Loading summary
Dave Buettner
You're listening to the CyberWire network, powered by N2K. Hey everybody, Dave here. I want to talk about our sponsor, LegalZoom. You know I started my first business back in the early 90s and oh what I would have done to have been able to have the services of an organization like LegalZoom back then. Just getting all of those business ducks in a row. All of that technical stuff, the legal stuff, the registrations of the business, the taxes, all of those things that you need to go through when you're starting a business, the hard stuff, the stuff that sucks up your time when you just want to get that business launched and out there. Well, LegalZoom has everything you need to launch, run and protect your business all in one place and they save you from wasting hours making sense of all that legal stuff. Launch, run and protect your business. To make it Official today@legalzoom.com you can use promo code CYBER10 to get 10% off any LegalZoom business information product, excluding subscriptions and renewals that expires at the end of this year. Get everything you need from set up to success@legalzoom.com and use promo code CYBER10. That's legalzoom.com and promo code CYBER10. Legalzoom provides access to independent attorneys and self service tools. Legalzoom is not a law firm and does not provide legal advice except where authorized through its subsidiary law firm, LZ Legal Services LLC. Pundits predict Trump will overhaul US cybersecurity Policy experts examine escalating cybersecurity threats facing the US energy sector. Palo Alto Network's patches apparently zero days, Akira and SafePay ransomware groups claim dozens of new victims. A major pharmacy group is pressured to pay a $1.3 million ransomware installment. Threat actors are exploiting Spotify playlists and podcasts. An alleged Phobos ransomware admin has been extradited to the US rapper Razzle Khan gets 18 months in prison for her part in the Bitfinex cryptocurrency hack. On today's threat vector, David Moulton speaks with Asaf Dahan, director of threat research at Palo Alto Network's Cortex Team, about the rising cyber threat from North Korea and Swiss scammers send snail mail. It's Tuesday, January 19th, 2024. I'm Dave Buettner and this is your Cyberwire intel briefing. A second Trump administration is expected to overhaul U.S. cybersecurity policy, prioritizing business interests, aggressive offensive measures and deregulation over the Biden era of focus on corporate accountability spyware restrictions and AI safeguards In an article for Wired, Eric Geller writes that Trump is likely to dismantle Biden's regulatory efforts on critical infrastructure cybersecurity, citing industry burdens. Rules impacting rail, aviation and water systems could be scrapped or weakened with a shift toward voluntary compliance and incentives. Efforts like CISA's disinformation campaigns and AI safety initiatives focused on societal harms may also end, reflecting Trump's emphasis on free speech and reduced regulation. Spyware policies are expected to favor market growth over human rights concerns, benefiting firms like NSO Group. AI regulations requiring transparency and safety measures may be repealed, favoring innovation over safeguards. Trump is poised to expand military cyber operations, emphasizing accountability for Chinese and Russian cyberattacks. Cyber command could see enhanced roles, including potentially forming a separate military cyber branch. Policies blocking Chinese tech could also resurface. Initiatives pushing companies to design secure software and accept liability for vulnerabilities may stall, while slogans like secure by design may persist. New regulations are unlikely, reflecting the administration's alignment with corporate interests. CISA's Cybersecurity Incident Reporting rules could be scaled back, exempting sectors or limiting required disclosures. Ultimately, Trump's cybersecurity agenda may favor deregulation and military action while sidelining corporate accountability, spyware restrictions and emerging AI safety policies. In an editorial for cyberscoop, Sachin Bansal, president of Security Scorecard, and Brian Harrell, former assistant secretary for infrastructure protection at the Department of Homeland Security, say the US Energy sector faces escalating cybersecurity threats as it integrates complex supply chains, clean energy technologies and digital systems. National Security Advisor Jake Sullivan recently highlighted the critical need for supply chain security as vulnerabilities in software and third party vendors present significant risks to vital infrastructure. A KPMG report revealed that third party risk accounts for 45% of breaches in the sector, compared to a global average of 29%. The shift to greener, software driven energy grids introduces additional risks, with renewable energy companies scoring lowest on cybersecurity metrics. Coupled with the potential for foreign exploitation, particularly by China, these factors underscore the urgency of a unified strategy. Efforts to enhance resilience include the Department of Energy's supply chain cybersecurity principles, supported by major firms like ge, Vernova and Siemens. Regulators such as the Federal Energy Regulatory Commission are revising standards to address supply chain risks. Meanwhile, the White House is exploring cybersecurity ratings for infrastructure sectors. However, challenges remain. Attacks such as the Colonial Pipeline ransomware incident show how breaches in IT systems disrupt operations. Utilities struggle with the resources and expertise to counter growing threats, the authors say. A collective effort between government and industry is vital to secure every link in the supply chain. By adopting consistent frameworks, measuring progress and fostering transparency, the energy sector can bolster cybersecurity resilience, safeguarding critical infrastructure and global stability. Palo Alto Networks has patched two zero day vulnerabilities exploited in Operation Lunar Peak. The first is a critical authentication bypass flaw allowing attackers to gain admin access via the Pan OS management interface. The second is a privilege escalation issue enabling root access. These vulnerabilities targeted exposed firewall management interfaces and have been addressed in Pan OS updates. CISA has added the flaws to its known exploited Vulnerabilities catalog, urging fixes by December 9 to mitigate risks. The SafePay cybercrime operation, a new ransomware group deploying Lockbit based malware, has claimed 22 victims as of November of this year, according to Huntress. The group exploits Remote desktop protocol access to encrypt files and exfiltrate data. SafePay's ransomware is derived from a well documented lockbit variant and incorporates tactics from other groups like alfv, blackcat, including UAC bypasses and Living off the Land binaries for privilege escalation. Huntress identified vulnerabilities in SafePay's Tor site, enabling deeper insights into its operations. SafePay employs tools like WinRAR for archiving stolen data and FileZilla for file transfers, often uninstalling them afterward to cover their tracks. The ransomware includes a Cyrillic language based kill switch to avoid attacks in the Commonwealth of Independent States countries. Meanwhile, the Akira Ransomware group leaked data from 32 new victims in a single day last week, according to Cyber Int. Active Since March of 2023, Akira operates as a ransomware as a service and has impacted over 350 organizations globally, earning an estimated $42 million targeting business services, critical infrastructure and other sectors. Akira primarily focuses on U S based organizations, but also attacks entities in Canada, Europe and beyond. Cyber Int reports that most victims were directly added to Akira's leaks sections on its Tor site, bypassing the usual news section. This aggressive activity, which aligns with trends of escalating ransomware operations, mirrors similar mass victim disclosures by groups like Lockbit. Akira's rapid growth and record breaking victim counts indicate its expanding influence in the global cybercrime ecosystem. The Embargo Ransomware group is pressuring American Associated Pharmacies to pay a second $1.3 million installment of an alleged 2.6 million doll ransomware deal after already receiving the first payment. The group, which claims to have stolen one and a half terabytes of data, has threatened to leak the information by midweek if the payment isn't made. Embargo accuses AAP of prioritizing system restoration over customer data protection. Embargo's tactics include double extortion, a common strategy among ransomware gangs, researchers note. Embargo targets various sectors worldwide and has increasingly targeted health care, including Georgia's Memorial Hospital and Manor. Embargo, which surfaced this year, denies political affiliations, focusing instead on opportunistic attacks. Experts warn of potential class action suits and growing risks without stronger privacy laws. To deter such cybercrime threat, actors are exploiting Spotify playlists and podcasts to promote pirated software, game cheats, spam links and dubious websites, leveraging Spotify's strong reputation and SEO presence to boost visibility. Using targeted keywords and links in titles and descriptions, scammers direct users to malware laden sites or fake surveys. Some playlists, like one advertising a Sony Vegas Pro crack and Spammy podcasts, use synthesized speech to lure users into clicking links, leading to ad heavy or malicious sites. These tactics extend to promoting game cheats and pirated ebooks. Cybercriminals often exploit third party podcast distribution services to bypass platform safeguards. Spotify has removed some flagged content and emphasized its rules against malicious practices, but the challenge of combating such spam campaigns persists. Russian national Evgeny Sitsyn, age 42, has been extradited to the US to face charges related to administrating the Phobos ransomware, according to the Department of Justice. Accused of running a ransomware as a Service Scheme since 2020, sits in allegedly developed and sold Phobos ransomware to affiliates who targeted over 1,000 victims worldwide, including schools and hospitals, extorting over $16 million. Affiliates used stolen credentials to encrypt and exfiltrate data, pressuring victims to pay ransom. Sitsen faces up to 120 years in prison if convicted. Heather Razalkan Morgan, a self proclaimed rapper and entrepreneur, was sentenced to 18 months in prison for assisting her husband, Ilya Lichtenstein, in laundering Bitcoin stolen during the infamous 2016 Bitfinex cryptocurrency hack. Liechtenstein, who received a five year sentence, stole over 119,000 Bitcoin worth $71 million then and now, valued at $10.8 billion. Morgan, aware of the fund's illicit origins since 2020, helped conceal them through financial accounts, virtual currency exchanges and mixers like Bitcoin Fog. Prosecutors recommended leniency, citing her clean record and limited personal gain. Coming up after the break. Today's Threat Vector David Moulton speaks with Asaf Dahan about the rising cyber threat from North Korea. Stay with us. And now a word from our sponsor, Know before it's all connected and we're not talking conspiracy theories when it comes to infosec tools, effective integrations can make or break your security stack. The same should be true for security awareness training. KnowBe4, provider of the world's largest library of security awareness training, provides a way to integrate your existing security stack tools to help you strengthen your organization's security culture. KnowBe4's security coach uses standard APIs to quickly and easily integrate with your existing security products from vendors like Microsoft, CrowdStrike and Cisco. 35 vendor integrations and Counting Security Coach analyzes your security stack alerts to identify events related to any risky security behavior from your users. Use this information to set up real time coaching campaigns targeting risky users based on those events from your network, endpoint identity or web security vendors. Then coach your users at the moment the risky behavior occurs, with contextual security tips delivered via Microsoft Teams, Slack or email. Learn more@knowbefore.com SecurityCoach that's knowbefore.com SecurityCoach and we thank KnowBe4 for sponsoring our show. Do you know the status of your compliance controls right now? Like right now, we know that real time visibility is critical for security, but when it comes to our GRC programs, we rely on point in time checks. But get this, more than 8,000 companies like Atlassian and Quora have continuous visibility into their controls with Vanta. Here's the Vanta brings automation to evidence collection across 30 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting, and helps you get security questionnaires done five times faster with AI. Now that's a new way to GRC. Get $1,000 off Vanta when you go to vanta.com cyber that's vanta.com cyber for $1,000 off. On today's segment from the Threat Vector, podcast host David Moulton speaks with Asaf Dahan, director of Threat Research at Palo Alto Network's Cortex Team. They're discussing the rising cyber threat from North Korea.
Asaf Dahan
North Korean threat actors are not script kitties. They are a major cyber force to be reckoned with, and the global reach of their cyber operations should be taken very seriously not just by governments or government affiliated organizations, but it crosses many industries and regions. The financial motivation of the North Korean threat actors that really sets them apart from other nation state threat actors and that aspect makes them more relevant to more organizations worldwide.
David Moulton
Welcome to Threat Vector, the Palo Alto Networks podcast where we discuss pressing cybersecurity threats and resilience and uncover insights into the latest industry trends. I'm your host, David Moulton, Director of Thought Leadership. Today I'm Speaking with Asaf DeHaan, Director of Threat Research at Palo Alto Network's Cortex team. Assaf is a seasoned cybersecurity expert with over 18 years and experience in both military and civilian domains. Throughout his career, Asaf has worn many hats, from malware analyst to threat hunter to team leader and director, working with top tier security companies and contributing to a variety of international security conferences. His experience spans across malware analysis, reverse engineering, threat hunting, threat intelligence, red teaming and application security, giving him a well rounded perspective on the ever evolving cybersecurity landscape. Currently leading the threat research for Cortex A, Saff's works focuses on providing insights into some of the most sophisticated cyber threats, including those coming from state sponsored actors like North Korea. AsAFTA Han, welcome to Threat Vector. I'm really excited to have you here today.
Asaf Dahan
Thanks for having me. I'm really happy to be here.
David Moulton
Today we're going to be talking about some of the research you and your team have done on North Korean threat actors that have shown up consistently in the news. From your research, what makes North Korean hackers such a formidable force on the global cyber landscape?
Asaf Dahan
That's an excellent question, David. So when we talk about major players in global cybersecurity, North Korea might not be the first nation that comes to mind, right? But over the last decade or so, they've really earned their spot in what we might call the hall of fame or of nation states actors. And let me tell you, their rise to cyber, I guess prominence, is a fascinating story for me at least. The pivotal year was 2014 and what became known as the Sony Pictures hack. So to those of you who maybe not be as Familiar, back in 2014, Sony was about to release the interview Seth Rogen parody with, I guess, about the assassination of the North Korean leader Kim Jong Un. And as you might imagine, North Korea wasn't exactly thrilled about this premise. And their response was a devastating cyber attack that caused a massive financial and reputational damage to Sony Pictures, ultimately forcing them to to cancel the movie's theatrical release. And this was, at least for me, it was one of North Korea's first true cyber, how shall I say, tour de force and perhaps a trailer for what's to come. And in the following years, we started observing the formation of a more, I guess, cohesive or coherent cyber warfare strategy. Less vendetta, motivated, if you will, but like something more robust. You can feel that there's a strategy, and a crucial part of this strategy really revolves around financial gain and generating revenue through cybercrime. You have to remember North Korea is a very impoverished country. It's under a lot of embargoes and sanctions. So for instance, in 2016, they attempted what could have been possibly one of the largest bank heists in history, and they targeted the Bangladeshi central bank. And their goal was to get away with $1 billion. And this is where it gets kind of comical. Their entire operation was nearly successful, but it was ultimately foiled due to a typo that raised flags in the banking system. So if you want to talk about a billion dollar spelling mistake, right, so they did manage to get away, I think, with $80 million, I think, and the bank was able to retrieve it at some point. But in later years, we've seen this trend of going directly after banks and conducting bank heists in other parts of the world quite as part of their strategy. Some of them were more successful, some were not as successful. But we've seen this direction pitting or targeting of banks.
David Moulton
Asafa, with your background on both the offensive and defensive sides of cybersecurity, what do you think the key human factors are that make defending against North Korean hackers so challenging?
Asaf Dahan
Well, I guess if we're talking about human factor, I always say, and based on my experiences, that the human factor or the human Lync is the weakest link in the chain of cybersecurity. You can have the best products out there, but it only takes a certain individual to click on a link, open an attachment, reveal to a caller the password for their okta, you know, because these things happen all the time. So the human factor here, when it comes to social engineering is. Is crucial because the technology that we have today especially I can speak about Palo Alto, but in general, we see it across other vendors as well. The technology is great. We are able to detect and prevent a lot of the stuff that we're seeing. But the one thing that is still very challenging is the human aspect of cybersecurity attacks. And that is usually has to do with social engineering. And the only thing to, I guess, fight it is by raising awareness, doing a lot of social engineering trainings. And also maybe with the introduction of new technologies such as LLMs, which can also worsen some aspects of social engineering because they can come off as very convincing. But on the flip side, you can use LLMs and Genet AI technology for defensive purposes as well. So it's going to be interesting. But if I had to put my money on this is really combating social engineering attacks. The rest the technology is quite good at detecting and preventing asaf thanks for.
David Moulton
A great conversation today. I really appreciate you diving into some of the insights on the North Korean threat actors that you and your team have been researching and publishing on and unpacking some of the forces behind their cyber activities.
Asaf Dahan
Thank you so much David. I had a great pleasure. I had a blast. Thanks for having me.
David Moulton
Thanks for listening to this segment of the Threat Vector Podcast. If you want to hear the whole conversation, you can find the show in your podcast player. Just search for Threat Vector by Palo Alto Network Networks each week I interview leaders from across our industry and from Palo Alto Networks to get their insights on cybersecurity, the threat landscape, and the constant changes we face. See you there.
Dave Buettner
Be sure to check out the complete Threat Vector Podcast right here on the N2K CyberWire network or wherever you get your podcasts. And now a word from our sponsor, NordPass. NordPass is an advanced password manager from the team behind NordVPN, designed to help keep your business safe from data leaks and cyber threats. It gives your IT professionals control over who has access to your company's data and makes it easy for everyone else on your team to use strong passwords. Right now you can go to www.nordpass.com cyberwire for 35% off the NordPass business yearly plan. Don't miss out on that. And finally, in a twist straight out of a cybercrime time machine, hackers in Switzerland are using snail mail with actual paper letters and stamps to deliver malware. The Swiss National Cybersecurity center revealed that scammers are posing as Mateo Swiss the Federal Meteorology Office, and sending fake weather alert letters with QR codes. Scan the code and instead of staying dry, you'll download malware named Cooper. Designed to pilfer sensitive data from Android devices. The fraudulent letters mimic official apps to exploit trust, catching victims off guard. Experts warn that while most of us have a healthy skepticism for digital phishing attempts, we're less suspicious of old school postal scams. Fortunately, this throwback hack targets only Android users in Switzerland, so iPhone owners can relax for now. I can only imagine that the next stop on this nostalgia train could be telegrams Dear Victim, kindly scan this code to ruin your life. Stop. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at@the cyberwire.com we'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com we're privileged that N2K Cyberwire is part of the daily routine of the most influential leaders and operators in the public and private sector. From the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies, N2K makes it easy for companies to optimize your biggest investment your people. We make you smarter about your teams while making your team smarter. Learn how@n2k.com this episode was produced by Liz Stokes. Our mixer is Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Iban. Our executive editor is Brandon Karp. Simone Petrella is our president, Peter Kilpie is our publisher and I'm Dave Buettner. Thanks for listening. We'll see you back here tomorrow. The IT world used to be simpler. You only had to secure and manage environments that you controlled. Then came new technologies and new ways to work. Now employees, apps and networks are everywhere. This means poor visibility, security gaps, and added risk. That's why Cloudflare created the first ever connectivity cloud. Visit cloudflare.com to protect your business Everywhere you do business.
CyberWire Daily: “Biden vs. Trump: A Tale of Two Cybersecurity Strategies”
Released on November 19, 2024
Host/Author: N2K Networks
Introduction
In this episode of CyberWire Daily, N2K Networks delves into the contrasting cybersecurity strategies of former President Donald Trump and current President Joe Biden. The discussion navigates through policy shifts, emerging threats, and the evolving landscape of cyber defense in the United States. Additionally, the episode covers significant cybersecurity incidents, updates on ransomware activities, and an in-depth interview with Asaf Dahan from Palo Alto Networks on North Korean cyber threats.
The episode opens with an analysis of the anticipated overhaul of U.S. cybersecurity policy under a potential second Trump administration. Drawing insights from Eric Geller’s article in Wired, the discussion highlights how Trump's approach is set to prioritize business interests, aggressive offensive measures, and deregulation. This stands in stark contrast to Biden's focus on corporate accountability, spyware restrictions, and AI safeguards.
Key Points:
Regulatory Changes: Trump is expected to dismantle Biden-era regulations on critical infrastructure cybersecurity, citing industry burdens. This includes weakening rules affecting rail, aviation, and water systems, shifting towards voluntary compliance and incentives.
“Trump is poised to expand military cyber operations, emphasizing accountability for Chinese and Russian cyberattacks.”
— Eric Geller, Wired
Spyware and AI Policies: Under Trump, spyware regulations are likely to favor market growth over human rights, benefiting firms like NSO Group. AI regulations requiring transparency and safety measures may be repealed to encourage innovation.
Military Cyber Operations: Expectation of enhanced roles for Cyber Command, potentially forming a separate military cyber branch to counteract adversarial cyber activities more effectively.
Corporate vs. Military Focus: The Trump administration may deprioritize corporate accountability and AI safety in favor of military-led cyber initiatives, aligning more closely with corporate interests and reducing overall regulatory oversight.
An editorial from Cyberscoop by Sachin Bansal and Brian Harrell emphasizes the increasing cybersecurity threats faced by the U.S. energy sector. As the sector integrates complex supply chains, clean energy technologies, and digital systems, vulnerabilities proliferate, particularly through third-party vendors.
Key Insights:
Third-Party Risks: A KPMG report reveals that third-party risk accounts for 45% of breaches in the energy sector, significantly higher than the global average of 29%.
“The shift to greener, software-driven energy grids introduces additional risks, with renewable energy companies scoring lowest on cybersecurity metrics.”
— Sachin Bansal & Brian Harrell, Cyberscoop
Regulatory Responses: Initiatives by the Department of Energy and the Federal Energy Regulatory Commission aim to enhance supply chain security through revised standards and cybersecurity principles.
Resilience Building: Emphasis on government-industry collaboration to secure the supply chain, adopting consistent frameworks, and fostering transparency to bolster cybersecurity resilience.
Palo Alto Networks has patched two significant zero-day vulnerabilities exploited in Operation Lunar Peak. These vulnerabilities pertain to:
The Cybersecurity and Infrastructure Security Agency (CISA) has added these flaws to its Known Exploited Vulnerabilities catalog, urging organizations to apply the necessary fixes by December 9.
The ransomware landscape continues to evolve with several active groups intensifying their operations:
SafePay Ransomware Group:
Akira Ransomware Group:
Embargo Ransomware Group:
Cybercriminals are leveraging Spotify's platform to disseminate malware through playlists and podcasts. By embedding QR codes and malicious links within titles and descriptions, scammers direct users to malware-laden sites or fake surveys. These tactics include promoting pirated software, game cheats, and ebooks.
Mitigation Efforts:
Significant legal actions highlight the ongoing battle against cybercrime:
Extradition of Evgeny Sitsyn:
Sentencing of Heather Razalkan Morgan:
A significant portion of the episode features an in-depth interview with Asaf Dahan, Director of Threat Research at Palo Alto Networks' Cortex Team, hosted by David Moulton.
Key Discussion Points:
North Korean Cyber Operations:
Historical Context: The 2014 Sony Pictures hack marked North Korea's entry into high-profile cyber attacks, driven by both political motives and financial gain.
“North Korean threat actors are not script kiddies. They are a major cyber force to be reckoned with...”
— Asaf Dahan [17:31]
Financial Motivation: Unlike other nation-state actors primarily driven by espionage or sabotage, North Korean hackers are significantly motivated by financial gain to support the impoverished nation under extensive sanctions.
“The financial motivation of the North Korean threat actors that really sets them apart... makes them more relevant to more organizations worldwide.”
— Asaf Dahan [17:31]
Notable Operations:
Strategic Evolution: Over the years, North Korea has developed a more cohesive cyber warfare strategy, focusing on bank heists and financial cybercrimes to generate revenue.
Defensive Challenges:
Human Factor: Asaf emphasizes that human behavior remains the weakest link in cybersecurity defenses, with social engineering being a primary method of attack.
“The technology is great... but the one thing that is still very challenging is the human aspect of cybersecurity attacks.”
— Asaf Dahan [23:06]
Mitigation Strategies: Raising awareness, conducting extensive social engineering training, and leveraging technologies like Large Language Models (LLMs) and Generative AI for both offensive and defensive purposes.
Conclusion of Interview: David and Asaf underscore the importance of understanding the multifaceted nature of North Korean cyber threats, emphasizing that combating these sophisticated actors requires both technological solutions and robust human-centric defenses.
Closing Remarks
The episode concludes by highlighting emerging cyber threats, including the use of traditional mail for malware distribution in Switzerland and legal assurances for iPhone users against certain scams. The CyberWire Daily stresses the importance of continuous vigilance and adaptive strategies in the face of evolving cyber threats.
Notable Quotes:
“North Korean threat actors are not script kiddies. They are a major cyber force to be reckoned with...”
— Asaf Dahan [17:31]
“The technology is great... but the one thing that is still very challenging is the human aspect of cybersecurity attacks.”
— Asaf Dahan [23:06]
Final Notes
For a comprehensive understanding of the discussed topics, including the full Threat Vector interview, listeners are encouraged to access the complete episode through their preferred podcast platforms or visit CyberWire Daily.