Identity Theft
Bit-Defender hack - Held Hostage!
Reported by tripwire.com
By Loucif Kharouni, Senior Threat Researcher, Damballa
Rogue bounty hunters forcing companies to pay higher bug bounties
Late last week, it was discovered that antivirus vendor BitDefender was hacked , and a portion of its customer data, which was stored unencrypted, was stolen. After stealing the data, the hackers are now asking for $15,000 in order not to release it. But in some ways, companies have been paying ransoms for many years now. Today, the stakes are just higher and more expensive.
Penetration testing evolves
Penetration testing, the practice of using offensive methods to test network defenses, has taken a greater role in organizations security programs, as opposed to a few years ago. With the growth of penetration testing come more powerful tools that allow less experienced and less skilled individuals to wield them on everything from neighbors to multi-national corporations with tremendous efficiency. Now, thanks to the Hacking Team breach, there are tool suites once yielded by nation-state actors available to the public – with very little defense against the initial attack.
Bug bounty programs
Bug bounty programs, incentive based bug hunting programs, have become more common and are a fast growing trend. Several companies offer payment or rewards for anyone who finds a vulnerability on their websites or systems. Recently, United Airline rewarded a security researcher 2 million frequent flyer miles for discovering several vulnerabilities on their systems. Companies like Google, Facebook, and Microsoft have reward programs, and companies overseas such as Yandex, the Russian counterpart to Google, also have bug bounty programs.
Exploits business
The other side of this coin is the exploits business. Companies like Hacking Team have made the exploit business a treasure trove for security researchers and criminals, claiming to be white hats. As mentioned in an article, Hacking Team paid $45000 to a Russian security researcher for an exploit . They also bought exploits from Vupen, who brought the exploit discovery business to another level. Vupen has now started a 0-day startup, that pays big bucks for 0-day exploits. Zerodium advertises what they are willing to pay for some exploits:
Extortion
Blackmail and Extortion are often interchangeable words but slightly differs in meaning. We also can note this difference when it comes to criminals. Groups like DD4BC , have made themselves experts in cyber-extortion. Their modus-operandi is to send an email to their targets, informing them they would be victims of a high scale Distributed Denial of Service (DDOS) if they do not make a payment of 25 Bitcoins (BTC). They claim to be capable of a 500 Gb/s DDOS.
Blackmail
What does the BitDefender hack teach us? That every company is potentially vulnerable? Hackable? Maybe, but more than that, it teaches us that every company must have a bug bounty program, or they could be victims of blackmail. Detoxransome claims BitDefender declined the payment of $15,000 to return stolen customer data. Most companies would pay for this type of discovery, but nothing forces them to pay the big bucks.
Conclusion
The vulnerabilities discovery business has turned into “Pay me or I’ll expose you”. Companies are held hostage by criminals trying to make easy money. The rise of companies like Hacking Team, Vupen and Zerodium is also encouraging people to compete against each other to find new vulnerabilities, and sell them to the best buyer, legitimate or not.
In order to combat data-theft and extortion for information schemes it is important to constantly ensure systems are updated and scanned for vulnerabilities. Along with updating, it is important to monitor internal and external networks for suspicious activity. The technology and skill set you have available for what happens after a breach is as critical as the technology you have to minimize your risk before a breach. As a take away from the BitDefender hack, include regular audits to ensure that patching of systems has occurred and that vulnerable systems have been remediated or replaced.
Loucif Kharouni
Senior Threat Researcher, Damballa
Willis McDonald
Senior Threat Researcher, Damballa