{"id":15126,"date":"2019-04-18T10:17:13","date_gmt":"2019-04-18T18:17:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/04\/18\/news-8875\/"},"modified":"2019-04-18T10:17:13","modified_gmt":"2019-04-18T18:17:13","slug":"news-8875","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/04\/18\/news-8875\/","title":{"rendered":"Wipro Intruders Targeted Other Major IT Firms"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Thu, 18 Apr 2019 17:42:46 +0000<\/strong><\/p>\n<p>The crooks responsible for launching phishing campaigns that netted dozens of employees and more than 100 computer systems last month at <strong>Wipro<\/strong>, India&#8217;s third-largest IT outsourcing firm, also appear to have targeted a number of other competing providers, including <a href=\"https:\/\/www.infosys.com\" target=\"_blank\" rel=\"noopener\">Infosys<\/a> and <a href=\"https:\/\/www.cognizant.com\" target=\"_blank\" rel=\"noopener\">Cognizant<\/a>, new evidence suggests. The clues so far suggest the work of a fairly experienced crime group that is focused on perpetrating gift card fraud.<\/p>\n<p>On Monday, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2019\/04\/experts-breach-at-it-outsourcing-giant-wipro\/\" target=\"_blank\" rel=\"noopener\">broke the news<\/a> that multiple sources were reporting a cybersecurity breach at Wipro, a major trusted vendor of IT outsourcing for U.S. companies. The story cited reports from multiple anonymous sources who said Wipro\u2019s trusted networks and systems were being used to launch cyberattacks against the company\u2019s customers.<\/p>\n<p>In <a href=\"https:\/\/krebsonsecurity.com\/2019\/04\/how-not-to-acknowledge-a-data-breach\/\" target=\"_blank\" rel=\"noopener\">a follow-up story Wednesday<\/a> on the tone-deaf nature of Wipro&#8217;s public response to this incident, KrebsOnSecurity published <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/04\/wiproiocs.txt\" target=\"_blank\" rel=\"noopener\">a list of &#8220;indicators of compromise&#8221; or IOCs<\/a>, telltale clues about tactics, tools and procedures used by the bad guys that might signify an attempted or successful intrusion.<\/p>\n<p>If one examines the subdomains tied to just one of the malicious domains mentioned in the IoCs list (internal-message[.]app), one very interesting Internet address is connected to all of them &#8212; <a href=\"https:\/\/www.virustotal.com\/en\/ip-address\/185.159.83.24\/information\/\" target=\"_blank\" rel=\"noopener\">185.159.83[.]24<\/a>. This address is owned by <a href=\"https:\/\/krebsonsecurity.com\/?s=%22king+servers%22&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">King Servers<\/a>, a well-known bulletproof hosting company based in Russia.<\/p>\n<p>According to records maintained by <a href=\"https:\/\/www.farsightsecurity.com\" target=\"_blank\" rel=\"noopener\">Farsight Security<\/a>, that address is home to a number of other likely phishing domains:<\/p>\n<p>securemail.pcm.com.internal-message[.]app<br \/> secure.wipro.com.internal-message[.]app<br \/> securemail.wipro.com.internal-message[.]app<br \/> secure.elavon.com.internal-message[.]app<br \/> securemail.slalom.com.internal-message[.]app<br \/> securemail.avanade.com.internal-message[.]app<br \/> securemail.infosys.com.internal-message[.]app<br \/> securemail.searshc.com.internal-message[.]app<br \/> securemail.capgemini.com.internal-message[.]app<br \/> securemail.cognizant.com.internal-message[.]app<br \/> secure.rackspace.com.internal-message[.]app<br \/> securemail.virginpulse.com.internal-message[.]app<br \/> secure.expediagroup.com.internal-message[.]app<br \/> securemail.greendotcorp.com.internal-message[.]app<br \/> secure.bridge2solutions.com.internal-message[.]app<br \/> ns1.internal-message[.]app<br \/> ns2.internal-message[.]app<br \/> mail.internal-message[.]app<br \/> ns3.microsoftonline-secure-login[.]com<br \/> ns4.microsoftonline-secure-login[.]com<br \/> tashabsolutions[.]xyz<br \/> www.tashabsolutions[.]xyz<\/p>\n<p>The subdomains listed above suggest the attackers may also have targeted American retailer <a href=\"https:\/\/www.sears.com\" target=\"_blank\" rel=\"noopener\">Sears<\/a>; <a href=\"https:\/\/www.greendot.com\" target=\"_blank\" rel=\"noopener\">Green Dot<\/a>, the world&#8217;s largest prepaid card vendor; payment processing firm <a href=\"https:\/\/www.elavon.com\" target=\"_blank\" rel=\"noopener\">Elavon<\/a>; hosting firm <a href=\"https:\/\/www.rackspace.com\" target=\"_blank\" rel=\"noopener\">Rackspace<\/a>; business consulting firm <a href=\"https:\/\/www.avanade.com\" target=\"_blank\" rel=\"noopener\">Avanade<\/a>; IT provider <a href=\"http:\/\/www.pcm.com\/n\/About-Us\/navLinks-151\" target=\"_blank\" rel=\"noopener\">PCM<\/a>; and French consulting firm <a href=\"https:\/\/www.capgemini.com\" target=\"_blank\" rel=\"noopener\">Capgemini<\/a>, among others. KrebsOnSecurity has reached out to all of these companies for comment, and will update this story in the event any of them respond with relevant information.<\/p>\n<h4>WHAT ARE THEY AFTER?<\/h4>\n<p>It appears the attackers in this case are targeting companies that in one form or another have access to either a ton of third-party company resources, and\/or companies that can be abused to conduct gift card fraud.<\/p>\n<p>Wednesday&#8217;s follow-up on the Wipro breach quoted an anonymous source close to the investigation saying the criminals responsible for breaching Wipro appear to be after anything they can turn into cash fairly quickly. That source, who works for a large U.S. retailer, said the crooks who broke into Wipro used their access to perpetrate gift card fraud at the retailer\u2019s stores.<\/p>\n<p>Another\u00a0source said the investigation into the Wipro breach by a third party company has determined so far the intruders compromised more than 100 Wipro systems\u00a0 and installed on each of them <strong>ScreenConnect<\/strong>, a legitimate remote access tool. Investigators believe the intruders were using the ScreenConnect software on the hacked Wipro systems to connect remotely to Wipro client systems, which were then used to leverage further access into Wipro customer networks.<\/p>\n<p>This is remarkably similar to activity that was directed in 2016 and 2017 against Cognizant, one of Wipro&#8217;s competitors and likely the target of the same attackers. In May 2018, <strong>Maritz Holdings Inc.<\/strong>, a Missouri-based firm that handles customer loyalty and gift card programs for third-parties, <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/04\/cognizant.pdf\" target=\"_blank\" rel=\"noopener\">sued Cognizant<\/a> (PDF), saying a <a href=\"https:\/\/stlrecord.com\/stories\/511446468-maritz-sues-it-contractor-after-cyberattacks-in-2016-and-2017-related-to-rewards-card-programs\" target=\"_blank\" rel=\"noopener\">forensic investigation<\/a> determined that hackers had broken into Cognizant&#8217;s systems and used them to pivot attacks into Maritz&#8217;s loyalty program and siphon more than $11 million in fraudulent eGift cards.<span id=\"more-47453\"><\/span><\/p>\n<p>That investigation determined the attackers also used ScreenConnect to access computers belonging\u00a0to Maritz employees. &#8220;This was the same tool that was used to effectuate the cyber-attack in Spring 2016. Intersec [the forensic investigator] also determined that the attackers had run searches on the Maritz system for certain words and phrases connected to the Spring 2016 attack.&#8221;<\/p>\n<p>According to the lawsuit by Maritz Holdings, investigators\u00a0also determined that the &#8220;attackers were accessing the Maritz system using\u00a0accounts registered to Cognizant. For example, in April 2017, someone using a Cognizant account utilized the \u201cfiddler\u201d hacking program to circumvent cyber protections that Maritz had\u00a0installed several weeks earlier.&#8221;<\/p>\n<p>Maritz said its forensic investigator found the attackers had run searches on the Maritz system for certain words and phrases connected to the Spring 2016 eGift card cashout. Likewise, my retailer source in the Wipro attack told KrebsOnSecurity that the attackers who defrauded them also searched their systems for specific phrases related to gift cards, and for clues about security systems the retailer was using.<\/p>\n<p>It&#8217;s unclear if the work of these criminal hackers is tied to a specific, known threat group. But it seems likely that the crooks who hit Wipro have been targeting similar companies for some time now, and with a fair degree of success in translating their access to cash given the statements by my sources in the Wipro breach and this lawsuit against Cognizant.<\/p>\n<p>What&#8217;s remarkable is how many antivirus companies still aren&#8217;t flagging as malicious many of the Internet addresses and domains listed in the IoCs, as evidenced by a search at <a href=\"https:\/\/www.virustotal.com\" target=\"_blank\" rel=\"noopener\">virustotal.com<\/a>.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/04\/wipro-intruders-targeted-other-major-it-firms\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Thu, 18 Apr 2019 17:42:46 +0000<\/strong><\/p>\n<p>The criminals responsible for launching phishing campaigns that netted dozens of employees and more than 100 computer systems last month at Wipro, India&#8217;s third-largest IT outsourcing firm, also appear to have targeted a number of other competing providers, including Infosys and Cognizant &#8212; two other large technology consulting companies, new evidence suggests.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,21587,16695,21588,21589,21590,10655,21591,21592,21593,21594,21595,18500,21565],"class_list":["post-15126","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-avanade","tag-breadcrumbs","tag-capgemini","tag-elavon","tag-green-dot","tag-king-servers","tag-maritz-holdings-inc","tag-pcm","tag-rackspace","tag-screenconnect","tag-sears","tag-virustotal-com","tag-wipro-data-breach"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15126"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15126\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15126"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}