Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Thursday, September 26, 2024

When Phishing Protections Fail, Isolate the Threat

Existing anti-phishing tech, together with training, is not getting the job done when it comes to Phishing. It is almost inevitable that someone will click a bad link leading to compromised credentials. A new approach is needed, and it is called isolation. No human firewalls are required! When a user clicks on a link in an email, it is opened in a remote cloud container, and the site’s content is streamed to the end user. Any phishing malware is blocked from getting to the machine and the site can be rendered in “read-only” mode to prevent users from handing over their credentials. This solution is available today as a component of our NetCloud SASE Solution. Peter Silva lights up how to protect users and devices from malicious links.



Tuesday, June 29, 2021

Cyberattacks at Banks and Financial Services Organizations

As part of the 2021 Application Protection Report, we looked at the top reported security incidents to the #F5 SIRT for the years 2018 through 2020. Now we’re taking a deeper dive into the reported security incidents at financial organizations, sometimes referred to as #BFSI for banking, financial services, and insurance institutions. Peter Silva starts the clock for Cyberattacks at Banks and Financial Services Organizations. Read the Report!


2021 Application Protection Report: Of Ransom and Redemption

 Now in its 4th year, the #F5Labs 2021 Application Protection Report (https://www.f5.com/labs/articles/thre...) is our effort to boil the application security risk landscape down to put the initiative back into the hands of defenders. We analyzed more than 700 data breaches from 2020. Peter Silva starts the clock for an extended edition of some the highlights from F5Labs 2021 #APR in this episode of 90 Seconds of Security.

Get your copy of the 2021 APR


Credential Stuffing Tools and Techniques

Credential stuffing is a type of cyberattack that uses credentials obtained from previous breaches to take over accounts on other web or mobile applications. This type of brute force attack relies on the fact that many people use the same usernames and passwords on multiple sites. See how attackers use #OpenBullet​ to create a Credential Stuffing attack. Let's start the clock for #CredentialStuffing Tools and Techniques including #OpenBullet in this 90 Seconds of Security episode. And learn more at F5Labs.com


F5 SIRT’s Top Reported Security Incidents, 2018-2020

The F5 Security Incident Response Team helps customers tackle security incidents in real time. In 2020, we talked about what happened in the beginning of the pandemic based on #F5 #SIRT cases. Now we're looking back at all F5 SIRT cases from the beginning of 2018 to the end of 2020 and break down what changed and what didn’t in the cyberthreat landscape because of the pandemic. So, let’s start the clock to look at SIRT’s Top Reported Security Incidents, 2018-2020. Go to the full article


Thursday, March 4, 2021

Credential Stuffing: Why It’s Here to Stay

Over the last few years, #F5​ security researchers have identified credential​ stuffing​ as one of today’s foremost threats. The value of stolen credentials has created a vicious circle: organizations suffer network intrusions in pursuit of credentials, and credential stuffing in pursuit of profits. Understanding both the supply and demand sides of the market for stolen credentials is, therefore, key to understanding the risk that cybercriminals pose to organizations today. With 5 years of data, it is definitive: credential spills are here to stay. So, let’s start the clock for some harrowing data from the 2021 Credential Stuffing Report.

Get your copy: https://www.f5.com/labs/articles/threat-intelligence/2021-credential-stuffing-report


Saturday, December 26, 2020

Phishing During a Pandemic

 #F5Labs 2020 Phishing and Fraud Report. #Phishing remains a popular method of stealing credentials, committing fraud, and distributing malware. In its crudest forms it might appear to be juvenile; but it’s often part of a well-orchestrated, multi-faceted, and sustained attack campaign by organized crime groups. Get all the details of Phishing & Fraud trends for 2020: https://www.f5.com/labs/articles/threat-intelligence/2020-phishing-and-fraud-report


How Cyber Attacks Changed During the Pandemic

 #F5 SIRT reviewed all the reported security incidents from January through August 2020 to see how the pandemic changed the cyberthreat landscape. Hint: #DDoS attacks dominated the pandemic lockdown. Learn more: https://www.f5.com/labs/articles/threat-intelligence/how-cyber-attacks-changed-during-the-pandemic

So let’s start the clock to see How Cyber Attacks Changed During the #Pandemic.


Wednesday, January 29, 2020

90 Seconds of Security: Tales from the Darknet

What happens to your data once it’s been compromised by a phishing attack or data breach? In this episode Peter Silva explores where your data goes and how much it is worth once it’s stolen in a data breach or phishing attack. If you're under attack, visit f5.com/sirt to get immediate help!




#f5Labs #90SecondsOfSecurity

Saturday, December 14, 2019

90 Seconds of Security: Phishing Trends for 2019

Phishing has become the number one attack vector for good reason - it requires a low amount of effort for a very high reward. 

F5 Labs (f5labs.com) released their 2019 Phishing and Fraud Report showing that there's no slowing down in the amount or number of phishing attacks. In fact, we expect phishing to occur year-round, not just around the holidays. Download the full report at: https://www.f5.com/labs/articles/threat-intelligence/2019-phishing-and-fraud-report


90 Seconds of Security: Breach Trends for 2019

F5 Labs Threat Intelligence team (f5labs.com) recently published their 2nd annual Application Protection Report and we take a look at some of the highlights. We cover PHP vulnerabilities, Formjacking, magecart attacks, and the relationship between breach causes and industry sectors. Get your copy at F5Labs.com

 

Tuesday, March 26, 2019

How Malware Evades Detection

Malware loves encryption since it can sneak around undetected. F5Labs 2018 Phishing & Fraud Report explains how malware tricks users and evades detection. 

Let's light up how evasion happens & get your F5 Labs 2018 Phishing & Fraud Report today.

Thursday, December 13, 2018

F5 Labs 2018 Phishing & Fraud Report

The F5 Labs 2018 Phishing & Fraud Report is out!

In this report, the F5 Labs team specifically investigated the rise of phishing and fraud during the 'holiday shopping season,' beginning in October and continuing through January. Fraud and phishing attempts increase 50% right now, from October to January and phishing was the root cause of 48% of the data breaches that F5Labs investigated. It's important to check out the report because it explains how phishing works, how to defend yourself against phishing attacks and the importance of training employees to recognize malicious emails.

Some of the crazy stats they found include 93% of phishing domains offered a secure (https) version of the site to appear more legitimate and 68% of malware sites used encryption certificates (https), meaning 68% of Command & Control servers use port 443. The crooks are going through the trouble of getting SSL certificates for their fake, but real looking sites.


Take a look at some of these. Do any of these web logins look familiar?


How about this one?

Or maybe this one?


If so then you need to check out the 2018 Phishing and Fraud report from F5 Labs because they were all fake. Attackers are getting so good at creating fake websites that impersonate the real thing, most people can’t tell the difference. One thing is for certain, employee click-through rates on phishing emails drop from 33% to 13% with security awareness training:
  • 33% — 1-5 training events
  • 28% — 6-10 training events
  • 13% — 11 or more training events
You can check out the Preview Video here and get your report at https://www.f5.com/labs


ps




Tuesday, September 27, 2016

Lock Down Your Login

Last week we talked about WebSafe and how it can help protect against phishing attacks with a little piece of code. This is important since malware can steal credentials from every visited web application from an infected machine. This time we’re going to look at how to protect against credential grabbing on a BIG-IP APM login page with WebSafe encryption layer.

You’ll need two modules for this, BIG-IP APM and of course, WebSafe Fraud Protection Service. The goal is to protect the laptop from any malware that grabs sensitive login credentials. In this case, the malware would be configured to grab the login page along with the username and password parameter fields. Command and control could also be set to retrieve any credentials from the infected machine at certain intervals, like every 5 minutes.

The first goal would be to encrypt the password. Within your BIG-IP admin GUI, you would navigate to Security>Fraud Protection Service> Anti-Fraud Profiles>URL List. APM’s logon page usually ends with ‘/my.policy’.


Create then click that URL to open the configuration page and enable Application Layer Encryption.


And select the Parameters tab to configure the fields you want to protect. In this case it is password and username.


In the screen grab, you can see ‘Obfuscate’ is selected and to both ‘Encrypt’ and ‘Substitute Value’ for the password field.

Now when the user goes to the page, a bit a JavaScript is injected in the page to protect the specified fields. If you run a httpwatch or wire shark on the page, you’ll see that the values for those parameters are obfuscated. This makes it incredibly difficult for the bad actor to determine the correct value.


And if the malware also grabs the password, since we set that to encrypt, all they get is useless information.

At this point, the BIG-IP will decrypt the password and pass on the traffic to appropriate domain controller for verification. This is a great way to protect your login credentials with BIG-IP. If you’d like to see a demonstration of this, check out F5’s Security Specialist Matthieu Dierick’s demo video. Pretty cool.

ps

Tuesday, September 20, 2016

Don’t Take the Imposter’s Bait

Phishing has been around since the dawn of the internet. The term was first used in an AOL Usenet group back in 1996 but it wasn’t until 2003 when many baited hooks and lures started dropping. Popular transaction destinations like PayPal and eBay were some of the early victims of these spoofed sites asking customers to update their personal and credit card information. By 2004, it was a full-fledged ‘get rich quick scheme’ with many financial institutions – and their customers – as targets.

Oxford Dictionary defines Phishing as, ‘The fraudulent practice of sending emails purporting to be from reputable companies in order to induce individuals to reveal personal information, such as passwords and credit card numbers.’

You’ve seen it, the almost perfect looking email with actual logos, images and links to a reputable company only to have it go to a slick looking replica complete with a login form. If you aren’t paying attention and do enter your credentials, you’ve just given a crook access to your money.

The Anti-Phishing Working Group (APWG) reports a 250 percent jump in the number of detected phishing websites between October 2015 and March 2016. More than in any other three-month span since it began tracking back in 2004. That’s around 230,000 unique phishing campaigns a month. And as recent as last week, American Express users were hit with a phishing email offering anti-phishing protection. Go figure. If you clicked the link, you were taken to a bogus Amex login page which asks for all the important stuff: SSN, DoB, mother’s maiden, AMEX number plus security code and a few other vitals.

When complete, you’ll be redirected to the authentic site so you think you’ve been there all along. That’s how they work their magic. A very similar domain URL and all the bells of the original, including the real customer service 800 number.

You can combat it however.

F5’s WebSafe Web Fraud Protection can secure your organization (and your customers) against the evolving online fraud and you do not need any special client to detect it. WebSafe inserts an obfuscated JavaScript code which can detect malware like bait, mandatory words or if the fake was loaded from a different domain. It can validate source integrity like comparing fields for multiple users and detect threats like automatic transactions. Alerts are sent to an on premise dashboard and can also be forwarded to F5’s Security Operations Center (SOC).

If you are configuring malware protection for the login and transaction pages for a financial application, it’s as simple as adding an Anti-Fraud profile to your VIP.

First, you create an anti-fraud profile:




Then indicate which URL should be watched and the action:




Then enable Phishing detection:




And when a phishing attach occurs, both the domain and the username of the victim get reported to the dashboard :




The code that’s inserted is a little piece of JavaScript added to your website to detect the malicious activity. No action is needed on the part of the user since everything is handled within BIG-IP.




This tiny piece of code will dramatically reduce fraud loss and retain the most important asset in business—customer confidence.

Don't get fooled by a faker.

ps

Related:

* Image Courtesy: makeuseof.com

Thursday, October 13, 2011

Our Identity Crisis

As as kid, my mom would constantly remind me that I was a Hawaiian Prince – a direct descendant of King Kamehameha’s grandparents and the Kekaulike (23rd Moi of Maui) line.  I was born in Hawaii but grew up on the East Coast so as a kid, I was embarrassed to be of Hawaiian Royalty since it was different from the typical ethnic groups of the New England states but that was/is Who I Am.  Of course as I got older I like being 254th in line to the Hawaiian throne…if it was still a sovereign kingdom.  Your identity is what makes you, You.  It is made up of things like, Your Family, Your history, What you say, What you know, Where you are, What you share, Who you know, Your preferences, Your choices, Your reputation, Your profession, Your biggest fears, Your greatest love and all the nuances that make each of us an individual. This information is available on the web, in profiles, contacts, email, data, documents, music, images, blogs, favorites…. Networks… you name it.  Some may confuse ‘image’ or ‘persona’ with identity.  Many celebrities have images to keep, or present a persona that they want their audience to latch to but many times, it is not their true identity and who they really are at their core. There are also certain pieces of our identity we’d also like to keep secret.  That’s the same information that the crooks want.

As we approach the holidays, this is an especially critical time to keep an eye on our information and those devices that contain our information, like our mobile devices.  You may have seen the recent commercials about making payments over your smartphone – the one where everyone pulls out their phones after dinner to pay their share and the guy with cash looks like the fool.  Huh?  I got real, crisp, green money in my hand, right from the ATM and nobody wants it.  The mobile payment infrastructure is still in the early stages but you can imagine the schemes already being hatched by those who would love to intercept those transactions. 

And speaking of crooks, did you see that 111 arrested in massive ID theft bust in New York?  Prosecutors are calling it the largest ID theft fraud case in US history.  For two years, law enforcement dug in for ‘Operation Swiper,’ which targeted a very sophisticated ID theft ring who recruited and paid restaurant workers, retail cashiers and even bank tellers to steal credit card numbers and quickly convert that data into cash.  They had everything – computers, skimmers, card readers, embossers, credit card blanks and shopping crews who went coast-to-coast buying high end merchandise while staying in 5-star hotels.  They made off with over $13 Million in less than a year and a half.

On a separate but positive note, a new Federal law was passed to protect foster children from identity theft.  This new law requires states to run credit checks on older foster children and work to resolve ID theft cases so when the child reaches adulthood, they have a clean slate.  Foster children are prime targets for and face greater risks of ID theft since their information passes through so many hands and agencies.  Most states also still use the foster child’s SSN to identify them, adding to the risk.  Many foster children enter adulthood with massive debt due to someone else leaving them with bad credit.  This law is intended to both protect against that and help those who have been victims.

And lastly, next week is the 4th annual National Protect Your Identity Week (PYIW).  Multiple Better Business Bureaus are joining several government agencies and other national advocacy organizations to offer educational workshops, free document shredding and computer recycling.  Javelin Strategy and Research noted that in 2010, 8.1 million adults were victims of identity theft resulting in the loss of $37 billion.  Plus, according to AllClear ID, children are 51 times more likely to have their identity stolen.

So as the year end festivities start heating up, don’t forget to keep an eye on you along with protecting and embracing your identity.

ps

Related:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 14, 2011

Custom Code for Targeted Attacks

Botnets?  Old school.  Spam?  So yesterday.  Phishing?  Don’t even bother…well, on second thought.  Spaghetti hacking like spaghetti marketing, toss it and see what sticks, is giving way to specific development of code (or stealing other code) to breach a particular entity.  In the past few weeks, giants like Sony, Google, Citibank, Lockheed and others have fallen victim to serious intrusions.  The latest to be added to that list: The IMF – International Monetary Fund.  IMF is an international, intergovernmental organization which oversees the global financial system.  First created to help stabilize the global economic system, they oversee exchange rates and functions to improve the economies of the member countries, which are primarily the 187 members of the UN. 

In this latest intrusion, it has been reported that this might have been the result of ‘spear phishing,’ getting someone to click a malicious but valid looking link to install malware.  The malware however was apparently developed specifically for this attack.  There was also a good amount of exploration prior to the attempt – call it spying.  So once again, while similar to other breaches where unsuspecting human involvement helped trigger the break, this one seems to be using purpose built malware.   As with any of these high-profile attacks, the techniques used to gain unauthorized access are slow to be divulged but insiders have said it was a significant breach with emails and other documents taken in this heist.  While a good portion of the recent attacks are digging for personal information, this certainly looks more like government espionage looking for sensitive information pertaining to nations.  Without directly pointing, many are fingering groups backed by foreign governments in this latest encroachment.  

A year (and longer) ago, most of these types of breaches would be kept under wraps for a while until someone leaked it.  There was a hesitation to report it due to the media coverage and public scrutiny.  Now that many of these attacks are targeting large international organizations with very sophisticated methods there seems to be a little more openness in exposing the invasion.   Hopefully this can lead to more cooperation amongst many different groups/organizations/governments to help defend against these.  Exposing the exposure also informs the general public of the potential dangers even though it might not be happening to them directly.  If an article, blog or other story helps folks be a little more cautious with whatever they are doing online, even preventing someone from simply clicking an email/social media/IM/txt link, then hopefully less people will fall victim.  Since we have Web 2.0 and Infrastructure 2.0, it might be time to adopt Hacking 2.0, except for the fact that Noah Schiffman talks about misuse and all the two-dot-oh-ness, particularly Hacking 2.0 in an article 3 years ago.  He mentions, ‘Security is a process’ and I certainly agree.  Plus I love, ‘If the term Hacking 2.0 is adopted, or even suggested, by anyone, their rights to free speech should be revoked.’  So how about Intrusion 2.0?

ps

Resources:

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, phishing, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach, rsa, lockheed, imf

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 7, 2011

Who In The World Are You?

Steven Wright has said, 'It's a small world, but I wouldn't want to paint it.' The world is getting smaller with today's 24/7 global marketplace. Businesses have offices and employees around the world to serve the needs of the organization's global customers. Those users, whether they are in a branch office, home office or mobile need access to critical information. Data like corporate information, customer information, sales information, financial information, product information and any other sources of business material is important to be able to make smart enterprise decisions. Without access to this data, poor decisions are made and the business can suffer.

The recent breaches, especially the intrusions tied to the RSA compromise, has put identity and access management in the spotlight.  Once upon a time, users had to be in the office connected to the network to access corporate applications. IT organizations probably knew the user was since they were sitting at a desk; organizations knew the type of device since it was issued by IT and the business applications were delivered quickly and securely since it was from an internal local area network. Then, users needed access to that same information while they were away from the office and solutions like VPNs and Remote Access quickly gained acceptance. As adoption grew, so did requests for access above and beyond the normal employee. Soon partners, contractors, vendors and other 3rd party ecosystems were given access to corporate resources. Employees and partners from around the globe were connecting from a barrage of networks, carriers and devices. This can be very risky since IT might not know the identity of those users.

imageAnonymous networks allow users to gain access to systems via a User ID and password but they cannot decipher exactly who the user actually is; an employee, guest, contractor, partner and the like. Anonymous networks do have visibility at the IP or MAC address level but that information does not equate to a user's identity. Since these networks are unable to attribute IP to identity, the risk is that information may be available to users who are not authorized to see it. There is also no reporting as to what was accessed or where a specific user has navigated within a system. Unauthorized access to systems is a huge concern for companies, not only pertaining to the disclosure and loss of confidential company data but the potential risks to regulatory compliance and public criticism. It is important that only authenticated users gain admission and that they only access the resources they are authorized to see.  Controlling and managing access to system resources must be based on identity. A user's identity, or their expressed or digitally represented identity can include identifiers like: what you say, what you know, where you are, what you share, who you know, your preferences, your choices, your reputation, your profession or any other combination that is unique to the user. 

Access can mean different things - access to an intranet web application to search for materials, access to MS Exchange for email, access to virtualized Citrix, VMware or Remote Desktop deployments, access to a particular network segment for files and full domain network access as if the user is sitting in the office. The resources themselves can be in multiple locations, corporate headquarters, the data center, at a branch office, in the cloud or a mix of them all.  When users are all over the world, globally distributed access across several data centers can help solve access and availability requirements. Organizations also need their application and access security solution in the strategic point of control, a centralized location at the intersection between the users and their resources to make those intelligent, contextual, identity based decisions on how to handle access requests.

Residing in this important strategic point of control within the network, the BIG-IP Access Policy Manager (APM) for BIG-IP Local Traffic Manager (LTM) along with BIG-IP Edge Gateway (EGW) provide the security, scalability and optimization that's required for unified global access to corporate resources for all types of deployment environments. The ability to converge and consolidate remote users, LAN access and wireless junctions on a single management interface and provide easy-to-manage access policies saves money and frees up valuable IT resources. F5's access solutions secures your infrastructure, creating a place within the network to provide security, scalability, optimization, flexibility, context, resource control, policy management, reporting and availability for all applications.

ps

Resources:

Technorati Tags: psilva, F5, context-aware, infrastructure, IP, security, application security, access control, virtualization, network, application delivery, unified application delivery and data services

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Friday, December 17, 2010

e-card Malware

I’ve gotten some e-cards this holiday season from organizations that I know, and you might even receive one from F5.  I just wanted to post a short reminder to be careful of these, especially if you get one from someone you don’t know.  This is, and has been for several years, one of cybercriminals favorite ways of distributing malware, infecting your computer and stealing your info.  Usually, the e-card arrives in your email with a link to view it online.  Once you click that link and visit the purported e-card site, you can become infected.  In fact, if you get one and don’t know the sender at all, I’d delete it right away.  Often you don’t need to visit a site to get infected since the payload might in the email itself.

The Better Business Bureau is also warning of another phishing scam with cybercriminals masquerading as a shipping company.  You’ll get an email with a tracking number in the subject line.  The note says that the package could not be delivered and asks the user to print the attached document.  At that point, if you do open the attachment, then a virus is installed on your computer.  There have also been charitable giving scams, coupon code scams, too good to be true sale scams and other rip-offs to swindle you of your money and sensitive info.

You might be thinking, ‘ahh, geeze – not another,’ but this is the time of year those cybercriminals like to prey on people’s holiday spirit and general preoccupation with with other things festive.  Keep anti-virus updated, use a firewall, be suspicious, use common sense and enjoy the holidays.

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach