leading electronics and electrical equipment manufacturing companies, and is in use by many of our customers. We have been working with Mitsubishi Electric for the last few months in handling this vulnerability, and on June 9th, Mitsubishi Electric published an official security advisory reporting this vulnerability and mitigations.

CVE-2020-13238

MELSEC iQ-R Series is Mitsubishi Electric flagship product line – design for high productivity automation systems. iQ-R CPUs’ communication with GX Works 3 (Engineering software package) is done via Mitsubishi Electric proprietary protocol MELSOFT (which works on both TCP and UDP). 

When an attacker sends a short burst of specially crafted packets over the MELSOFT UDP protocol on port 5006, which causes the PLC’s CPU to get into fault mode, causing a hardware failure (error code: 0x3C00 – hardware failure). The PLC then becomes unresponsive and requires a manual restart to recover.

What SCADAfence Recommends Vendors To Do

Upgrade to the Latest Firmware

Most of Mitsubishi Electric’s iQ-R Series PLCs are not running on the firmware versions later than Version 40. In addition, automation engineers don’t usually upgrade to the latest firmware, which can lead to their PLCs being exposed to a DoS (denial of service) attack. Upgrading to the latest firmware (Version 49) can prevent this attack from happening.

Block UDP Port 5006 and Use MELSOFT TCP

MELSOFT is an engineering software for Mitsubishi PLCs and gives users the option to use either the (connectionless) UDP and (connection-oriented) TCP protocols for programming and configuring the devices. SCADAfence recommends to block Block UDP port 5006 since the cyberattack leverages the connectionless UDP protocol and can cause the PLCs to stop functioning and cause a denial of service. Instead, users should use the TCP protocol for communicating with devices in the shop floor or the control network.

Special Thanks & Recognition

The SCADAfence Research team would like to thank the Mitsubishi Electric team for a speedy vulnerability reporting process even during the challenging COVID-19 times.

SCADAfence is committed to continued research of offensive technologies and development of new defensive technologies.

Exploit PoC

We wrote a Python POC (GPLv3) script of the exploit in action. You can download it for free and use this for educational / research purposes.

Warning: The script will crash the PLC’s CPU – don’t use in production.

To get this free python script, please send an email to christoph@scadafence.com

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

後防疫時代非接觸性生物辨識需求升溫 訊連科技FaceMe®推出口罩偵測及臉部辨識解決方案

2020610日,台北訊】 AI臉部辨識技術領導廠商訊連科技(5203.TW)宣布,旗下FaceMe® AI臉部辨識引擎推出兩項全新功能,包括偵測是否配戴口罩、及於戴口罩時進行人臉辨識,此兩項技術將應用於所有智慧物聯網場域,包括醫療、零售、門禁、安控、辦公大樓的「後防疫時代」防護控管及人員控制等解決方案。

近日新冠肺炎疫情趨緩,商業活動已逐步復甦,出入醫院、商場等公共場所時,仍建議配戴口罩及保持適當社交距離。FaceMe®AI臉部辨識引擎全新的口罩偵測功能可透過AI技術,偵測及判別人員是否配戴口罩,或口鼻露出、使用其他物品遮住口鼻等非正確配戴狀況。FaceMe®可辨別醫用口罩、 N95口罩、布口罩等各式口罩,並可辨識不同臉部角度下之口罩配戴狀況。

 此外,人員進出必須配戴口罩之場所,如醫院、廚房、公共運輸等,FaceMe®也可於配戴口罩後進行臉部辨識及身分確認,準確率達95%以上,可大幅減少刷臉時須取下口罩之風險及不便。

「受到疫情影響,指紋辨識、靜脈辨識等接觸性生物辨識因有接觸風險,已被非接觸性生物辨識取代。而與需要特殊硬體及近距離使用的虹膜辨識相比,臉部辨識技術具備準確、彈性、安全等優勢,成為非接觸性生物辨識之主流技術。」訊連科技黃肇雄執行長表示:「因應後防疫時代的口罩配戴措施,FaceMe®口罩偵測及戴口罩臉部辨識等功能,可提供智慧物聯網廠商及系統整合商完整的解決方案,廣泛應用於醫療、零售、門禁等場景。」

 FaceMe®是專為邊緣運算裝置開發的臉部辨識引擎,擁有高達99.70%的辨識率。在全球知名NIST臉部辨識競賽中,名列全球最精準且最快速的刷臉技術之一,也是台灣表現最佳之廠商。除了支援功效強大的工作站或個人電腦,亦可針對IoT/AIoT物聯網設備中的輕量、低功耗設備進行優化。本次推出口罩相關功能, FaceMe®精確、即時及安全的特性也獲得更廣泛的實務應用。

除了口罩相關應用,訊連科技也預計於第三季陸續推出整合熱感攝影機的體溫檢測、及AI人數統計等功能,可進一步為後防疫時代的安控、零售及醫療等相關應用提供一站式的智慧解決方案。

更多訊息,請參考FaceMe®官方網站(https://tw.CyberLink.com/FaceMe),或透過電子郵件(FaceMe_TW@cyberlink.com)與訊連科技業務單位聯絡取得試用。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

×

Hello!

Click one of our contacts below to chat on WhatsApp

×