Skip to content

Trojanized Mac cryptocurrency app collects wallets and screenshots, ESET Research discovers

BRATISLAVA, MONTREAL – ESET researchers have recently discovered websites distributing trojanized cryptocurrency trading applications for Mac computers. These were legitimate apps wrapped with GMERA malware, whose operators used them to steal information, such as browser cookies, cryptocurrency wallets and screen captures. In this campaign, the legitimate Kattana trading application was rebranded – including setting up copycat websites – and the malware was bundled into its installer. ESET researchers saw four names used for the trojanized app in this campaign: Cointrazer, Cupatrade, Licatrade and Trezarus.

“As in previous campaigns, the malware reports to a Command & Control server over HTTP and connects remote terminal sessions to another C&C server using a hardcoded IP address,” says ESET researcher Marc-Etienne M.Léveillé, who led the investigation into GMERA.

ESET researchers have not yet been able to find exactly where these trojanized applications are promoted. However, in March 2020, the legitimate Kattana site posted a warning suggesting that victims are approached individually to lure them to download a trojanized app, thus pointing to social engineering. Copycat websites are set up to make the bogus application download look legitimate. The download button on the bogus sites is a link to a ZIP archive containing the trojanized application bundle.

In addition to the analysis of the malware code, ESET researchers have also set up honeypots (research computers) and lured GMERA malware operators to remotely control the honeypots. The researchers’ aim was to reveal the motivations behind this group of criminals. “Based on the activity we have witnessed, we can confirm that the attackers have been collecting browser information, such as cookies and browsing history, cryptocurrency wallets and screen captures,” concludes M.Léveillé.

For more technical details on the latest GMERA malicious campaign, read the full blogpost, “Mac cryptocurrency trading application rebranded, bundled with malware,” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET discovers a chat app spying on users and leaking stolen data

BRATISLAVA – ESET researchers have discovered a new operation within a long-running cyber-espionage campaign in the Middle East, apparently with links to the threat actor group known as Gaza Hackers, or Molerats.

Instrumental in the operation is an Android app, Welcome Chat, which serves as spyware while also delivering the promised chatting functionality. The malicious website promoting and distributing the app claims to offer a secure chat platform that is available on the Google Play store. Both those claims are false; the claim of being “secure” couldn’t be further from the truth, according to ESET researchers.“

In addition to Welcome Chat being an espionage tool, its operators left the data harvested from their victims freely available on the internet. And the app was never available on the official Android app store,” says Lukáš Štefanko, the ESET researcher who conducted the analysis of Welcome Chat.

The Welcome Chat app behaves like any chat app downloaded from outside Google Play: it needs the setting “Allow installing apps from unknown sources” to be activated. After installation, it requests permission to send and view SMS messages, access files, and record audio, as well as requesting access contacts and device location. Immediately after receiving the permissions, Welcome Chat starts receiving commands from its Command and Control (C&C) server, and it uploads any harvested information. Besides chat messages, the app steals information such as sent and received SMS messages, history of calls, contact list, photos, phone call recordings and GPS location of the device.“

Unfortunately for the victims, the Welcome Chat app, including its infrastructure, was not built with security in mind. Transmitted data is not encrypted, and because of that, not only is it freely accessible to the attacker, but also to anyone on the same network,” comments Štefanko.

ESET researchers tried to establish whether Welcome Chat is an attacker-trojanized version of a clean app, or a malicious app developed from scratch. “We did our best to discover a clean version of this app, to make its developer aware of the vulnerability. But our best guess is that no such app exists. Naturally, we made no effort to reach out to the malicious actors behind the espionage operation,” explains Štefanko.

The Welcome Chat espionage app belongs to the very same Android malware family and shares infrastructure with a previously documented espionage campaign named BadPatch, which also targeted the Middle East. BadPatch has been attributed to the Gaza Hackers, aka Molerats, threat actor group. Based on this, we believe that this cyber-espionage campaign comes from the same threat actors.

While the Welcome Chat-based espionage operation seems to be narrowly targeted, ESET strongly discourages users from installing apps from outside the official Google Play store – unless it’s a trusted source, such as the website of an established security vendor or some reputable financial institution. On top of that, users should pay attention to what permissions their apps require and be suspicious of any apps that require permissions beyond their functionality – and, as a very basic security measure, users should run a reputable security app on their mobile devices.

For more details about Welcome Chat spyware, read the full blog post “Secure chat platform? Nothing could be further from the truth for Welcome Chat” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Pass-the-hash – What it is and how to protect yourself?

Every day, we hear about cyberattacks against companies of all kinds. According to the 2019 Cost of a Data Breach Report, not only did the number of data leaks rise, but its cost as well. The average cost of a data leak, in the 507 organizations surveyed, was USD 3.92 million, an increase of 1.5% over the previous year. That’s right, and investments in cybersecurity have also increased, although the growth rate is lower today, according to Gartner. 

One of the techniques used by malicious attackers is the exploitation of flaws, which allows access to sensitive data and pass-the-hash. In this article, we discuss how this technique works, as well as the business risks involved, and how the Privileged Access Management (PAM) senhasegura tool can help organizations to prevent this type of attack.

The pass-the-hash attack technique has been around since the early 1990s and remains widely used by hackers to perform attacks. Although many organizations are adequately protected against pass-the-hash attacks, many have not taken any steps to protect themselves yet. Pass-the-hash occurs when a malicious agent steals privileged credentials by compromising the device. When a malicious attacker succeeds in performing this type of attack, they can quickly obtain the password hash of a domain admin credential. Thus, when the hash is compromised, the attacker is able to move laterally within the infrastructure and thus compromise other credentials and devices.

In this case, the attack needs Social Engineering skills to make the user click on a phishing email or infect a device with malware. When detecting the problem, the user will probably call the Technical Support team. Upon responding to the user’s request, the Support agent will use a privileged credential to authenticate into the device and check the problem. At this moment, the malicious attacker stores the administrative credentials used as a hash, even when the agent remotely accesses it. That’s it! With this hash, the attacker can use it to access IT resources within the affected organization’s infrastructure. It is no coincidence that the pass-the-hash attack is one of the most common attacks in the cybersecurity market.

It is worth remembering that, although it can be performed even on Linux and Unix devices, this type of attack is more common to occur on devices with the Windows platform installed. In this environment, pass-the-hash exploits the Single Sign-On feature of some authentication protocols such as NT Lan Manager (NTLM) and Kerberos. In this case, a malicious attacker is able to obtain private SSH keys and thus authenticate themselves on devices, in addition to moving laterally. 

On Windows platforms, when a password is created on a device, it is hashed in the memory of the Security Account Manager (SAM) and Local Security Authority Subsystem (LSASS) processes. Moreover, the Credential Manager process stores a database file in Active Directory, for example. Now that we know the dynamics of pass-the-hash attacks, the question that remains is: how do you protect yourself from this type of attack?

Many organizations implement actions based on best practices to protect themselves from pass-the-hash attacks. The separation of Domain Admin accounts is one of these actions. In this way, users with administrative credentials can have a common privileged credential, but without privileged access to the network. Therefore, it is possible to use Domain Admin accounts only when necessary, reducing the attack surface. Another good practice to mitigate the risk of these attacks is to make stronger password policies for this type of account. This involves not only the complexity of passwords, but the policies for changing and accessing credentials, including the frequency for changing passwords.

After implementing these best practices, the next step is to completely remove privileged access from devices connected to the infrastructure. This is because pass-the-hash attacks only occur when using these privileged credentials. One of the ways to achieve these results is through a Privileged Access Management (PAM) solution.

According to Gartner, PAM-related technologies provide secure privileged access in order to meet business requirements (auditing, for example). This is accomplished by protecting, managing, and monitoring privileged access and accounts. In addition to the controls associated with user access, technologies linked to PAM are also able to reduce cyber risks and the attack surface through the secure storage of credential passwords, both the personal and system ones. 

Accounts stored in a PAM solution are the most critical. In this case, many Information Security policies used in organizations may provide for complex requirements for these passwords, including their frequent changes. Regulatory requirements and cybersecurity best practices require that these passwords are unknown to most people within the organization. Thus, in addition to controlling connectivity to administrative systems, the features of a PAM solution will allow the management of access, the life cycle of privileged credentials, and the audit of privileged actions performed by these credentials. Finally, passwords can be rotated by the end of the respective accesses.

The functionalities of a PAM solution such as senhasegura, which help mitigate the risks associated with pass-the-hash attacks, include:

  • Role-based access controls: it allows the implementation of the least privilege concept, which brings greater control over users’ privileges. Consequently, it is possible to reduce the risks of a range of threats. The access granularity of senhasegura simplifies the implementation of least privilege models in Linux and Windows environments.
  • Access requests based on approval workflow: senhasegura allows the invocation of administrator privileges to run applications, considering the control by lists of authorized actions. Besides, one can also protect Linux and Windows systems through the configuration of approval workflows at one or multiple levels.
  • Windows features: access to Windows Control Panel operations with administrative privileges. Also, senhasegura allows the invocation of administrator privileges to access sensitive data shared on the network, thus ensuring the security of files and directories against threats.
  • Auditing and compliance: all requests for use of administrative credentials must be recorded in session logs, allowing for greater traceability of user actions and easier auditing of privileged activities and actions. 

When it comes to cybersecurity, the different components of the infrastructure may demand different solutions involved with PAM. Thus, it is recommended to use both Privileged Account and Session Management (PASM) and Privileged Escalation and Delegation Management (PEDM) solutions. While access and credential management requirements in isolated applications can be fulfilled with PASM, critical infrastructure such as server environments are best covered with PEDM solutions. Despite being different approaches, PEDM and PASM are complementary, allowing, as a consequence, the creation of a complete, secure, and reliable solution.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

NetJapan becomes Actiphy

Tokyo – On July 1, 2020 NetJapan, A Leading Publisher Of Backup, Disaster Recovery, And Virtualization Software Becomes Actiphy, Inc

Our state-of-the-art backup, disaster recovery, and virtualization technology, has been a leading software solution for nearly a quarter century. In changing our name to Actiphy we will expand our sales network with a renewed focus on global markets.

BACKGROUND

Founded in 1996, we began developing and distributing an image-based backup software solution. Since that time, we’ve introduced a number of leading-edge technologies to the Japanese markets. Our flagship product, ActiveImage Protector has become a major system backup and disaster recovery solution in the global markets.

As the use of big data accelerates, networks evolve, malware proliferates, AI, and IoT technologies emerge, the value of data backup and recovery increases exponentially. By taking advantage of our broad range of technologies, we will continue to innovate upon our existing data protection solutions.

As we continue to take on new challenges in the development of one-of-a-kind technologies to make a difference in the world we want our new company name, Actiphy, to reflect our determination to remain ”Swift, Active and Reliable”.

NEW COMPANY NAME AND LOGO DESIGN:

  1. The Name
    Actiphy is a portmanteau of the words Active and Rectify. Active meaning “engaged in progress, motion or action” and rectify meaning to “set right or make correct.”
  2. The Logo
    The logo color refers to “Fireman” red associated with rescue and disaster recovery.。

REFERENCES

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Actiphy
Actiphy founded in 2007, focuses on developing and offering innovative backup and disaster recovery solutions for complete protection of all your systems and data. ActiveImage Protector backs up Windows, Linux machines on physical and virtual environments and restore systems and data fast for you to be up and running with minimal downtime and data loss. Today Actiphy hold 20% of the image backup market in Japan and are expanding our services in the Asia/Pacific and North American regions, as well as in Europe, the Middle East and Africa.

AV-Comparative Release 2020

On June 30th, we got certified by AV-Comparatives for our parental control software. The certification recognizes anew the capability of SafeDNS to filter out undesirable content for children, e.g., pornography, violence, and the likes.

The test was carried during the month of June against 2000 websites deemed inappropriate for kids, which resulted in a block rate of 98.5% and 0 False-Positives. The full report can be found here. This follows our constant efforts to improve and keep the highest standards for the services we offer you.

Just in case you didn’t know: SafeDNS solutions can be operated with an extensive range of devices. Similarly, SafeDNS offers a wide spectrum of web-filtering categories. Thus, should you have more questions about the installation of our software or its web-filtering categories, kindly get in touch with our support@version-2.com.hk, they’ll be glad to help.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SafeDNS
SafeDNS breathes to make the internet safer for people all over the world with solutions ranging from AI & ML-powered web filtering, cybersecurity to threat intelligence. Moreover, we strive to create the next generation of safer and more affordable web filtering products. Endlessly working to improve our users’ online protection, SafeDNS has also launched an innovative system powered by continuous machine learning and user behavior analytics to detect botnets and malicious websites.