'Digital drive puts India at greater cyber attack risk'

July 17, 2017

Singapore, Jul 17: India`s growing economy and digital push have caught the attention of hackers and an increasing wave of cyber attacks could soon badly impact the country, experts from Russian cyber security firm Kaspersky Lab have warned.Cyber3

India and other South Asian countries are now on the radar of cyber attackers, said experts, adding that the government and corporates need to procure state-of-the-art, New Age security solutions to thwart their plans.

The impact of recent global cyber attacks were clearly visible in India as "WannaCrypt" -- that affected 150 countries globally -- and the recent "Petya" malware attack hit computers in the country.

"India`s growing economy and digitalisation are really a big concern as cyber attackers have now begun focusing on developing countries with big populations and average incomes," Eugene Kaspersky, Chairman and Chief Executive of Kaspersky Lab, said on the sidelines of the recently-concluded "Interpol World 2017" conference in Singapore`s Suntec City.

His comments came as the Moscow-based cyber security firm found that the "Petya" attack hit Gateway Terminal India operated by AP Moller-Maersk at the Jawaharlal Nehru Port Trust (JNPT), a facility near Mumbai which is India`s biggest container port.

The terminal was unable to load or unload because of the attack as it failed to identify which shipment belongs to whom.

According to Vitaly Kamluk, Director of Global Research and Analysis Team for APAC at Kaspersky Labs, there was no cyber security threat till 2010 and India was quite safe till then.

But now, India and other "developing countries are most vulnerable, especially the financial sector. We perceive that banks are most vulnerable in India", Kamluk said.

Stephan Neumeier, Managing Director of Kaspersky Lab Asia Pacific, stressed the need to educate people to save them from becoming victims of cyber attacks.

"As India`s economy is growing fast, more and more people are now getting access to Internet. They have 4G access and Android devices are becoming popular. They need to be educated about anti-virus solutions as mandatory for devices and be made aware about not falling for phishing attacks," Neumeier emphasised.

He suggested that malicious emails or links should also be part of the awareness process.

"Countries like India are developing very fast which opens doors for more cyber attacks," Neumeier added.

The experts also recalled how over 200,000 users were affected in 150 countries after the "WannaCrypt" virus attack which paralysed computers -- with a demand being made for a payment of $300 in bitcoins (crypto-currency or virtual currency) for a system to be unblocked.

Citing reports, Kaspersky Lab said that cyber crime costs the world $450 billion per year, which is almost the annual budget of Russia, China and Japan.

The experts said the hackers target government ministries, banks, utilities, other key infrastructure and companies nationwide, demanding ransom in crypto-currency.

Giving the example of Bangladesh, the experts said the hackers recently made a bank heist in the country and made away with $1 billion in one attack, since the security was vulnerable.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 19,2020

Cybersecurity researchers on Monday warned of a Trojan malware campaign which is targeting India's co-operative banks using COVID-19 as a bait.

Seqrite, the enterprise arm of IT security firm Quick Heal Technologies, detected the new wave of Adwind Java Remote Access Trojan (RAT) campaign.

Researchers at Seqrite warned that if attackers are successful, they can take over the victim's device to steal sensitive data like SWIFT logins and customer details and move laterally to launch large scale cyberattacks and financial frauds.

According to the researchers, the Java RAT campaign starts with a spear-phishing email which claims to have originated from either the Reserve Bank of India or a nationalised bank.

The content of the email refers to COVID-19 guidelines or a financial transaction, with detailed information in an attachment, which is a zip file containing a JAR based malware.

Upon further investigation, researchers at Seqrite found that the JAR based malware is a Remote Access Trojan that can run on any machine which has Java runtime enabled and hence it can impact a variety of endpoints, irrespective of their base operating system.

Once the RAT is installed, the attacker can take over the victim's device, send commands from a remote machine, and spread laterally in the network.

In addition, this malware can also log keystrokes, capture screenshots, download additional payloads, and extract sensitive user information, Seqrite said, adding that such attack campaigns can effectively jeopardise the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds.

To prevent such attacks, users need to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Banks should also keep their operating systems updated and have a full-fledged security solution installed on all the devices, Seqrite advised.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 3,2020

Giving each and every app access to personal information stored on Android smartphones such as your contacts, call history, SMS and photos may put you in trouble as bad actors can easily use these access to spy on you, send spam messages and make calls anywhere at your expense or even sign you up for a premium "service", researchers from cybersecurity firm Kaspersky have warned.

But one can restrict access to such information as Android lets you configure app permissions. 

Giving an app any of these permissions generally means that from now on it can obtain information of this type and upload it to the Cloud without asking your explicit consent for whatever it intends to do with your data.

Therefore, security researchers recommend one should think twice before granting permissions to apps, especially if they are not needed for the app to work. 

For example, most games have no need to access your contacts or camera, messengers do not really need to know your location, and some trendy filter for the camera can probably survive without your call history, Kaspersky said. 

While decision to give permission is yours, the fewer access you hand out, the more intact your data will be.

Here's what you should know to protect your data.

SMS: An app with permission to send and receive SMS, MMS, and WAP (Wireless Application Protocol) push messages, as well as view messages in the smartphone memory will be able to read all of your SMS correspondence, including messages with one-time codes for online banking and confirming transactions.

Using this permission, the app can also send spam messages in your name (and at your expense) to all your friends. Or sign you up for a premium "service." You can see and conrol which apps have these rights by going to the settings of your phone.

Calendar: With permission to view, delete, modify, and add events in the calendar, prying eyes can find out what you have done and what you are doing today and in the future. Spyware loves this permission.

Camera: Permission to access the camera is necessary for the app to take photos and record video. But apps with this permission can take a photo or record a video at any moment and without warning. Attackers armed with embarrassing images and other dirt on you can make life a misery, according to Kaspersky.

Contacts: With permission to read, change, and add contacts in your address book, and access the list of accounts registered in the smartphone, an app can send your entire address book to its server. Even legitimate services have been found to abuse this permission, never mind scammers and spammers, for whom it is a windfall.

This permission also grants access to the list of app accounts on the device, including Google, Facebook, and many other services.

Phone: Giving access to your phone means permission to view and modify call history, obtain your phone number, cellular network data, and the status of outgoing calls, add voicemail, access IP telephony services, view numbers being called with the ability to end the call or redirect it to another number and call any number.

This permission basically lets the app do anything it likes with voice communication. It can find out who you called and when or prevent you from making calls (to a particular number or in general) by constantly terminating calls. 

It can eavesdrop on your conversations or, of course, make calls anywhere at your expense, including to pay-through-the-nose numbers, Kaspersky warned.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 17,2020

In a bid to help tackle rise in domestic violence during the social distancing times in India, Twitter on Wednesday launched a dedicated search prompt to serve information and updates from authoritative sources around domestic violence.

Twitter has partnered with the Ministry of Women and Child Development the National Commission for Women in India to expand its efforts towards women.

The search prompt will be available on iOS, Android and on mobile.twitter.com in India, in both English and Hindi languages, the company said in a statement.

Data shows that since the outbreak of Covid-19, violence against women and girls has intensified in India and across the globe.

"We recognise collaboration with the public, government and NGOs is key to combating the complex issue of domestic violence. Accessing reliable information through this search prompt could be a survivor's first step towards seeking help against abuse and violence," said Mahima Kaul, Director, Public Policy, India and South Asia, Twitter.

Every time someone searches for certain keywords associated with the issue of domestic violence, a prompt will direct them to the relevant information and sources of help available on Twitter.

This is an expansion of Twitter's #ThereIsHelp prompt, which was specifically put in place for the public to find clear, credible information on critical issues.

The feature will be reviewed at regular intervals by the Twitter team to ensure that all related keywords generate the proactive search prompt, said the company.

Violence against women and girls across Asia Pacific is pervasive but at the same time widely under reported.

"In fact, in many countries in our region, the number is even greater, with as many as 2 out of 3 women in some countries reporting experiences of violence," added Melissa Alvarado, UN Women Asia Pacific Regional Manager on Ending Violence against Women.

Rekha Sharma, Chairperson, the NCW, said: "With social distancing norms in place, several women are unable to contact their regular support systems. This initiative by Twitter will provide big support to the survivors, who would otherwise be easily isolated without access to relevant information and help".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.