Threat Intelligence

12/26/2018
03:00 PM
0%
100%

Attackers Use Google Cloud to Target US, UK Banks

Employees at financial services firms hit with an email attack campaign abusing a Google Cloud storage service.

A malicious email campaign has been found abusing a Google Cloud Storage service to host a payload sent to employees of financial services organizations, Menlo Labs researchers report.

The threat appears to have been active in the US and UK since August 2018. Victims receive emails containing links to archive files; researchers say all instances in this particular campaign have been .zip or .gz files. All cases involve a payload hosted on storage.googleapis.com, which appears to be related to Google's cloud storage service but is, in fact, a malicious link.

Attackers often use this domain to host payloads because it's trusted and likely to bypass security controls in commercial threat detection products. These actors may have chosen bad links in lieu of malicious attachments because many email security products are designed to detect files and only pick up on malicious URLs if they're already in their threat repositories.

The use of a link resembling Google's cloud storage service is a form of "reputation jacking," a tactic in which attackers abuse well-known hosting services to evade detection. It's a growing trend, researchers say: In its annual analysis of the top 100,000 domains as ranked by Alexa, Menlo Labs found 4,600 phishing sites that used legitimate hosting services.

Google has responded to the report. "We regularly remove malware on Google Cloud Storage, and our automated systems suspended the malware referred to in this report," a spokesperson says. Further, account holders who suspect abuse can report it via Google's site.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DavidHamilton
50%
50%
DavidHamilton,
User Rank: Apprentice
1/10/2019 | 11:33:58 PM
Cloud storage perks and cons
Cloud storage has its pros and cons and when it is being utilized on a large scale by organisations, they ought to review the security aspects of it. The amount of data that is being uploaded online is massive and they should be noted that, that particular set of data is actually going to remain in the digital realm for good. If they are willing to grasp this concept, then only should they utilize the cloud facility, else they should really just stick to traditional data storage means.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/3/2019 | 10:05:32 AM
Re: Security practice
Gee, what a surprise?  Hackers using the cloud, imagine that.  Give them ANY open door and they are happy to enter any way they can.  The cloud, long vaunted, is one such door.  Anybody remember the words of dear WOZniak ages ago - there is NO security in the cloud.  A lamented savant of the truth. 
markgrogan
50%
50%
markgrogan,
User Rank: Apprentice
1/2/2019 | 11:30:06 PM
Security practice
Are you really surfside that people would try to do this with a cloud-based storage system? Of course there are hackers everywhere who are going to try and get all of this information out of the cloud to use for their own advantage! We just need to take that information and translate it into better security practices!
How the US Chooses Which Zero-Day Vulnerabilities to Stockpile
Ricardo Arroyo, Senior Technical Product Manager, Watchguard Technologies,  1/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3906
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
CVE-2019-3907
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
CVE-2019-3908
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.
CVE-2019-3909
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
CVE-2019-3910
PUBLISHED: 2019-01-18
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.