Monday, October 28, 2019

Browser Update Warnings May Actually Be Malicious Hackers

Researchers at FireEye have recently unearthed a particularly nasty new campaign that is both multi-faceted and dangerous.

At the heart of the attack are hacked websites which display seemingly innocuous popup message informing the site visitor that their browser is out of date.

It will helpfully provide a one-touch solution to the non-existent problem via a button that promises to download the latest version of the browser in question.

Naturally, it does no such thing.  Instead, it uses a series of JavaScripts to gather information about the target computer and send the details back to the command and control server.

The server then responds to the findings reported by the initial script by uploading the initial payload.  This varies based on the details gleaned, but generally includes some type of banking trojan malware and a backdoor such as Dridex, NetSupport Manager RAT, or similar.  If the initial scan reveals that the target computer is part of a corporate network, then an additional payload is also injected onto the target machine, but we'll get to that in a moment.

The first part of the payload will busily ferret out login credentials and other sensitive information, exfiltrating any files of value back to the command and control server.

Only when this operation has been completed and if the computer is part of a corporate network will the second stage we referenced earlier trigger, which is a strain of ransomware, normally BitPaymer or DoppelPaymer. The ransomware spreads through the network as far as it is able, encrypting files network wide.

These two ransomware strains are known for their hefty ransom demands, which often run into the hundreds of thousands, or even millions of dollars.

This multi-stage approach is dreadfully effective.  It not only allows the hackers to squeeze a wide range of sensitive data from infected systems, but then, locks them down hard and demands a hefty payment.  Be sure your staff is aware.  This one's about as dangerous as they come.

Nowadays, whether you own a startup or established company, you need to be cautious, aware, and proactive when it comes to online security. Let SpartanTec Inc. in Greenville help you secure your computers and networks against various types of online threats. 


SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Thursday, October 17, 2019

NASA Suffers Data Breach With Device Connected To Network

Not even NASA is immune to hacking.  Recently, the American space agency announced that they traced a breach back to April of 2018.

That was when a group described as an APT (Advanced, Persistent Threat) breached the Jet Propulsion Laboratory's network via a 'Raspberry-Pi' device that was improperly connected to the network.

The hackers made off with more than 500MB worth of data in 23 files. Two of the files contained sensitive information relating to international Traffic in Arms Regulations relating to the Mars Science Laboratory mission.

According to investigators, the reason the hackers were able to burrow so deeply into the agency's networks from a third-party device was that the agency did not have their network properly segmented.  Once the hackers gained access, they could go pretty much anywhere they wanted.

"We also found that security problem log tickets, created in the TISB when a potential or actual IT system security vulnerability is identified, were not resolved for extended periods of time - sometimes longer than 18 days."  The investigators from the OIG said.

Late last year, the US Department of Justice charged a pair of Chinese nationals for hacking cloud providers, the US Navy, and NASA.  The DOJ's filings identified the pair as part of one of the Chinese government's elite hacking corps known as APT10.

Given that, it is entirely possible that APT10 was behind the Raspberry Pi incident.  They certainly have the skills, means and motive. Especially given Chinese interest in US technology in general and their recent big push for space exploration.
Clearly, NASA has some work to do to shore up their security, and the hope is that now that these events have come to light, the agency will take decisive steps to do just that.  Good luck, NASA.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Tuesday, October 15, 2019

Google Adds Several New Password Features To Help Users

Google is taking additional steps to provide a safer and more secure environment for their massive user base.  Chrome is the most widely used browser in the world. In recent months, Google has made moves to provide better password security. Most recently, they released a Chrome Extension called Password Checkup that scans all of your stored login credentials to see if they've been found in data breaches. If they have been breached, it prompts you to change them.

As good and helpful as that is, the company has taken an additional step and has now integrated the Password Checkup tool directly into Google's Password Manager.

Here's how it works:
  • Open your Google Password Manager, which you can access via https://passwords.google.com.
  • When the page displays, you'll see a new link labelled "Check Passwords." Click that.
  • Google will then proceed to check your stored login credentials to see:
    • If any of your passwords have been exposed via a third-party data breach
    • If the password in question is being reused among multiple sites
    • Assess the relative strength of all of your stored passwords.
Once this check is complete, it will display the results in different categories that show you exactly which passwords are at risk, and why they were flagged.  From there, you'll be able to change any problematic passwords and re-run the check to give yourself a clean bill of health.

This is a fantastic move, but the company isn't stopping there.  Ultimately, the company plans to have Chrome automatically alert you when your saved passwords were discovered in a breach and allow you to act immediately to change them and keep your accounts safe.

When the plan is fully realized, Google's password security feature built into Chrome will rival the capabilities of many paid password management offerings, and that's a very good thing indeed.
Kudos to Google for raising the bar.

Online security is an integral part of any company these days. If Google is taking steps to help their users secure their passwords, you should also do you part. Call SpartanTec Inc. now if you want to know how to keep your personal or business information secure.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Tuesday, October 1, 2019

LastPass User Credentials May Have Been Exposed To Hackers


Do you use the password manager LastPass?  If so, you're certainly not alone.  In recent years it has seen its popularity surge and has grown to become the most popular app of its type on the web.

Unfortunately, last month, Tavis Ormandy (part of Google's Project Zero team) discovered a critical flaw in the app's design that allowed some user data to be compromised.

Having said that, there are a couple of important caveats:

First, the bug only appears for Chrome and Opera browser extensions.  Second, the only credentials revealed are the ones for the last site you visited, so this bug does not expose all the passwords that LastPass saves and manages for you.

Even so, it's a critical bug and the company moved swiftly to patch the issue.  If you download the latest build as soon as you finish reading this article, you won't have any issues.

It should also be noted that since Google found and reported the issue, and since LastPass moved so quickly to resolve it, there's no indication that this issue was exploited by hackers in the wild.  Even so, it doesn't pay to take chances, so if you're a LastPass user and it's been a while since you updated, the time to do so is now while it's still fresh in your mind.

The worst thing you could do would be to abandon the password gate because of a bug that has already been fixed.  Unfortunately, this isn't the first, and won't be the last issue of this type to impact LastPass and other password protection services.  Even though that's true, you're much more secure using them than not.  If you're not currently using LastPass or some other password manager, you should strongly consider doing so.  It's a simple way to take your online security to the next level

Keeping up with all the possible problems that arise with email and passwords it almost an impossibility for business owners/managers. SpartanTec Inc is here to help with training your employees on how to stay safe, creating internal standards for handling emails and monitoring your data to ensure it stays safe.

Don’t let online threats be the downfall of your business. Email & Spam Protection from SpartanTec, Inc. assures your email is working to benefit your company, and not leaving you vulnerable to security problems.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914



Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer


Friday, September 27, 2019

Your Google Calendar Settings May Be Sharing Your Info

Twelve years ago, Google introduced a new feature to Google Calendar that allowed users to share their calendars with others.  It's a great feature and invaluable in a corporate environment because it gives teams an easy way to collaborate.  Google itself even touted the "make it pubic" feature of their calendar as being a cool way to use their search engine to discover upcoming events.

Unfortunately, as with most things, there's a potential downside.  Recently, a security researcher named Avinash Jain discovered more than 8,000 publicly accessible Google Calendars, searchable via Google's own search engine.  Many of these calendars contain sensitive information (which is bad enough), but worse, they allow any user to add new events that can cause real harm to the system hosting the calendar. This is done via maliciously crafted events or poisoned links.

As Avinash Jain reports:

"I was able to access public calendars of various organizations leaking out sensitive details like their email IDs, their event name, event details, location, meeting links, zoom meeting links, google hangout links, and much, much more.

This is more of an intended setting by the users and intended behavior of the service. The main issue however, is that anyone can view anyone's public calendar, add anything on it - just by a single search query without being shared the calendar link.

Jain goes onto say that several calendars belonging to many of the top 500 Alexa company's employees were made public, which is certainly cause for concern.

This most recent finding adds to the chorus already warning of the dangers of calendar sharing.  Just a few months ago, researchers from Kaspersky Lab discovered scammers abusing Google Calendar in a variety of ways. For example, there were phishing scams that contained poisoned links masquerading as google calendar event links.

Stay vigilant and be sure you have all employees check their Google Calendar security settings so you're not revealing more than you intended to.

It is also crucial to make sure that your computers or the entire business network is not in any way at risk of any kind of online breach. Call SpartanTec, Inc. in Greenville now and let our team set up and efficient strategy to protect your business.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Saturday, September 14, 2019

Hackers Are Using Resumes To Deliver Malicious Software


Hackers have used poisoned documents to deliver malware payloads for years. Recently though, researchers at the security company Cofense have spotted a new twist to the ploy, aimed squarely at HR departments. The recently detected campaign uses fake resume attachments to deliver Quasar Remote Administration Tool. It is affectionately known as RAT to any unsuspecting Windows user who can be tricked into jumping through a few hoops.

Here's how it works:

An email containing a document that appears to be a resume is sent to someone in a given company.  The document is password protected, but the password is politely included in the body of the email, and is usually something simple like '123.' If the user enters the password, a popup box will appear, asking the user if he/she wants to enable macros.

Up to this point, the attack is fairly standard, but here's where it gets interesting:

If the macros are allowed to run, they'll display a series of images and a message announcing that content is loading.  What it's actually doing is throwing out garbage code that's designed to crash analysis and detection tools while RAT is installed quietly in the background.

At that point, the system is compromised. RAT's capabilities give the hackers the ability to open remote desktop connections, log keystrokes and steal passwords, record any webcams in use, download files, and capture screenshots of the infected machine.

Worst of all, the first part of the infection process knocks out most detection programs. So, the hackers generally have a large window of time to take advantage of the newly created beach head. That can cause all manner of havoc in your network or simply choose to quietly siphon proprietary data from your systems.

Be on the alert and make sure your HR staff is aware.  This is a nasty campaign and it's just hitting stride.

These kind of attacks can be prevented. The IT Management Services of SpartanTec, Inc. will work with your HR department to ensure the resumes they are receiving are free of any harmful malware. Contact us today for a consultation.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Friday, August 16, 2019

How Can You Secure Your Computer From Hackers?


Back in the 1990’s, computer users have started to notice the disadvantages of the internet and many of them didn’t like what they saw. Email accounts were bombarded with tons of spam while business networks were plagued with various computer viruses. A scary criminal component came about that widened the definition of robbery to a whole new level. It now includes infiltrating the computer, stealing personal details, duping you to revealing personal details, as well as using that information to extort and steal everything from your bank account, identity, and down to your business secrets.

Despite all that, small and large businesses depend on the internet to monitor their orders, financials, and their inventory as well as perform PR campaigns and marketing, connect with clients, participate in social media, and conduct other important business operations. However, there’s been a lot of reports about computer breaches in different companies including those that are already at the top of the ladder. Small companies are responsible when it comes to the prevention of such crimes so that company property is not harmed and consumer information is not stolen. A few steps to ensure computersecurity and protect your integrity are listed below.

Use a Firewall

Two of the biggest computer operating systems come with built in firewalls, software that were made to develop a barrier between the outside world and your information. They prevent unauthorized access to your company’s network and notify you of any attempt of intrusion.

Install Anti-Virus

Trojans, keyloggers, and computer viruses are all around. Anti-virus programs like Avast and Malwarebytes work by immunizing your computer against any software that will threaten the operating system or any unauthorized code. Viruses can have different effects that might be quite easy to identify. They may slow down your computer or in some cases delete or halt key files.

Install Anti-Spyware Package

Spyware is a specialized type of software that will collect and monitor your organizational or personal information secretly. It is designed to be difficult to detect and remove. It also tends to serve up undesired adverts or search results that will direct you to malicious websites.

Use Complex Passwords

One important way of preventing illegal intrusions onto your computer and your network is to use secure and complex passwords. It will be harder for a hacker to invade your computer if you use more secure passwords. It is not a good idea to use obvious combinations or words that will represent common things like your birthday or any basic information that could be easily connected to you.

Update Your OS, Browser, and Apps

You should always install updates to your computer’s operating system. The majority of updates include security patches that will stop hackers from gaining access and exploiting your personal or business information. This also applies to your favorite apps.

Ignore Spam

You should be careful of emails that come from unknown parties and don’t click on the links or even open attachments that on the email. Over the years, spam catchers have upped their game and have become extremely effective at catching spam. But you still need to be very careful.

The threats to your computer, personal and business information are everywhere. Never let your guard down and always make sure that effective security measures are in place to protect your network and company in general. Call SpartanTec, Inc. now and let our team determine if your network is at risk and what measures can be taken to protect your company.



SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer