Tuesday, April 20, 2021
  • Facebook Security Knew in 2017 There Was a Problem and Failed to Act
  • CPDP 2021 – Moderator: Franziska Boehm ‘EDPL Young Scholar Award’
  • Delphix Partner Spotlight on J2 Consulting
  • Assessing the state of mobile application security through the lens of COVID-19
  • Cybereason Excels in 2020 MITRE Engenuity ATT&CK Evaluations

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Bloggers Network
    • Latest Posts
    • Contributors
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming
    • On-Demand
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
  • Library
  • Related Sites
    • MediaOps Inc.
    • DevOps.com
    • Container Journal
    • Digital Anarchist
    • SweetCode.io
  • Media Kit

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Data Security Malware SBN News Security Bloggers Network 

Home » Cybersecurity » Data Security » Digital Criminals Abusing Secure Tunneling Service to Deliver Lokibot

Digital Criminals Abusing Secure Tunneling Service to Deliver Lokibot

by David Bisson on May 28, 2019

Digital criminals have begun abusing a secure tunneling service to deliver samples of the Lokibot banking malware family.

My Online Security came across an instance of this campaign when they received an email pretending to originate come from BBVA Banco Continental, a Spanish bank. The email leveraged the lure of a fake payment transfer to trick the recipient into clicking on an attachment named “Detalles de la transferencia de pago.xls.” When opened, the email instructed the recipient to enable macros. Doing so caused the document to download a sample of Lokibot.

The fake BBVA email. (Source: My Online Security)

This campaign stood out against other Lokibot attacks in that it abused NGROK, a secure tunneling service hosted on Amazon AWS. In the eyes of My Online Security, this particular choice worked in the favor of those behind this operation. As quoted in the security blog’s research:

The Ngrok service is hosted on Amazon AWS so reporting to them is basically a waste of time because by the time they respond the malware has done its work & vanished and the malware isn’t actually stored anywhere on an Amazon server, just a link or redirect to the malware happens via Amazon AWS.

What’s more, the way VirusTotal works makes it hard to gauge the efficacy of this campaign. That’s because VirusTotal (at least the public version) doesn’t show all subdomains. As a result, security researchers can only see malware delivered from the main ngrok.io.domain and not potentially thousands or even millions of subdomains.

Given this lack of visibility, organizations should focus on protecting themselves against attack campaigns similar to the one described above. They should do so by educating their employees about some of the most common phishing attacks in circulation today. They should also leverage (Read more...)

*** This is a Security Bloggers Network syndicated blog from The State of Security authored by David Bisson. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/digital-criminals-abusing-secure-tunneling-service-to-deliver-lokibot/

May 28, 2019May 28, 2019 David Bisson IT Security and Data Protection, Latest Security News, LokiBot, Malware, NGROK
  • ← CapLoader 1.8 Released
  • The Emotet-ion Game (Part 3) →

TechStrong TV – Live

Watch latest episodes and shows

Subscribe to our Newsletters

Get breaking news, free eBooks and upcoming events delivered to your inbox.
  • View Security Boulevard Privacy Policy

Most Read on the Boulevard

U.S. Fingers Putin’s Cozy Bear for SolarWinds Attacks
Wordsmithing: Cybersecurity or Cyber Safety?
Emotet Takedown: Time to Celebrate?
Clubhouse Exclusivity Applies to Membership, Not Data
New Federal Data Privacy Legislation Proposed
Securing APIs: Empowering Security
Phishing 101: How It Works & What to Look For
New integration: MSPs can now manage Acronis via Kaseya VSA
Why is Cyber Security Essential in the Education Sector?
Cybereason and MassCyberCenter Partner to Mentor College Students

Upcoming Webinars

Wed 21

Managing Open Policy Agent at Scale

April 21 @ 3:00 pm - 4:00 pm
Thu 22

A New Approach to Secure Web Gateways

April 22 @ 11:00 am - 12:00 pm
Mon 26

The Kubernetes Network (Security) Effect

April 26 @ 9:00 am - 10:00 am
Mon 26

Application Security: Moving at the Speed of DevOps

April 26 @ 1:00 pm - 2:00 pm
Wed 28

Cyber Attacks From the Open Source Perspective

April 28 @ 1:00 pm - 2:00 pm
Thu 29

Hack My Java Application: How Snyk and Red Hat Help Developers Stay Performant and Secure

April 29 @ 11:00 am - 12:00 pm
May 05

Managing Permissions and Entitlements is at the Core of a Zero Trust Model in the Cloud

May 5 @ 3:00 pm - 4:00 pm
May 17

Are We There Yet? The State of Cloud Native Application Security

May 17 @ 9:00 am - 10:00 am

More Webinars

Download Free eBook

7 Must-Read eBooks for Security Professionals

Recent Security Boulevard Chats

  • Cloud, DevSecOps and Network Security, All Together?
  • Security-as-Code with Tim Jefferson, Barracuda Networks
  • ASRTM with Rohit Sethi, Security Compass
  • Deception: Art or Science, Ofer Israeli, Illusive Networks
  • Tips to Secure IoT and Connected Systems w/ DigiCert

Industry Spotlight

Taking Steps Toward an Impactful SASE Architecture
Cybersecurity Data Security Endpoint Industry Spotlight Network Security Security Boulevard (Original) 

Taking Steps Toward an Impactful SASE Architecture

April 20, 2021 Mike Spanbauer | 16 hours ago 0
Online Ed is the New Corporate Threat Vector
Cybersecurity Governance, Risk & Compliance Industry Spotlight Malware Security Boulevard (Original) Threats & Breaches 

Online Ed is the New Corporate Threat Vector

April 19, 2021 Curtis Simpson | Yesterday 0
Three Wishes to Revitalize SIEM and Your SOC
Cybersecurity Data Security Endpoint Industry Spotlight Network Security Security Boulevard (Original) 

Three Wishes to Revitalize SIEM and Your SOC

April 16, 2021 Albert Zhichun Li | 4 days ago 0

Top Stories

Wait, What? Nvidia/ARM Sale on Hold—for Security Reasons
Analytics & Intelligence Cloud Security Cyberlaw Cybersecurity Data Security Endpoint Featured Governance, Risk & Compliance IoT & ICS Security Mobile Security Network Security News Security Boulevard (Original) Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Wait, What? Nvidia/ARM Sale on Hold—for Security Reasons

April 20, 2021 Richi Jennings | 7 hours ago 0
U.S. Fingers Putin’s Cozy Bear for SolarWinds Attacks
Analytics & Intelligence Application Security Cloud Security Cyberlaw Cybersecurity Data Security Endpoint Featured Governance, Risk & Compliance Incident Response IoT & ICS Security Malware Network Security News Security Boulevard (Original) Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

U.S. Fingers Putin’s Cozy Bear for SolarWinds Attacks

April 16, 2021 Richi Jennings | 4 days ago 0
YT$AW: FBI Cleans Up Exchange Servers, NSA Tips Microsoft 4 More Bugs
Analytics & Intelligence Cloud Security Cyberlaw Cybersecurity Data Security Endpoint Featured Governance, Risk & Compliance Incident Response Malware Network Security News Security Awareness Security Boulevard (Original) Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

YT$AW: FBI Cleans Up Exchange Servers, NSA Tips Microsoft 4 More Bugs

April 14, 2021 Richi Jennings | Apr 14 0

Security Humor

via     the  Comic Noggins  of   Nitrozac     and     Snaggy     at     The Joy of Tech®   !

Joy Of Tech® ‘Zuck’s Law vs. Tim’s Law!’

Join the Community

  • Add your blog to Security Bloggers Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: info@securityboulevard.com

Useful Links

  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • Privacy Policy
  • DMCA Compliance Statement

Other Mediaops Sites

  • Container Journal
  • DevOps.com
  • DevOps Connect
  • DevOps Institute
Copyright © 2021 MediaOps Inc. All rights reserved.
Our website uses cookies. By continuing to browse the website you are agreeing to our use of cookies. For more information on how we use cookies and how you can disable them, please read our Privacy Policy.