Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/28/2017
06:50 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

New Locky Ransomware Phishing Attacks Beat Machine Learning Tools

Late September attacks highlight the persistent nature of ransomware threats, Comodo says.

The Locky ransomware strain, initially spotted in February 2016, has emerged as one of the most dangerous examples of the highly persistent and pernicious nature of modern cyber extortion campaigns.

The operators of the malware—among the most prolific ransomware samples ever—have shown a tendency to launch brief waves of attacks, go dormant for some time and then come back with a vengeance to torment businesses and consumers.

The most recent of those waves happened in late September and appeared targeted at businesses in multiple regions including North America, Europe and Southeast Asia, security vendor Comodo said in a soon-to-be-published special report.

Comodo described the September Locky campaign as building on two previous attack waves that the vendor reported on last month (here & here). As with the earlier attacks, the latest ones too used a botnet of zombie computers distributed around the word to send highly convincing looking phishing emails to potential victims.

One of the emails used in the phishing campaign was designed to appear like a scanned document from a business printer located at the victim's organization. To lend credibility, the phishing email included a model number for a very popular Konica Minolta scanner/printer widely deployed in businesses around the world.

A second email used in the phishing campaign was spoofed to appear like a query pertaining to the status of a vendor invoice. Recipients, who were lured into opening the attachments in these emails, downloaded Locky on their systems. The average ransom amount for the decryption key tended to range between $2,000 and $4,000.

The social engineering that was used to engage victims was carefully designed to slip past malware detection tools including those using machine-learning algorithms to spot phishing emails, says Fatih Orhan, vice president, threat labs at Comodo.

The attachment in one of the emails for instance was disguised as a printer output, and it contained a script inside an archive file. "This is not enough to make a phishing detection," Orhan says.

"Machine learning algorithms need to extract the attachment, open the archive, extract the script and understand it has a malicious intent," he notes. "Usually, these scripts contain just a download component and do not have malicious intent on their own. That’s why even machine learning is not sufficient in making these kinds of detections."

Additional measures are needed to run the script dynamically and to download the actual payload, and conduct malware analysis to detect phishing, Orhan explains.

Security researchers at Comodo detected and analyzed over 110,000 Locky-related emails at customer endpoints over a three-day period between Sept. 17 and Sept. 20.

The phishing emails that purported to be printer output were sent from a total of nearly 120,000 IP addresses from 139 country code top-level domains, according to Comodo. The other phishing email that was utilized in the September Locky campaign was sent from over 12,350 IP addresses in 142 countries. In total, the IP addresses used in the September attacks were scattered across more than half of all countries in the world.

Many of the IP addresses belonged to infected computers belonging to individual consumers. But there were a fair number of systems belonging to ISPs as well, Orhan says.

Significantly, a considerable number of servers used to spread the phishing email were the same as ones used in previous campaigns. "These are mostly compromised servers as we understand," Orhan said. "The fact that they are used for multiple attacks shows there is no remediation on these servers."

Many ISPs also do not appear to have controls for spotting infected systems belonging to their customers that are being used to continuously send phishing emails over weeks.  "It's possible they don’t have real-time detection capabilities. But the attacks being continuous over weeks, shows they are incompetent in securing the network traffic they are providing," Orhan says.

Locky was one of the most widely distributed ransomware tools in 2016 and looks set to be among the most widely distributed pieces of malware this year as well. One of its most notable victims—at least publicly disclosed ones—is Hollywood Presbyterian Medical Center, which was forced to pay $17,000 to retrieve a critical database that was encrypted with the malware.

News about the latest Locky attacks comes even as Europol this week warned of ransomware eclipsing all other forms of cyber threat for the second year in a row.

"Ransomware attacks have eclipsed most other global cybercrime threats, with the first half of 2017 witnessing ransomware attacks on a scale previously unseen following the emergence of self-propagating ‘ransomworms,' " Europol said citing examples like WannaCry and Petya/NotPetya outbreaks.

Related content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Ritu_G
50%
50%
Ritu_G,
User Rank: Moderator
8/19/2018 | 11:36:02 PM
hi
This is very worrying especially when we usually think of scam scares as trivial or non-threatening at all. Just look at the fatality of their impact on hardwares and we know for sure how much caution we need to take before we are hit. We are constantly advised to update our system even if it means spending an awful lot of time to ensure a system update. Prevention is always better than cure and when it comes to technology, it is to also safeguard ourselves against a hefty amount of potential damage costs.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Google Cloud Debuts Threat-Detection Service
Robert Lemos, Contributing Writer,  9/23/2020
Shopify's Employee Data Theft Underscores Risk of Rogue Insiders
Kelly Sheridan, Staff Editor, Dark Reading,  9/23/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26120
PUBLISHED: 2020-09-27
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, which can cause image callbacks to fire even witho...
CVE-2020-26121
PUBLISHED: 2020-09-27
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an uploa...
CVE-2020-25812
PUBLISHED: 2020-09-27
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
CVE-2020-25813
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
CVE-2020-25814
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an <a> ...