Threat Actors Get Creative with Building Block Style Attacks, Finds HP

HP Ireland today issued its quarterly HP Wolf Security Threat Insights Report, showing how threat actors are chaining different combinations of attacks together like toy bricks to sneak past detection tools. It comes as the Government has published the Mid-Term Review of the National Cyber Security Strategy 2019-2024 plan to boost cybersecurity, which includes measures to support the potential growth of the cybersecurity industry.

The research has found that by isolating threats that have evaded detection tools on PCs, HP Wolf Security has specific[i] insight into the latest techniques used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

Based on data from millions of endpoints running HP Wolf Security[ii], the researchers found:

  • It’s playtime for cybercriminals using building block style attacks: Attack chains are often formulaic, with well-trodden paths to the payload. Yet creative QakBot campaigns saw threat actors connecting different blocks together to create unique infection chains. By switching up different file types and techniques, they were able to bypass detection tools and security policies. 32% of the QakBot infection chains analysed by HP in Q2 were unique.
  • Spot the difference – blogger or keylogger: Attackers behind recent Aggah campaigns hosted malicious code within popular blogging platform, Blogspot. By hiding the code in a legitimate source, it makes it harder for defenders to tell if a user is reading a blog or launching an attack. Threat actors then use their knowledge of Windows systems to disable some anti-malware capabilities on the users’ machine, execute XWorm or the AgentTesla Remote Access Trojan (RAT), and steal sensitive information.
  • Going against protocol: HP also identified other Aggah attacks using a DNS TXT record query – typically used to access simple information on domain names – to deliver the AgentTesla RAT. Threat actors know the DNS protocol is not often monitored or protected by security teams, making this attack extremely hard to detect.
  • Multi-lingual malware: A recent campaign uses multiple programming language to avoid detection. Firstly, it encrypts its payload using a crypter written in Go, disabling the anti-malware scanning features that would usually detect it. The attack then switches language to C++ to interact with the victim’s operating system and run the .NET malware in memory – leaving minimal traces on the PC.

Val Gabriel, Managing Director of HP Ireland, comments:

In Q2, we welcomed the Government’s plan to boost cybersecurity in Ireland but there is still a long way to go. We have observed that the top threat attack vectors that can be exploited to break into an IT system, is email (79%) and browser downloads (12%). Our research shows that today’s attackers are becoming better organised and more knowledgeable. It’s easier for attackers so exploit any security gaps by knowing the best entry points and how to easily navigate systems. To limit the chances of a security breach, businesses and users should avoid downloading files from untrusted sites or clicking on any suspicious links.

The report details how cybercriminal groups are diversifying attack methods to bypass security policies and detection tools. Key findings include:

  • Archives were the most popular malware delivery type for the fifth quarter running, used in 44% of cases analysed by HP.
  • Q2 saw a 23% rise in HTML threats stopped by HP Wolf Security compared to Q1.
  • There was a 4%-point increase in executables from 14% to 18% from Q1 to Q2, mainly caused by usage of the PDFpower.exe file, which bundled software with a browser hijacking malware.
  • HP noted a 6%-point drop in spreadsheet malware (19% to 13%) in Q1 compared to Q4, as attackers move away from Office formats that are more difficult to run macros in.
  • At least 12% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in Q2.
  • The top threat vectors in Q2 were email (79%) and browser downloads (12%).

Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc., comments:

While infection chains may vary, the methods of initiation remain the same – it inevitably comes down to the user clicking on something. Instead of trying to second guess the infection chain, organisations should isolate and contain risky activities such as opening email attachments, clicking on links, and browser downloads.”

HP Wolf Security runs risky tasks in isolated, hardware-enforced virtual machines running on the endpoint to protect users, without impacting their productivity. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that slip past other security tools and provides unique insights into novel intrusion techniques and threat actor behaviour.

Tech Review – TOZO OpenReal Air Conduction Headphones

Bone conduction headphones are popular now but now we are seeing AIR conduction headphones which is a different take on the technology used and for the better, having tested countless pairs of bone conduction headphones AIR conduction are far and few between but we have tried a few pairs over the last while, TOZO is a new brand to us and we recently tested their Golden X1 earbuds which are fantastic with a great app and we recommend you try them out and give this brand a look in the near future if not already.

The TOZO OpenReal Air are another pair or headphones that are closer to wearing earbuds than you think same as bone conducting but better, You still get all the features required with controls and so on but on these type of headphones it is actually much simpler. Yes we have an app this time around for these too which is not common and again kept simple.

The design is simple yet robust and sleek you will forget you are wearing these after a few mins and they are comfortable and don’t bounce on your head if jogging or training, a question that is asked alot on such headphones. As you are aware they do not go into your ears but sit on the outside of them and delivering decent audio too which you might not expect but they do work really well and they also have an IPX7 rating for those who are more sporty or use outdoors.

Now when it comes to sound they are loud enough with 16.2mm dynamic drivers, not as loud as earbuds or headphones but loud enough also they do not seem to leak like bone conduction headphones so if someone is sitting beside you on the train or bus you need not worry. Battery life is decent too with around 14 hours per charge less when used full volume and EQ setting dependent.

The controls are simple to use being both on the right earbud and the small control buttons which are very small for me with big fingers it must be said but they work and work fine, you also have the charge port there which of course is a two pin proprietary charger which will hopefully be gone by the end of this year but for now it is the norm like most smartwatches.

The app gives you more control allowing you to pick from custom EQ settings or make your own and the thing is here there is a notable difference between the EQ sounds compared to even recent earbuds tested where you would not notice much of a change between your bass and trebles etc, you can hear the difference with these which is good.

For the price you pay here these are one of it not the best air conduction headphones I have tried to date and look forward to seeing this improve even more over time.

Features

  • Open-Ear Design
  • Air Conduction Technology & Ergonomic Design
  • Clear Calls with Dual-Mic ENC & Bluetooth 5.3
  • 16.2mm Dynamic Drivers
  • Up to 14 Hours Playtime & Fast Charging
  • Support TOZO APP

BUY

Video Review

 

Tech Review – XtremeSkins White Marble skin for the Samsung Galaxy Z Flip 5

Skins for your phone are a thing like cases and covers and something I do not dabble to much in but we ordered some for the Galaxy Z Flip 5 to try out and of course some cases, the prices on these vary in price and also location is a factor with taxes and customs and this one cost 20 sterling in total from the UK as I was looking around to see what is on offer the price including shipping does not warrant a purchase in my book you may as well just get a case locally like the OtterBox thin shield case for example.

Maybe I picked the wrong skin up but this one in particular offers no additional grip nor has it any side skins for the phone or cover for the fold area which is kinda lame however it does look nice on the phone and again to be fair to them they have a big selection and some with textures that will give you a better grip, I you drop your phone with a skin on it will be a hit and miss on this one on how it lands and with the sides and flip mechanism not protected I think I would rather take a chance and still leave the case on which I can say makes no difference and the would be the safer option, I would like to go caseless but with this skin on I will not and will keep searching for other options.

To be fair though they have lots of nice skins on their site and worth a look so check them out and we may just revisit XtremeSkins and pick something else this time. They are simple to install by the way so that is one good thing to take out of it and if you have never done these skins before the company has instructions which I completely ignored and still got it done. It will stop your device from getting scratched on the rear and front which overall is not a bad thing.

 

Samsung Galaxy Z Flip 5 skin details

• These skins ONLY fit the Samsung Galaxy Z Flip 5
• Covers the top and bottom
• Precision cut-outs for the lenses, sensors and flash
• Our vinyls can be re-lifted, repositioned and stretched with a hair dryer
• We use high quality glue that does no harm to your phone and doesn’t leave any residual glue after removal
• Back of the vinyl comes with air release, making it easy to wrap and refuse air bubbles
• Protects your phone from scuffs, scratches, UV rays, dirt, grease and surface water
• Alcohol wipes are included to ensure perfect adhesion to your Samsung Galaxy Z Flip 5

Video Review

Tech Review – Creative Outlier Free+ and Outlier Free Pro+

Bone conduction headphones have surged in popularity over the last two years and we know that due to the numerous models we have tested and stay tuned for more by the way which are in the review process and for the most these are simple products to use and set up and again for the most there is no app to content with so they are a connect to your phone device and away you go, some however offer more and then you have Air conduction headphones.

Creative however is not new to the scene here nor is the brand and known for delivering excellent audio products be it speakers headphones or earbuds and this is their second time around now with these bone conducting headphones and there is an improvement on last years models and that being in the sound department.

I am speaking about the two products in one review because they are almost identical and the pro offering extra on board storage and a better IP rating other than that the sound for me was identical the controls are identical and the audio profiles are also identical so is the looks apart from the colour choice.

The build quality is great as before and these are super robust they could be flung about the place and still work they can be twisted and tortured and they still work so they are built to last.

Some folk find these neckband type headphones annoying and the questions I always get asked is does the band bounce up and down and how do they sound same two questions all the time oddly enough they never ask about battery life or any other factors.

The neckband sits nicely on your neck to begin with and stays there even in the gym once you have these sat on your ears correct there will be no issue now you might get the odd bounce on the neck if you push it but for the most they are grand and comfortable the only difference is they don’t do in your ears and that is a transition you can only decide if it is for you and it is not as bad as some might be lead to believe.

Controls are simple to use on these guys and both identical you cet three small raised buttons that are tactile and work well to do all the things you need to do so which is volume control skip and reverse tracks play and pause control calls and activate your voice assistant so you have all the controls required however there is no app here.. You have a mfb or better known as a multifunction button which you press 4 times yes 4 times to change the latency, now I say 4 times however there is some earbuds I recently tested that went up to 5 times to do something which is a bit of a joke to be honest.

How do they sound then, well they will and bone conducting headphones will never be as good as headphones or earbuds however the sound quality is getting better as the technology improves over time and for me it has from what I have tested to date and these have vastly improved over their previous models and you have to take into account these are aimed at the sporty person but anyone can wear them which I often do asides from testing.

These both have some bass in there pretty decent sound overall for the technology in play here and deliver a good audio experience whilst being able to hear what is going on around you which is important, not as good as in ear earbuds or headphones but overall you can’t complain when using this technology but it is getting better.

Creative Outlier Free+ is priced at £89.99 and is available at Creative.com. For more information, visit creative.com/OutlierFreePlus

Creative Outlier Free Pro+ is priced at £119.99 and is available at Creative.com. For more information, visit creative.com/OutlierFreeProPlus

Video Review

 

 

Tech Review – Galaxy Watch One Click Fabric Band

The Galaxy Watch One Click Fabric band is one of many straps available to up the game with your watch, just like phones with cases watches now are an area where manufacturers can cash in with straps and bands to spice up your watch if you wish to do so.

This One Click Fabric Band is a simple installment and takes less than a minute to swap out, the pins however would be a bit of concern for me being so thin but so far so good, the strap is solid on the arm and can be fixed to any tightness you like and looks well, the colour may be a problem being so bright with getting dirty but that is to be expected and for the more demanding of us out there like sports fans. It is comfortable and has some breathability.

Overall it is a nice strap and the hook and loop fastener works well and the watch will remain secure on the wrist by my only worry is the pins holding it on but so far so good. Check the video below for more and stay tuned for more accessories for the Z Flip5 and Watch 6

Video Review

Tech Review – Otterbox Thin Flex case for the Samsung Galaxy Z Flip5

The Otterbox thin flex case is one of the latest on the market for Samsung’s latest devices the Galaxy Z Flip5, cases for flip phones tend to take a while to hit the shelves but over the next few weeks we will see them arrive but some companies have them ready out the gate on a device launch

The Thin Flex case comes in many colours so there is choice for the customer and that choice is only up to you on which colour you go for. The case is presented as expected from Otterbox and just comes in simple packaging and you get some information inside the box and two parts for the case being a flip phone.

The case itself for me is on the thicker side making the device a tad bulky on the front however this protects that all important cover display on the phone giving you piece of mind in that area all ports are well covered too and deep, you get a clear view on the rear of the cover of your phone and the keys work well. I did find the fingerprint sensor a tad awkward to use though with the thickness of the case opened and closed but again this could be just me and my big fingers.

Overall your device will be protected from harm here with the case but the only exposed part is the folding mechanism itself and I yet have to see any cases that cover this bar one I seen on an ad on Facebook so I might get that in soon.

Check out the video below for more.

Features

  • Hard case with soft grip edges
  • Ultra-slim case designed for foldable phones
  • DROP+ | drop tested to meet military standard (MIL-STD-810G 516.6)
  • Made with more than 50% recycled plastic
  • Wireless charging compatible
  • Easy installation
  • Lasting antimicrobial properties to protect the case*
    * Helps protect the case exterior against many common bacteria. It does not protect you or the screen.
  • Raised edges protect camera and screen
  • Hassle-free customer experience

Video Review

First look – Samsung Galaxy Z Flip5 and Watch 6 classic 47mm

The latest tech from Samsung is now hitting the shops and this time around it is the latest flips phone foldable phone and watches, samsung have been a leader in the flip and fold department over the years but the competition is now heating up from other known brands and I was was personally going to go with the latest Motorola flip phone which knocks on samsungs door on the cover display, speaking of the cover display on first noticing you have a lack of apps that can be placed on it,which is stupid in my book lets be honest here, they have had a tiny display on the cover for years and this time comes up with an almost full display and limit it.

There is workarounds though which is handy enough to implement and by going to the Samsung store you get the apps called good lock and multistar and this enables you to add what you like on the cover screen but it should not have to be this way so hopefully there will be an easier way with an update later on from them.

Having used the device with the Watch 6 the last few days so far so good bar some notifications not hitting the watch, the watch itself is nice and for me the bigger the watch the better and it is certainly getting attention along with the Flip5 as people have asked me about both and seen my typing and scrolling on the cover screen when the device is closed.

Check out the unboxing of both devices below and a walkthrough of the Flip5 and if you have any questions feel free to hit me up.

Unboxing and walkthrough

Exploring the Advantages of a VPN

Understanding the benefits of a Virtual Private Network (VPN) can help your organization decide whether to use it and how. In many cases, the advantages of using a VPN outweigh the cons.  When properly configured, it can greatly enhance your company’s security configuration. 

Security on Internet

A VPN is first and foremost a security solution. It establishes an encrypted communication tunnel between you and the Internet. Simply put, it creates a secure internet connection to protect you from external threats which is another advantage of using a VPN.

Your security is further enhanced with features like Kill Switch and Private DNS. Kill Switch will shut down your internet connection if the VPN is offline, so no sensitive data is leaked. Private DNS adds an extra layer of security to your searches and the data you send to websites when you visit them.

Better privacy

When it comes to VPNs, privacy is just as important as security. Much of your personal information can be collected if you are not using a VPN. This includes your searches, the websites you visit, your activity on those sites, or even your name, email address, phone number, and location.

By encrypting all your traffic and changing your IP address, a VPN app effectively eliminates these problems. When you are connected to a VPN, neither your ISP (Internet Service Provider) nor the bad guys can see your online activity. On top of that, you can even hide the fact that you’re using a VPN if you connect to one of the obfuscated servers. 

Stream regionally blocked websites

People know this problem all too well. You pay for a streaming service or visit a website in one area, only to find yourself stuck in another or if you want to watch something on the internet but all of sudden it shows you that your country has a restriction for it. Finding a solution can be a problem but there are ways for it and they are so easy to approach if you know where to look. If you want to watch Netflix, for instance, unblocking access using VPN is possible. There are even free VPN options that may work with Netflix and other streaming sites. Movies, shows, videos, it doesn’t matter, you will be able to watch all the content that was restricted in your country without worrying about unexpected surprises. Sit back and enjoy!

Saving money

While any good VPN costs money, it can also save you money. Some websites keep a log of your activity and use this information to increase prices. This is especially common with airline tickets and accommodation bookings. The more you visit to check prices, the higher they go. To fix this damage, clear your browsing history and cache, and connect to the VPN. Sometimes the prices of goods and services vary by location. You can try switching VPN servers to get an even better offer.

Unrestricted internet access

The Internet can be like an open ocean that you can explore without constraints or limitations. Unfortunately, that’s not always the case. Oppressive governments tend to heavily censor the Internet for their citizens, while fewer Internet restrictions or tweaks may apply depending on where you live.

You can bypass oppressive censorship and freely access the wonders of the World Wide Web by connecting to a VPN server. Secure encryption won’t let anyone track your online activity, so you can enjoy the best Internet without worrying. 

Prevent internet tracking

Your ISP, or Internet service provider, tracks your online activity and may share this data with advertisers, government agencies, and other third parties without your knowledge or consent. They do this for a variety of reasons, not all of which are harmful, but nonetheless an invasion of privacy. Some countries require ISPs to store your digital activity data, while others, such as the US, allow ISPs to openly sell your browsing data to advertisers and data brokers.

If that’s not enough of a reason to use a VPN, remember that they also have access to your passwords, social media data, and physical location. 

Scalability of a network

While a private network can help you start a business, the cost of network expansion can be very high. If you use a VPN server, you can provide simultaneous access to multiple employees and remote workers. You can also run key applications in a cloud environment and provide access to them through a secure VPN tunnel.

This can include anything from email to full-featured applications that you normally run on the desktop. When employees connect to the VPN, they access another computer that you use to run the applications they need. Every employee with credentials can access the VPN and the application. Adding more employees means providing more bandwidth if needed, and credentials for each new team member.  

Stay anonymous

One of the most commonly cited reasons to use a VPN is anonymous browsing. There are many reasons why you might want to stay anonymous while browsing online, many of which are related to the benefits of a VPN discussed above. You don’t even know sometimes why you want to stay anonymous online until the consequences of oversharing hit you in the face.

In modern society, we all depend on the Internet for everything. We want to access information, communicate with friends and family, and shop online. All of this can be done when connected to a virtual private network (VPN) service. It is an essential tool for Internet freedom. Governments, ISPs, businesses, and advertisers all track internet users. Internet Freedom allows you to surf any website without worrying about your privacy. 

First Look – EDIFIER TWS1 Pro 2 earbuds

The latest from EDIFIER has dropped in to be tested out and it is the new Edifier TWS1 Pro 2 earbuds packed with features and app connection for small money and an update to the TSW1 earbuds which we tested back in 2021, you can see that review here.

We have the White version here and they do look super clean and has a glossy finish to them and look well out of the box and we look forward to seeing how much things have changed over the last two years, the cost to performance ratio has come down over the years yet Edifier still always maintained to deliver great audio products regardless at any price point.

With ANC, wear detection, ultra low latency and app connection we look forward to testing the latest out and if you have any questions feel free to let us know as ususal.

 

Main Features:

    • Long Battery Life. Around 4 hours music playtime with ANC ON with 12 hours charging case. A total 16 hours playtime.
    • Active noise cancellation with 2 levels of ANC selection and multiple ANC modes is designed to reduce unwanted background noise in various environments.
    • Clear call quality. Built-in microphone to ensure high quality calls.
    • Wear Detection. Music will pause automatically when taken out of your ear and will start playing once you place them back in.
    • Ultra-low latency connection with seamless experience on gaming activities.
    • Edifier Connect App. Unlock all the features through APP: customize control setting and EQ selection (Classic/POP/Classical/Rock).
  • Dust proof and splash proof for active wear. IP54 certified.

Price & Availability:

The Edifier TWS1 Pro 2 is available for £49.99 from https://www.amazon.co.uk/dp/B0C7L1KJRQ

Unboxing and first look