Month: June 2022

Why You Should Protect Browsers Against Malvertising

It is important for businesses to take steps to improve web security and block the web-based component of phishing attacks and drive-by malware downloads, and one of most important steps to take is to protect browsers against malvertising.

What is Malvertising

Malvertising is the term given to the use of malicious online adverts for downloading malware or directing website traffic to attacker-controlled websites for phishing or other scams. Malicious adverts may be placed on compromised websites, but commonly they are added to legitimate ad networks, which website operators use for improving engagement and generating additional revenue. Third-party advertising blocks are used on many high-traffic websites, and if malicious adverts are added, they can be displayed on large numbers of high-traffic websites to huge volumes of website visitors. Since the adverts may be displayed on trusted websites, that trust is then transferred to the adverts. Website visitors may click the adverts and be directed to a malicious website. Worse, it is possible to embed malicious code into the adverts themselves, so it is not always necessary to click the advert to have malware downloaded.

Malvertising is a significant attack vector and is often used for malware distribution. The attacks can bypass in-built browser security features that protect against website redirects and pop-up adverts. It is also possible for attackers to create malvertising campaigns that are targeted at specific users, and only serve adverts to those users.

How to Defend Against Malvertising

Since people interact with the Internet using a web browser, web browsers should be secured to protect against malvertising. The malicious code in adverts can probe for and exploit vulnerabilities in web browsers. Those vulnerabilities may exist due to the use of an outdated web browser such as Internet Explorer, or a web browser that has not been updated to the latest version. Web browsers may have unsecure configurations that can be exploited, or users could be redirected to a malicious website or web application. Attackers also use malvertising to exploit human weaknesses, such as unsecure browsing habits or untrained or poorly trained users.

The threat from malvertising cannot be totally eliminated, but steps can be taken to reduce risk. Many of the protective measures are low-cost and can be implemented easily. The four main methods for protecting against malvertising, as recommended by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are:

  1. Standardize and secure web browsers
  2. Deploy ad blocking software
  3. Implement protective domain name system technologies
  4. Isolate web browsers from operating systems

Standardize and secure web browsers

Limit the browsers, versions, and configurations that are used by your organization – The greater the variety, the higher the probability that vulnerabilities will exist that can be exploited. By restricting browsers, versions, and configurations, you will have a more consistent and easily managed network portfolio. You must then ensure that the browsers are kept up to date and new versions are installed as soon as possible after a version has been released.

Deploy ad blocking software

Ad-blocking software can prevent malicious adverts from being displayed. Ad blockers will remove adverts or prevent them from being displayed, often via a web browser extension. In theory, ad blockers are a great choice for defending against malvertising, but this option should be treated with caution as ad blockers have their own security concerns. Ad blockers may operate with high levels of privileges and may therefore access all data traffic between the user workstation and the network, which means they may be able to perform malicious actions with high levels of privileges. Malicious ad blockers have been detected, and some browser extensions accept payments from advertisers to ensure that paid for ads are allowlisted and are not blocked.

Isolate web browsers from operating systems

Browser isolation is an architectural decision that is used by many large organizations to defend against web-based threats, although the design, implementation, and maintenance of Internet browser isolation can be complex and may be beyond the capabilities of some small- and medium-sized businesses. Browser isolation involves creating a logical barrier between the web browser and other systems and operates on a zero-trust principle, assuming that all web traffic is untrustworthy and potentially malicious. Browser isolation is often achieved locally using a sandbox or virtual machine on the user’s computer.

Implement protective domain name system technologies

One of the best steps to take is to use protective domain name system (DNS) technologies such as WebTitan. WebTitan is a DNS-based web filtering solution for blocking access to malicious websites. When a malvertising attempts to redirect a user to a malicious domain, that redirect is blocked, and the user is directed to a locally hosted block page and is advised that the web resource cannot be accessed as a threat was detected. WebTitan can also be configured to block access to risky categories of websites and will block drive-by malware downloads.

WebTitan incorporates threat intelligence feeds and collects data from over 500 million endpoints worldwide to ensure that threats are rapidly blocked for all users when new threats are detected. According to CISA, 91% of malware uses DNS for cyberattacks. WebTitan can block malware command-and-control server communications.

Advice from the U.S. Cybersecurity and Infrastructure Security Agency

In 2021, CISA issued a Capacity Enhancement Guide for all federal agencies calling for them to take steps to secure browsers and defend against malvertising. This year, CISA has recommended all businesses and non-profit organizations follow the guidance and take steps to protect their browsers against malvertising.

Matanbuchus Loader Being Distributed in Phishing Emails using Excel and ZIP Attachments

Phishing emails are commonly used to distribute malware and in recent years malware loaders have been a common payload. Malware loaders include the likes of BazarLoader and Bumblebee, which are used to infect devices with the goal of delivering the malware and ransomware payloads of other threat groups.

Security researchers have identified a relatively new malware loader dubbed Matanbuchus that is being delivered via phishing emails. Like other malware loaders, Matanbuchus is operated under the malware-as-a-service model, and has been developed to stealthily download and execute second-stage malware payloads and executable files. The Matanbuchus loader has recently been observed dropping Cobalt Strike on infected systems. Cobalt Strike is a legitimate adversary simulation framework that is used in red team operations for detecting vulnerabilities that could potentially be exploited, but is also extensively used by criminal hackers for post-exploitation activities.

The Matanbuchus loader is currently being offered on Russian cybercrime forums for $2,500, and has been available since at least February 2021, with a malware developer operating under the moniker BelialDemon believed to be the developer of the malware. BelialDemon is known to have been involved in the development and sale of other malware loaders, such as TrumpLoader.

Matanbuchus, which is an alternate name for the demon Belial, can be used to launch an .exe or .dll file in the memory, add or modify task schedules, launch PowerShell commands, and execute standalone executable files to load a DLL. The malware has already been used in several attacks in the United States, including entities in the education sector.

Researchers at Palo Alto Networks’ Unit 42 team have identified phishing emails being used to deliver the Matanbuchus loader that use Excel documents with malicious macros. As is common in these types of phishing campaigns, if the user opens the attached file, they are informed that the document was created in an earlier version of Microsoft Excel, so the content cannot be viewed unless the user clicks on Enable Editing and then Enable Content. Should content be enabled, Excel 4.0 macros are then leveraged to drop and execute the Matanbuchus loader.

A campaign has also been detected that uses a .zip file attachment that contains an HTML file, which delivers a second .zip file that includes an MSI installer. If that file is executed, an error message is displayed indicating to the user that something has gone wrong, when in the background a DLL file is delivered and executed, which acts as the loader for delivering the Matanbuchus loader DLL file.

To block the delivery of malware loaders such as Matanbuchus, it is important to implement multiple cybersecurity solutions. A Spam filter such as SpamTitan can be used to block the delivery of the phishing emails. SpamTitan includes dual antivirus engines for detecting and blocking known malware and sandboxing to identify unknown malware through in-depth analysis of the behavior of attached files.

A web filter such as WebTitan should be used to block connections to malicious websites that host the malware. WebTitan can also be configured to block downloads of files often used to deliver malware and command-and-control center communications.

It is also strongly recommended to provide comprehensive security awareness training to all members of the workforce to explain the threat of phishing emails, explain the red flags to look for in emails, and not to open attachments unless they can be verified as authentic. TitanHQ can help in this regard through the SafeTitan Security Awareness Training solution, which includes a phishing simulation platform for simulating phishing emails to test how employees respond. For further information on these solutions, contact TitanHQ today.

Expert Insights Names TitanHQ One of the Most Innovative Cybersecurity Companies of 2022

TitanHQ has been included in the Expert Insights’ list of the Top 100 Most Innovative Cybersecurity Companies of 2022. Expert Insights is a leading online publication for businesses that conducts research into cloud-based business technologies and cybersecurity solutions to help businesses with their purchasing decisions. The site includes editorial buyers’ guides, industry analyses, interviews, and technical product reviews written by industry experts, and is visited by more than 80,000 business owners and IT admins each month.

In addition to an awards program that recognizes the best cloud-based and cybersecurity solutions – TitanHQ received 5 ‘Best of’ Awards in Spring 2022 – Expert Insights produces a list of the Top 100 Most Innovative Cybersecurity Companies. The list is divided into 12 categories and recognizes the most innovative companies that are developing cutting-edge solutions for businesses and consumers to help them deal with current and emerging cyber threats. TitanHQ was included in the list in the Email and Messaging Security category.

It has been a busy year for TitanHQ. The company has been taking great strides into the U.S. market and has significantly boosted its presence throughout North America and globally, and has brought in a host of new talent. The latest addition to the North American management team is channel veteran, Tom Watson, who was recently appointed as TitanHQ’s new Channel Chief. Watson is now working alongside another channel champion and recent appointee, Jeff Benedetti, who is TitanHQ’s new VP of Sales.

TitanHQ has recently bolstered its product portfolio with another product for boosting defenses against phishing and other cyber threats – The SafeTitan Security Awareness and Phishing Simulation planform, which follows on from the launch of a cutting-edge addition to the SpamTitan suite of products, SpamTitan Plus. SpamTitan Plus includes all of the market-leading anti-phishing feeds and provides unrivaled detection speeds of malicious URLs – 1.6x faster than the current market-leading anti-phishing solutions.

“The overwhelming feedback from our users and customer base has been that phishing attacks are becoming more advanced, proficient, and dangerous. Phishing is the number one problem to solve in the email security community,” said TitanHQ CEO, Ronan Kavanagh. “With that in mind, we’re delighted to have been recognized in the Email and Messaging Security Category. We will continue to innovate and provide email and messaging security solutions that MSPs can use to deliver a consistent, secure, and reliable experience to their customers,” added Kavanagh.