Tag Archive for: rare

Infoblox discovers rare Decoy Dog C2 exploit


Domain security firm Infoblox discovered a command-and-control exploit that, while extremely rare and complex, could be a warning growl from a new, as-yet anonymous state actor.

Illustrated rat wearing sunglasses in front of a blue background
Image: andrenascimento/Adobe Stock

If you do a search for the most recent reports on Domain Name System attacks, you may have a hard time finding one since IDC’s 2021 report noting that in 2020, 87% of organizations experienced a DNS attack during 2020.

The fact that DNS isn’t front-of-mind nomenclature for many attacks that actually put DNS in the attack chain may have to do with the security alphabet soup of DNS over TLS or HTTP. As a CloudFlare report explains, TLS and HTTP encrypt plaintext DNS queries, keeping browsing secure and private.

SEE: Google’s 2FA may lack encryption, meaning unlocked doors to mobile devices

Still, Akamai’s Q3 DNS threat report noted a 40% increase in DNS attacks in that quarter last year, and 14% of all protected devices communicated with a malicious designation at least once in the third quarter last year.

Jump to:

Infoblox Threat Intelligence Group, which says it analyzes billions of DNS records and millions of domain-related records each day, has reported a new malware toolkit called Decoy Dog that uses a remote access trojan called Pupy.

Renée Burton, senior director threat intelligence at Infoblox, said Pupy is an open-source product that is very difficult to use and not well documented. Infoblox found that the Decoy Dog toolkit that uses Pupy in fewer than 3% of all networks, and that the threat actor who has control of Decoy Dog is connected to just 18 domains.

“We discovered it through our series of anomaly detectors and learned that Decoy Dog activities have been operating a data exfiltration command and control, or C2, system for over a year, starting early April 2022,” Burton said. “Nobody else knew.”

Russian hound

When Infoblox analyzed the queries in external global DNS data, the firm’s researchers found that the Decoy Dog C2 originated almost exclusively from hosts in Russia.

“One of the main dangers is nobody knows what it is,” Burton said. “That means something is compromised and someone…

Source…

Ransomware Attacks: Why Case Studies Provide Rare Learning Opportunities


The United States suffered a staggering 421.5 million ransomware attempts in 2021, a 98% increase from 2020. Those figures come from United States Senate Committee on Homeland Security and Governmental Affairs staff report titled “America’s Data Held Hostage: Case Studies in Ransomware Attacks on American Companies.”

The report details three companies’ experiences responding to attacks by Russia-based ransomware group REvil. The companies varied in size and industry but their previously established incident response plans in place helped mitigate the damage from the attacks.  However, the companies reported receiving little assistance from the Federal Government, highlighting the need for change at the federal level to better combat future attacks.

The report provides a comprehensive overview of ransomware’s state of play but the three case studies on anonymous companies’ reactions to ransomware attacks provides the freshest insight. The companies ranged from a Fortune 500 company with over 100,000 employees to a technology firm with approximately 50 employees.  Each had an incident response plan and various cybersecurity measures in place that helped mitigate the effects but to different levels of success.  Offline backups were uniformly hailed as one of the best defense measures each had in place to keep their company running while addressing the attacks but they all acknowledged at the attacks’ conclusions that they needed to address gaps in their plans and security that the attacks uncovered.

One of the companies did not need the government’s help responding to the ransomware attack but the two others reported little help from the government despite seeking its assistance.  Not surprisingly, the FBI continues to focus its efforts on its core law enforcement mission by identifying the bad actors and bringing them to justice, rather than proactively protecting and assisting victim companies.

Cybersecurity Incident Reporting: Time for FBI and CISA Reforms?

The Committee made seven recommendations in its report based on its investigation, three of which called for reform in the government:

  1. The Cybersecurity and…

Source…

Researchers Discover Rare Form of Malware that Targets VoIP Softswitches – Infosecurity Magazine

Researchers Discover Rare Form of Malware that Targets VoIP Softswitches  Infosecurity Magazine
“malware news” – read more

Senator Thom Tillis Seems Really Pissed Off That The Internet Archive Bought A Record Store To Make Rare Recordings Accessible

Senator Thom Tillis (or perhaps some staffer in his office who is desperate for a job as a legacy copyright industry lobbyist in his next job) really seems to have it in for the Internet Archive. Beyond trying to rewrite copyright law to make it favor the legacy players even more than it already does, and beyond telling copyright experts that they shouldn’t even dare think of commenting on the state of copyright law today, Tillis really seems to have an infatuation with the Internet Archive wanting to help people by providing them information. I don’t know what the library ever did to Tillis as a child, but as a Senator he sure seems to hate the very concept. He sent one very confused, misinformed, and angry letter to the Internet Archive over its National Emergency Library, and now he’s sent another one after news broke that the Archive had purchased the distressed, but famed, Bop Street Records in Seattle.

When the news originally broke that the Archive had purchased Bop Street, most portrayed it as great news. The owner, Dave Vorhees, had decided to shut down the shop a month earlier, and he wasn’t sure if he’d be able to sell off the 500,000 recordings the store held. So people were excited that the Archive stepped in — and did so not with plans to lock up and hide the collection, but to find the gems that could be made available and do so:

Kahle has a particular interest in obscure recordings, he said. “High school marching bands, soundtracks for foreign movies you’ve never heard of — those are just treasures.”

The diversity and quality of the Bop Street inventory, which includes more than 100 albums by jazz pianist Fats Waller as well as a healthy selection of classical music, rock, R&B, jazz, country and other musical genres, was exactly the kind of thing the Internet Archive is on the lookout for, Kahle said.

If you can’t tell, Brewster Kahle has the mind of someone looking to preserve and share culture.

Thom Tillis, on the other hand, has the mind of someone who thinks that culture must be locked up:

According to a May 15, 2020 article in the Seattle Times, the Internet Archive has purchased Bop Street Records full collection of 500,000 sound recordings with the “inten[t] to digitize the recordings and put them online, where they can be streamed for free.” It is not clear from the article, or others, if you intend to digitize all of the sound recordings acquired from Bop Street. But it is clear that these sound recordings were very recently for sale in a commercial record shop and likely contain many sound recordings that retain significant commercial value. This raises serious alarms about copyright infringement.

As I understand, Bop Street Records, which the Wall Street Journal once deemed a top-five record shop in the country, focuses on collectible-quality vinyl records across a diverse range of musical genres. According to its website, there sound recordings includes “Rock, Soul/R&B, Jazz, Blues, Classical, Country, World and many other genres from the 1920’s to 1990’s.” The overwhelming majority-if not all-of these sound recordings are protected by U.S. copyright law, and thus may not be digitized and streamed or downloaded without authorization.

In a similar vein, I am aware of the Internet Archive’s “Great 78 Project,” which has already digitized-and continues to digitize daily-a vast trove of 78 rpm recordings, many of which are also commercially valuable recordings already in the marketplace, and has made those recordings available to the public for free through unlimited streaming and download. I understand that the Internet Archive is framing this and its other sound recording projects–which include both obscure gems for music fans and hits from the likes of Elvis Presley, Chuck Berry, and Johnny Cash-as preservation, but your current practices raise numerous potential issues of copyright infringement. The Bop Street collection is likely to add to that. Among other things, your sound recording projects do not appear to comply with the relevant provisions of the Orrin G. Hatch-Bob Goodlatte Music Modernization Act (MMA), which deals only with pre-1972 sound recordings and would not allow for streaming or downloading. Moreover, there are additional copyrights, such as the musical composition and the album artwork, that are displayed on the Internet Archive website and would not be covered by an exception for preservation.

The inclusion of the Great 78 Project here just seems to be a gratuitous anti-culture attack by Tillis for no goddam reason other than he is against the preservation of cultural artifacts. The Great 78 Project has been out for a few years now, and it’s a project that was put together not just by the Internet Archive, but in collaboration with the Archive of Contemporary Music and George Blood LP. The project is a recognition that tons of old 78rpm records are the only copies of that music ever recorded and my grandparents were the last generation to have easy access to a 78 rpm record player. The archival of those records falls into a murky space in copyright law because, thanks to insane copyright term extension. You can be pretty damn sure that anything on a 78rpm record, when it was recorded, was recorded with the clear understanding that by 2020, it would be in the public domain. The fact that some might not be isn’t a condemnation of the Great 78 Project, but of Congress for destroying culture in this manner.

Now, someone who was actually, say, an elected official representing the public and who took an oath to protect and defend the Constitution, including the clause that pretty directly states that the purpose of copyright law is to “promote the progress,” might look at that last paragraph and say, quite obviously, that if a jumble of messed up copyright laws are getting in the way of preserving music that no one can listen to, and of making it widely available — or that merely posting album artwork is somehow against the law — that maybe the law is pretty damn messed up, and that Congress — or even the Senate Intellectual Subcommittee, of which Thom Tillis is the chair — would want to fix those obviously broken laws.

But, nope. To Tillis it’s an opportunity to attack a library that has stepped up to save a massive collection of rare items, and to give them a new life. To someone of Tillis’ point of view — that seems to merely be an unfiltered, unthinking conduit for some giant Hollywood interests — this kind of public good must be stopped.

Techdirt.