Skip to content

ESET uncovers Operation NightScout: Cyberespionage supply-chain attack on gamers in Asia

BRATISLAVA, MONTREAL – A few days ago, ESET researchers discovered a new supply-chain attack compromising the update mechanism of NoxPlayer, an Android emulator for PCs and Macs. Three different malware families were spotted being distributed from tailored malicious updates to selected victims with no sign of leveraging any financial gain, but rather, only cyberespionage capabilities were seen. ESET dubbed the malicious operation NightScout.

BigNox is a company based in Hong Kong that provides various products, primarily an Android emulator for PCs and Macs called NoxPlayer. The company claims that it has more than 150 million users in over 150 countries who speak at least 20 different languages. That said, BigNox’s follower base is predominantly in Asian countries.

“Based on ESET telemetry, we saw the first indicators of compromise in September 2020. Activity continued apace until we uncovered explicitly malicious activity this week, at which point we reported the incident to BigNox,” says ESET researcher Ignacio Sanmillan, who revealed Operation NightScout.

Operation NightScout is a highly targeted operation with ESET researchers able to identify only several victims. Those identified victims are based in Taiwan, Hong Kong and Sri Lanka. “Based on the compromised software in question and the delivered malware exhibiting surveillance capabilities, we believe this may indicate the intent of intelligence collection on targets involved in the gaming community,” elaborates Sanmillan.

Map – Distribution of NightScout victims

In this specific supply-chain attack, the NoxPlayer update mechanism served as the vector of compromise. On launch, if NoxPlayer detects a newer version of the software, it will prompt the user with a message box offering the user the option to install it, thus delivering the malware.

“We have sufficient evidence to state that BigNox’s infrastructure was compromised to host malware and also to suggest that their API infrastructure could have been compromised. In some cases, additional payloads were downloaded by the BigNox updater from attacker-controlled servers,” adds Sanmillan.

 

A total of three different malicious update variants were observed by ESET researchers. The first malicious update variant does not seem to have been documented before and has enough capabilities to monitor its victims. The second update variant, in line with the first, was spotted being downloaded from legitimate BigNox infrastructure. The deployed final payload was an instance of Gh0st RAT (with keylogger capabilities) also widely used among threat actors

The third variant, PoisonIvy RAT — a remote access tool popular with cybercriminals was only spotted in activity subsequent to the initial malicious updates and downloaded from attacker-controlled infrastructure.

ESET has spotted similarities between loaders that our researchers have monitored in the past and some of those used in Operation NightScout. The similarities we see relate to instances discovered in a Myanmar presidential office website supply-chain compromise in 2018, and in early 2020 in an intrusion into a Hong Kong university.

“To be on the safe side, in case of intrusion, perform a standard reinstall from clean media. For uninfected NoxPlayer users, do not download any updates until BigNox sends notification that they have mitigated the threat, furthermore, best practice would be to uninstall the software,”, advises Sanmillan.

For more technical details about Operation NightScout, read the blogpost “Operation NightScout: Supply-chain attack targets online gaming in Asia” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

[Update – February 3, 2021]
Following the publication of our research, BigNox have contacted us to say that their initial denial of the compromise was a misunderstanding on their part and that they have since taken these steps to improve security for their users:

  •  use only HTTPS to deliver software updates in order to minimize the risks of domain hijacking and Man-in-the-Middle (MitM) attacks
  •  implement file integrity verification using MD5 hashing and file signature checks
  •  adopt additional measures, notably encryption of sensitive data, to avoid exposing users’ personal information

BigNox have also stated that they have pushed the latest files to the update server for NoxPlayer and that, upon startup, NoxPlayer will now run a check of the application files previously installed on the users’ machines.

*ESET assumes no responsibility for the accuracy of the information provided by BigNox.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

資料保護: insider 或 outsider?

網路犯罪以前往往是無差別式機會主義,惡意程式隨機散布,有設備未修補或有人上當就成為受害者。侵入內部後向外滲漏資料,內部使用者可能成為不知情的共犯。

為了討論關於事件和資料外洩,先定義事件與洩漏的差別

Incident v.s. breach

Incident : 危及資訊資產的完整性、機密性或可用性的安全事件。

Breach : 造成確認的未經授權的披露資料(而不僅僅是潛在洩露)的事件。

這二年的手法轉變成有目標性的勒索(Targeted ransomware),有情感上(民族主義或政治)或財務上的針對性。以往勒索軟體單單只加密本機檔案,受害者可能選擇不付贖金,一切重新來過。偷走資料的目的是為了威脅逼迫受害者支付贖金。

Targeted ransomware 還有一項特色,為了滲透潛伏大多利用APT (Advanced Persistent Threat )手法,有組織有規劃的長期秘密工作,信仰和財務可能是最大的動機;單純搞破壞炫技已不多見。

Targeted還有另一種針對,傾向於遵循一個基本模式:針對組織環境進行規劃。他們研究受害者,瞭解漏洞在哪裡,例如缺少更新或更新失敗,以及員工容易受到網路釣魚活動的影響。駭客了解目標的弱點,然後展開一項活動,讓內部人員不小心誤載惡意軟體。

儘管資料外洩可能是無心之過,但未經授權的竊取並出售個人身份資訊 (PII)或公司專利、營業數據以獲取利益或破壞,則可能會造成組織嚴重損失。

 

探討資料外洩統計結果,是內部威脅多,還是外部攻擊多?

這個問題在很多專家的統計結果呈現各說各話的局面,這可能跟現在主要的滲透取得資訊動機手法有關。認為外部威脅多的,可能是因為邊際防火牆,及入侵偵測系統上發現並且阻擋到的可疑事件。傳統的安全防護方案著重在外部,對內部的偵測本來就少,或者沒有偵測內部活動的方法;代表內部即使有資料洩漏,也不會被發現,看起來外部威脅比較多的假象。

另外一個原因是,內部威脅(包含已滲透進來的)專業越來越熟練,新的手法還沒被資安系統偵測識別出,就不會知道有內部威脅。想要竊取組織資料的人可能是敵對的外國政府、組織、職業罪犯或憤怒的人士;但他們很可能進入組織成為自己的員工,儘管現在技術進步,仍很難發現可能竊取或洩露資料的員工。

 

企業的規模、產業別與外洩事件的相關度 

甚麼產業是最可能被覬覦的對象? 鎖定對象針對性的攻擊,具備如此大費周章複雜程序,想必目標的選擇一定精挑細選,高價值目標的高價資產是首選。這代表著,受害的組織可能具備部分或全部特質;如高科技產業、金融產業、或年收上億、或規模夠大,指標性組織(如國防部)等。

台灣的中小企業佔總體97%左右,理論上大部分都不容易成為被針對的目標,雖然有可能遭無辜波及。那為何總覺得這些外洩案例這麼聳動? 因為新聞裡的這些受害企業實在太具備指標性了,甚至有些企業體上述的特徵全部符合。但我們並不排除,以前那種亂槍打鳥式的勒索仍然會存在,只是因為沒利用APT滲透,比較容易被發現。

排除這個最大的外部攻擊,內部人員的威脅對中小企業而言才是防不勝防的。由於主動識別和預防無意或有目的的內部威脅可能非常困難,許多公司實際上意識到了內部人員的風險,但與網路解決方案的領域不同,公司和機構也在為解決方案而苦苦掙扎。

 

不論外部內部,要防的是資料失竊

由以上的討論發現,外洩防護已經沒辦法分得出內外了,也不可能靠單一的技術來解決。應該回歸到保護的標的物本身: Data的使用、移轉、儲存上面的保護。

資料失竊類型分類與對策:
  • 遺失裝置-裝置遺失後,實施註銷管理,資料自動清除等機制。內部儲存資料在未被認證的狀態下,保護其不能被其他平台存取。
  • 傳輸活動- 限制不必要的網路傳輸活動,如電子郵件、FTP、IM、雲端存取等,如果必要,留下可供追查究責的證據。
  • 可卸除式裝置-防止不必要的存取,或採取有效的寫出管制與加密保護。
  • 資產與更新管理-掌握資產狀態,與定期更新修補,防止被利用成為工具。
  • 使用者活動-使用者使用檔案的活動,作業系統的事件,程序的活動等,保留與資料存取相關的記錄。
  • 第三方存取-儘管採取一切可能的措施來確保內部資料的安全,惡意分子仍可以使用第三方供應商系統進入組織。甚至軟體供應商來源的修補軟體,都可能被植入惡意程式。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

7 tips to prevent cyber attacks during remote work

The year 2021 has arrived, and organizations of all types and sizes are continuing their efforts to adapt their workforce to the new work reality imposed by the Covid-19 pandemic. People, who were previously working using corporate devices and infrastructure within its security perimeters, have been forced to quickly change their approach, now working from their homes and accessing the same resources as before lockdowns. And according to Cisco research published in the Future of Secure Remote Work report, even with the introduction of a vaccine against the coronavirus, IT decision-makers believe that a significant part of this workforce will continue to operate remotely, thereby accelerating the move to Cloud-based models and their projects linked to digital transformation.

Many companies, however, did not have the adequate infrastructure to support a huge number of people working from their homes, let alone to ensure that sensitive data was not exposed. The change introduced by the pandemic has created a strong demand for digital solutions, bringing an important mission for the Information Security teams: not only to protect the company, its employees, and customers but also to guarantee business continuity. A Promon survey of 2,000 remote workers provides some worrying data: almost two-thirds of them had not received any cybersecurity training in the past 12 months. Besides, 77% of them are not concerned with data security while working from their homes. It is worth remembering that data protection laws provide for heavy sanctions in case of data leaks. If the personal data of Brazilians are leaked, for example, a company is subject to fines that can reach 2% of revenues or 50 million reais.

In this context, the Covid-19 pandemic also brought new attack vectors to this entire remote workforce. With so many people using insecure devices and networks to perform their daily activities, malicious attackers saw an opportunity to exploit security gaps introduced by this form of work. Also according to the Cisco report, 61% of decision-makers have reported an increase of 25% or more in cyber threats since the pandemic began in March 2020. And for those who think cybersecurity is something that concerns only global organizations, this increase in threats is also reported by small (55%) and medium-sized (70%) companies. But what aspects should Information Security leaders consider in order to guarantee the security of data transmitted via unprotected devices and networks?

Virtual Private Network, or VPN – as a basic tool in the kit of those who want to guarantee data security, VPNs are old known to IT teams. In addition to the function of avoiding geographical restrictions, the use of these tools also improves privacy on the internet. Also, a VPN allows you to encrypt all internet traffic through devices;

Wi-Fi, or Wireless Connections – most Wi-Fi networks are secure in some way. However, when outside their workspaces, employees should be aware that using public wireless networks is one of the preferred targets for malicious agents to spy on internet traffic and collect sensitive data

Home Routers – many people do not change the passwords for their home routers when they are installed, which increases the risk of falling victim to a cyberattack. To prevent any malicious attacker from having access to the home network and thus gaining improper access to critical data, the first step includes changing the router’s password. Also, it is interesting to encourage employees and third parties to check and install device firmware updates.

Passwords – In these times, it is more important than ever that your passwords are properly protected. Unfortunately, many people use the same password for multiple-service access credentials, both personal and corporate. This means that if a malicious attacker has access to a compromised password, it will be much easier to gain access to other services, including corporate accounts. Therefore, it is recommended to use a PAM solution to manage these privileged credentials.

Multi-Factor Authentication – often, strong passwords are not enough to protect systems from unauthorized access. If a criminal has access to a credential compromised in a data leak, it is not difficult to compromise other user accounts. Thus, by using multi-factor authentication, such as confirmation via an OTP (One-Time Password) generated by an application or SMS, it is possible to add an extra layer of protection to user accounts;

Backups – all user files must be configured to be backed up, preferably in a cloud-based environment. If there is a cyberattack through malware, such as ransomware, and the data is not properly saved, it is not possible to recover it without paying a ransom, which can directly affect the victim’s activities and even the business continuity;

Phishing – in addition to investing in cybersecurity solutions, it is also necessary to train employees appropriately to learn how to deal with phishing attempts or other social engineering-based attacks by malicious attackers to gain improper access to systems. One way to address this problem is to alert employees how to detect suspicious emails from unknown senders, especially if it involves any user action, such as clicking a link or opening an attachment. Even messages received from trusted senders must be considered and verified before they are opened.

As remote work becomes more and more common, companies of all sizes need to implement infrastructure in addition to the appropriate policies to minimize their exposure to cybersecurity risks. The list we presented here is a good start to give an idea of what should be considered in order to create an adequate policy to ensure the protection of the remote workforce. In this way, it is possible to reduce the risks of cyberattacks and avoid heavy penalties from data protection laws, which can affect the trust of employees, partners, suppliers, and even business continuity.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

如何使用Mirror-Cam搭配視訊會議軟體分享文件

IPEVO Mirror-Cam 是個小巧卻功能強大的工具,可幫助學生及專業人士線上溝通與學習。 Mirror-Cam 具有易攜帶、輕巧且直覺的設計,將筆電內建的攝影鏡頭變成實物攝影機,透過 Mirror-Cam的反射,立即在螢幕上看到筆電鍵盤上發生的所有活動。

Mirror-Cam的創新設計提供了俯角視野,創造出一個展示空間,讓學生在其中筆記、創作速寫、解決數學問題、解說文件、大聲朗讀和做許多事情。專業人士只要將工作放在筆電鍵盤上,便可輕鬆的即時在線上展示工作內容和修改。Mirror-Cam包裝附上一塊小白板,可以完美放在任何筆電的鍵盤上。 Mirror-Cam有著可調整的小翼板、口袋尺寸和輕巧的設計,適合各種尺寸筆電和Chromebook,並方便隨身攜帶。

最重要的是,Mirror-Cam可與Zoom、Google Meets、Skype、Microsoft Teams、Webex和Go to Meeting等第三方通訊軟體一起使用。搭配IPEVO Visualizer軟體,Mirror-Cam提供了一種新奇且省錢、在視訊時分享文件或實物的方式(Mirror-Cam 一組6入裝,僅售1,280元)。

以下是使用步驟,說明如何使用Mirror-Cam及視訊會議軟體分享文件或實物,以及如何解決使用時的鏡像問題。

所需設備

步驟說明

以下是IPEVO Mirror-Cam在第三方通訊軟體中進行螢幕分享的設定步驟。

  1. 將Mirror-Cam安裝在筆電或Chromebook的鏡頭前,請看簡易設定的操作影片、或參考以下說明。
  2. 下載IPEVO Visualizer軟體到筆電,啟動軟體,接著選擇筆電鏡頭作為攝影鏡頭的來源。
  3. 將文件放在Mirror-Cam下,並於IPEVO Visualizer軟體中檢查即時影像。
  4. 使用IPEVO Visualizer軟體的「旋轉」功能內之「鏡像」功能以調整鏡像,然後文件便會按照使用者看到的樣子正確顯示在螢幕上。

  5. 可使用梯形校正功能,以數位對齊投影影像的頂部或底部。

  6. 準備就緒後,在筆電上啟動Zoom、Google Meets、Skype、Microsoft Teams、Webex或Go to Meeting等通訊軟體,以開啟或加入會議。
  7. 在第三方通訊軟體的會議視窗口中找尋「螢幕分享」按鈕。

  8. 選擇「 Visualizer」視窗。請注意,可能需在使用的第三方通訊軟體中選擇「分享應用程式視窗」。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於IPEVO
IPEVO源自於PChome Online硬體事業部門,2007年7月正式獨立。自2004年於台灣營運Skype網絡電信服務,使台灣成為Skype全球發展中最成功的市場。2005年起以IPEVO品牌推出一系列Skype專屬硬件產品,將Skype虛擬服務轉化為使用者實質經驗。IPEVO以簡單、實際且具有價值的經驗為產品目標,其簡潔俐落的產品風格呼應著IPEVO的核心思考與產品精神。目前已研發之產品包括:Skype有線USB話機、Skype無線話機、Skype會議系統、Skype視訊設備、Stand-alone免電腦Skype話機。

Scale Computing Announces HC3 Video Surveillance and Security Solutions

INDIANAPOLIS – February 2, 2021 — Scale Computing, a market leader in edge computing, virtualization, and hyperconverged solutions, is introducing a video surveillance and security solution optimized to consolidate video storage, video management and analytics workloads. Scale Computing HC3 is an IT infrastructure platform with the performance, ease of use and resilience required to support surveillance, security and IoT requirements.

Building server and storage infrastructure to support critical video surveillance needs is easy with Scale Computing HC3 Software and Hyperconverged Infrastructure Appliances. HC3 automatically handles hardware failures, making the system easy to manage from day one and easy to “scale out” to expand resources when they are needed without adding additional “islands” to manage in the process. This is a great improvement from legacy video where systems adding additional legacy server based VMS / NVR monolithic systems was expensive and time consuming.

Recent protests in Minneapolis impacted three Jerry’s Foods locations and like many businesses in the region, Jerry’s Foods experienced property damage and stolen goods. As the situation unfolded, the IT team at Jerry’s Foods wanted access to each store’s video surveillance system, but needed to move quickly. Rapid, trouble-free implementation and deployment allowed the local IT team to move the small and lightweight Scale Computing HE150 servers from one location to another in less than an hour.

“Of our affected stores, one video surveillance system was running on Scale Computing and Digital Watchdog, the other was running on Digital Watchdog without Scale Computing,” Miller said. “We were impressed when we were able to quickly and easily move servers from one location to another, but our operations team was thrilled that we were up and running and watching video from a safe location within an hour. We’re constantly blown away by the simplicity and functionality of Scale Computing HC3, especially in a moment of uncertainty. It’s safe to say, I’m sleeping better at night.”

HC3 is delivered as a family of modular building block appliances with the intelligent infrastructure software included and pre-loaded. Additional HC3 nodes can be added to expand the overall HC3 cluster pool of storage and/or compute resources as needed without adding anything new to manage, so IT and security leaders can buy the resources as needed. HC3 nodes are available with a variety of resources and capabilities from high capacity magnetic storage, low latency NVMe and flash storage, a wide range of processor and RAM configurations as well as GPU.

One of the UK’s premier suppliers of plastic packaging, M&H deployed hyperconverged infrastructure and edge computing on its video surveillance system to keep premises secure and optimise scalability. “We are super satisfied with how our Blue Iris Video Management Software runs on Scale Computing’s HC3 solution. It is secure, efficient, and fast enough to handle all of our video surveillance and we have not had any issues with it. It has truly ticked all the boxes, because of this we now have the majority of our IT equipment running on Scale Computing,” said Rob Mellor, Director of IT at M&H Plastics.

VMS Software Solutions

  • VMS software for Windows or Linux can be installed inside a HC3 virtual machine.
  • Popular VMS software tested on HC3 includes MIlestone XProtect VMS, Genetec Security Center / Omnicast, Digital Watchdog DW Spectrum, Blue Iris, Pelco VideoXPert and many others.
  • Scale Computing HC3 is Milestone Verified and listed in the Milestone Marketplace

“HC3 software is intelligent infrastructure software that runs applications reliably. As a video surveillance and security solution we offer a flexible, reliable, and secure IT platform capable of being deployed quickly, managed both locally and remotely, and has self-healing technology that reduces the overall amount of time spent on IT support and maintenance,” said Jeff Ready, CEO and co-founder, Scale Computing.

The Scale Computing Video Surveillance and Security solution is available today. For more information please visit https://www.scalecomputing.com/video-and-surveillance-infrastructure-solutions

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.