Showing posts with label 2020. Show all posts
Showing posts with label 2020. Show all posts

Saturday, July 4, 2020

ICS Attacks in Japan


ICS Attacks in Japan

Japan is well known internationally as a peaceful, well organized society where citizens obey the law and are compliant with rules across different governmental institutions. Spite of some internal problems like ageing society, sinking birthrate and now the economic consequences of the ongoing Covid-19 pandemic, Japan has done a great job into keeping its society under very traditional structures. Examples of how Japan is keeping parts of their society traditional is the banking system which continue using passbooks in order to allow the users to have records of their transactions, the existence of paper based processes in the governmental and private sector, the use of Hanko (a personal stamp used for personal/business/public documents), etc. In that traditional environment, the use of credit cards and other electronic payment methods have been introduced in the recent quinquennium without bumps in the road, like the loss of customer’s money to hackers from the Seven-Eleven Payment System 7Pay [1]. One of the factors that contribute to have such slow adoptions of electronic payment systems, for example, is the false sensation of security when it comes to transactions due to the image of safety society that Japan shows to the world [2].

It is also well known that Japanese organizations have been impacted due to different information security attacks during the last decade, being the ones that generated a great deal of media attention: the leaked of 12.6 million personal records in 2016, the previously mentioned 7Pay, etc. [3].

In addition to the dramatic increase in number of attacks due to the Covid-19 Pandemic, Japan has the same problem as other G7 countries, shortage of Cyber Security, which is projected to be around 193,000 professionals in 2020 and increasing due to Covid-19 is pushing companies to move their business online [4, 5, 6, 7].

With this increased in Security attacks, also attacks that are directed to Industrial Control Systems (ICS) have increased dramatically as well [8].  It is interesting to note that Japan has its own story of Security attacks against Industrial Control Systems (ICS), although not as abundant as US or Europe. The main officially reported incidents were (until 2017) [9]:

Year: 2005

Case Summary: Leak of atomic power plant’s confidential information via file sharing software.

Cause: Malware infection of an employee’s home PC storing confidential information.

Year: 2006

Case Summary: Leak of thermal power plant’s confidential information via file sharing software.

Cause: Malware infection of an employee’s home PC storing confidential information.

Recently, the attack against Honda’s factories indicates a new level of attack where the kinetic impact on the target was considerable [10]. IT related consequences of the attack payload were: employees were not able to use internal systems, inability to access servers, and inability to use email; while the kinetic impact of this attack was associated to halt operations in Honda’s factories located in Japan, UK, Turkey, USA and Italy [10, 11]. While there is no conclusions from the internal investigation on the attack, Honda had RDP accessible server facing the internet, which based on the analysis of Malwarebytes, there is clear evidence this could have been the attack vector used in order to compromise Honda’s IT infrastructure and cause economic losses as a potential collateral damage by the EKANS ransomware [12, 13].

Figure 1. Function responsible for performing DNS query [12]

Here are two important differences between the attack to Honda and the one to Enel:

While the ransom email is the same in both cases, here are two important differences between the attack to Honda and the one to Enel [12]:

Honda

Resolving internal domain: mds.honda.com

Exposed RDP: /AGL632956.jpn.mds.honda.com

Enel

Resolving internal domain: enelint.global

Exposed RDP: /IT000001429258.enelint.global

Interestingly enough, the same EKANS ransomware is also responsible for the attack against Edesur S.A., a company who belongs to Enel an Argentinian Electric Company, which could prove that Industrial Control Systems (ICS) became one of its main targets [12, 13, 14].

Additional screenshots of the RDP access to the specific Honda and ENEL publicly accessible servers can be found here: https://twitter.com/1ZRR4H/status/1270066266137559042?s=20

Conclusions:

  1. Japan false sensation of secured information (which comes from the false Japanese society’s sensation of security) needs to be updated in the near future in order to improve the methods and controls used to secure information across different organizations
  2. Attacks are increasing in general during the Covid-19 period, not only against company information but also against Industrial Control Systems (ICS)
  3. Reasons of the Honda and Enel attacks could vary from specific business purposes to attempts to disrupt normal operations in those specific targets
  4. Ransomware campaigns are still having great impact in organizations around the world, the more complex the organization is (with large number of assets) the more important is to have multi layer controls in place and a well-tested DR environment
  5. As the same as Stuxnet, EKANS is the newest member of a small family of highly targeted attacks against ICS infrastructure where specific entry points or payloads strategies are embedded in the malicious code
  6. EKANS differentiate itself from other ICS targeted attacks in using a more common entry points as RDP in order to deliver the malicious payload in the impacted machine/network
  7. The attack against Honda represents (based on officially reported information) the first large size ICS attack against a Japanese automaker
  8. Previous ICS related attacks against Japanese organizations were infections in company endpoints connected to user’s home internet connection
  9. Attacks originated in not secure home network environments against not-well managed or BYOD devices will increase due to ongoing Covid-19 Pandemic and the new Working from Home (WFH) company strategy
  10. Japanese organizations, of all sizes and business niches, need to see the opportunities available in their organizations to improve security methods and controls


References

[1] Another 7pay system defect left personal data of users exposed The Asahi Shimbun 

[2] Four firms with links to Japan's Defence Ministry hacked - The Straits Times

[3] 12.6 million cases of personal information leaked in Japan in 2016, survey shows - Japan Times

[4] What the Data Is Telling Us About the Current Rise in Security Threats During the COVID-19 Pandemic

[5] Cyber Security Talent Shortage in Japan - Accenture Security

[6] 71% of Security Pros See Threats Jump Since COVID-19 Outbreak - Dark Reading

[7] Addressing the Cyber Security Talent Gap - Dennis Ludena

[8] Critical infrastructure cyber attacks on the rise - EET Asia

[9] An Analysis of the Actual Status of Recent Cyberattacks on Critical Infrastructures, NEC, Matsuo Noguchi, and Hirofumi Ueda, NEC Security Research Laboratory, NEC Technical Journal, Vol. 2, 2017

[10] Honda's global operations hit by cyber-attack - BBC News

[11] ICS Threat Snake Ransomware Suspected in Honda Attack - Dark Reading

[12] Honda and Enel impacted by cyber attack suspected to be ransomware - Malwarebytes Labs

[13] EKANS Ransomware and ICS Operations - Dragos

[14] Edesur Argentina - Twitter

 



Monday, September 23, 2019

Securing organizations in large scale events



Securing organizations in large scale events

This year Japan is the host of multiple large scale sport events, the 2019 Rugby World Cup and the 2019 Volleyball World Cup, both nationwide events that will attract a significant number of fans to different cities across Japan [1, 2].

To have an idea of the magnitude of the 2019 Rugby World Cup in Japan, approximately 400 000 fans will arrive to Japan for the different matches from September 20. Online activity will have a drastic increase in Japan as well having as a reference the 2015 World Cup where over 270 million social media videos were viewed, 2.8 million official app downloads, and the hashtag #RWC2015 appeared twice a second [3].

It is predicted that the online activity in Japan will be larger than the last World Cup; moreover, Japan is in the top 10 countries with the fastest internet connection, which allows travelers and locals to exchange a vast amount of information.

Fans cheer up your team and secure your devices!

In this scenario, fans (local and travelers) should exercise standard security measures in order to protect their information, like:

  1. VPN use when connecting through publicly available Wi-Fi spots
  2. Having patched and updated all your Oss, laptops and phones
  3. As a general measure, not only for these events, users should act with caution when receiving mails with attachments and follow simple rules to avoid phishing mails [4]
  4. Download apps from trusted sources (Apple store or Google Play)
  5. Only visit sites that have https enabled [5]

Securing IoT

The Japanese government began to scan any device that is accessible through the internet, especially IoT devices, as part of their initiative to identify devices that can be victims of brute force attacks, meaning that they are still using easy-to-guess passwords or factory default passwords. Once a vulnerable device is found, the Internet Service Provider (ISP) will be contacted in order to establish communication with the end user [9, 10].

Therefore, fans, if you haven’t updated your device’s passwords, it’s time to do it. Don’t wait until you receive a notification from the company you used to get internet access in Japan.

Securing organizations in Japan

Organizations, especially the ones who have a close relationship with any event, like sponsors for example, could become target of different types of attack from various groups of attackers.

Attackers groups could vary from people trying to learn more about Security and unwillingly cause some damage to a company infrastructure, groups of people that they have different interests like: financial, political, religious, etc., that could have much more advanced tools at their disposal to launch attacks to specific organizations’ infrastructure, and of course we have Nation State attackers who belong to different Advanced Persistent Threats (APTs) grouped according to the targets they have and the tools they commonly use [6].

Although Security Professionals we cannot precisely forecast when an attack could occur, we can continuously assess the efficiency and reliability of our set of tools. There are some steps to follow in order to efficiently test the reliability of our own tools, this is a simple guide but you can make it much more detailed if required.

Understand the company lifecycle

Having a clear idea of where are the crown jewels of your organization, where the revenue is coming from, prioritized assets, Intellectual Property (IP), internal systems that support the organization is the first and foremost important step to create the scenarios together with the full understanding of the impact on the impact if one of your priority infrastructure is compromise.

a. Collect information

The Mitre ATT&CK framework is a collection of Tactics, Techniques and Procedures (TPPs) used by different attackers groups. This information is crucial to know what to test in our security systems.

Please remember that although this is a collection of all TPPs, specific groups like APT, have their own favorite set of TPPs, there is no “magic” blueprint that can be used to generalize attacks from different groups.

An additional important set of data is the threat lifecycle, also known as kill chain model, there are many variants of this, but we can use the follow high-level steps [6]:

  1. Reconnaissance
  2. Weaponization
  3. Delivery
  4. Exploitation
  5. Installation
  6. Command & Control
  7. Actions and objectives

b. Create scenarios

Together with the use of Frameworks like Mitre’s ATT&CK, detailed scenarios can be created according to the organization’s specific requirements [7].

Scenarios like controls against Phishing mail are common and well understood. More complex scenarios can be created but depends on your organization’s requirements.
Once the most relevant attack scenarios are ready is time to test them, a table top exercise could be used to understand not only the tool efficiency but also the process around them that are required in any organization independently of their size and nature.
Gaps resultants from the test are required to be discussed and remediated, then tested again and the cycle continues.

c. Special circumstances

In this moment Japanese organizations are, one way or another and in different levels, involved in the Rugby World Cup and Volleyball World Cup, especially sponsors, governmental organizations, partners, etc.

Those highly involved organizations need to put additional attention into the Security Landscape, if possible, adding Threat Intelligence to their normal security operations could improve their vantage point incrementing the resilience capacity of their installed tools.
Education for end users is, as always, the most one of the most important strategies available in any organization to improve their security posture. Constant training, simulations and exercises are a must for any organization to improve their preparedness for any potential security attack.

Conclusion

As a conclusion, organizations involved in big ticket events in Japan need to improve their security posture through testing, user’s training, focused threat intelligence and process improvement. Specially, when the Enthronement Ceremony for the new Emperor will happen on October 22 generating interest from a different group of attackers than the ones interested in sports [8].

Let's remember this is a rehearsal for the 2020 Tokyo Olympics.


References

[1] https://www.rugbyworldcup.com/
[2] http://worldcup.2019.fivb.com/en
[3] https://www.techradar.com/uk/news/tackling-cybersecurity-at-the-rugby-world-cup
[4] https://www.pandasecurity.com/mediacenter/security/10-tips-prevent-phishing-attacks/
[5] https://www.digicert.com/blog/buy-site-know-website-secure/
[6] https://www.sans.org/security-awareness-training/blog/applying-security-awareness-cyber-kill-chain
[7] https://attack.mitre.org/
[8] https://en.wikipedia.org/wiki/2019_Japanese_imperial_transition
[9] https://dennisludena.blogspot.com/2019/02/japanese-government-to-probe-insecure.html
[10] https://dennisludena.blogspot.com/2019/02/japanese-government-to-probe-insecure_26.html

Tuesday, February 26, 2019

Japanese Government to probe insecure IoT devices - Part 2



Japanese Government to probe insecure IoT devices - Part 2

The Japanese government released the technical details regarding the IoT probing devices. Here is an extract of the most important information.

Starting date: February 20, 2019.

Important Contents:

Scope of the probe:
  1. Devices that can be accessed from the Internet using IPv4 addresses assigned to the Japanese territory
  2. Easy to guess ID and password
  3. Devices without a password
  4. There are about 200 million devices that match the above mentioned scope
  5. Devices: routers, web cameras, sensors, etc.
The National Institute of Communications and Technology (NICT) is going to use an approximately a set of 100 IDs and Passwords for this investigation. Here are the samples published in the referred site [1].

Commonly used for Cyber attacks

ID Password
admin admin
admin1 admin1
root root
supervisor supervisor


Identical characters, consecutive numbers, etc.

ID Password
admin 111111
root 123456
root 666666
root 54321
888888 888888

IP addresses to be used in the investigation

150.249.227.160-175

153.231.215.8-15

153.231.216.176-183

153.231.216.184-191

153.231.216.216-223

153.231.226.160-167

153.231.226.168 to 175

153.231.227.192 ~ 199

153.231.227.208-215

153.231.227.216-223

153.231.227.224-231

(96 total)

Communication:

In the case a device is identified, a communication will be sent to the ISP/owner of the IP.


References:

1. In Japanese https://notice.go.jp/
2. In Japanese https://www.nict.go.jp/info/topics/2019/02/13-2.html



Saturday, February 16, 2019

Japanese Government to probe insecure IoT devices



Japanese Government to probe insecure IoT devices


The Japanese government passed a law in which authorized to the National Institute of Communications and Technology (NICT) to use dictionary-alike attacks to IoT devices around the nation. Basically, default passwords list, overuse ones and easy to guess passwords will be used from February 2019 against internet-discoverable devices indistinctly of being public or private. The reason of this decision is to improve preparedness for different important events coming to Japan from this year:
  1. The new emperor coronation in April, which also will change the Era name in Japan from the current one Heisei to a new one that will be decided.
  2. The Rugby World Cup from September 2019, this is consider a rehearsal for the most important even next year.
  3. Tokyo Olympics in 2020, this is the main reason behind the decision of the government to take action this year finding weak passwords in IoT devices.

Additional concerns are coming from enterprises, the reason is simple, these activities could generate alerts in enterprise infrastructures depending on their configurations and monitoring level.
Therefore enterprises are concern; since the probing activity might use the same techniques and possible tools than potential malicious actors, moreover no technical details have been shared; therefore there is no way to correctly identify and whitelist (which could lead us to a very different discussion) the “suspicious” traffic, in this case attackers could use this probing activities in order to hide in plain sight. Security teams and SOCs are concern and expecting an increase of traffic.
This activity could prove itself useful, but at the same time bad actors could potentially take advantage. From behind all perimeter defenses, hopefully enterprises are ready and well organized for this, especially since they had 4 years to improve their infrastructure, process and human resources to face these activities.

References
  1. https://www.darkreading.com/attacks-breaches/japan-authorizes-iot-hacking/d/d-id/1333745
  2. https://threatpost.com/japan-insecure-iot-devices/141304/
  3. https://www.itpro.co.uk/policy-legislation/32848/japan-law-will-allow-government-to-hack-civilian-iot-devices




The importance of Information Security in our lives – Part 6

  6. In our relaxing time In these moments even our relaxing time is related to the use of a PC or to an streaming service, we should be mor...