Showing posts with label incident response. Show all posts
Showing posts with label incident response. Show all posts

Saturday, December 21, 2019

New VMware Global threat report identifies lateral movement, island hopping as key cyberattack tactics

VMware Carbon Black releases its semiannual Global Incident Response Threat Report (GIRTR), and it reveals that attackers are continuing to evolve.


VMware Carbon Black has a vast incident response (IR) partner ecosystem, comprising more than 100 leading IR firms. These partners use Carbon Black technology in more than 1,000 response engagements per year. Aggregated data from these top IR firms shows that cooperation among attackers is increasing. That makes it more important than ever for the good guys to fight back.



“Because geopolitical tension is playing out in cyberspace, targets must boost defenses,” says Tom Kellermann, VMware Carbon Black head cybersecurity strategist. “Beyond politics, financial motivation is a top driver. That means organizations with decentralized systems protecting high-value assets, including money, intellectual property, and state secrets, continue to be at high risk.”  


The GIRTR includes eight key research highlights. Three demonstrate significant increases since the last report include financial gain was the primary motivation for 90 percent of attacks. This is a sharp increase from 61 percent in the first half of 2019. It’s also a shift from previous years, when intellectual property theft and stealing customer information topped the list; “island hopping” continues to rise, as forty-one percent of total attacks came from this advanced method, where attackers target enterprises via partners and vendors; and IR pros said they experienced destructive/integrity attacks in about 41 percent of attacks, a 10 percent increase compared to the past two quarters.


The majority of cyberattacks now include tactics like lateral movement, island hopping and destructive attacks, according to the November report. Advanced hacking capabilities and services for sale on the dark web compound the issue, as does an unprecedented collaboration among nation-states, according to the report.


This most recent GIRTR also highlights the rise in custom malware, which the report defines as “coded with a specific purpose in mind, a sign of more sophisticated and well-financed attacks, as opposed to commodity malware, which is widely available for purchase or for free on the dark web.” 


Custom malware was used in 41 percent of attacks, up from 33 percent in the first quarter of this year, according to the report.


“This increase should also worry enterprises because of the pass-along effect. These attackers are like Johnny Appleseed,” says Kellermann.


Kellermann explains why people who build custom attack code sell it on the dark web; buyers use that purchased code to attack a company with it; and once that happens, the custom code builder can now teleport into the attacked company’s environment because he or she has administrative access to that attack code.


As communities of attackers come together, so, too, must defenders. And that’s exactly what VMware Carbon Black and top IR professionals are doing. They’re “fighting back as a global community with actionable intelligence and holistic strategies to mitigate the ongoing cyber insurgency online.”

Saturday, December 14, 2019

Kaspersky research finds 174 municipal institutions targeted with ransomware in 2019

According to Kaspersky security experts, 2019 has seen a significant spike of ransomware attacks on municipalities. This conclusion comes after the company’s researchers observed at least 174 municipal institutions with more than 3,000 subset organizations have been targeted by ransomware throughout the last year. This represents a 60 percent increase from the same figure in 2018.


Ransomware is notorious in the corporate sector for financial devastation and has affected businesses around the world for several years. This year has seen rapid development of an earlier trend where malware distributors have targeted municipal organizations. 

Researchers note that while these targets might be less capable of paying a large ransom, they are more likely to agree to cybercriminals’ demands. Blocking any municipal services directly affects the welfare of citizens in financial losses as well as other significant and sensitive consequences.

When considering publicly available information, ransom amounts have varied greatly with highs reaching up to $5,300,000 and $1,032,460 on average. Researchers note that these figures do not accurately represent the final costs of an attack, as the long-term consequences are far more devastating.

The malware that was most often observed were varied, yet three families were named as the most notorious by Kaspersky researchers: Ryuk, Purga and Stop. Ryuk appeared on the threat landscape more than a year ago and has since been active all over the world in public and in the private sector. Its distribution model usually involves delivery via backdoor malware which spreads by the means of phishing with a malicious attachment disguised as a financial document. 


Purga malware has been recognized since 2016, yet only recently municipalities have been discovered to fall victims to this Trojan having various attack vectors from phishing to brute force attacks. Stop cryptor is relatively new as it is only a year old. It propagates by hiding inside software installers. This malware continues to be prevalent, ranking at number seven in the top 10 most popular cryptors ranking of the third quarter this year.

“One must always keep in mind that paying extortionists is a short-term solution which only encourages criminals and keeps them funded to quite possibly repeat the same acts,” said Fedor Sinitsyn, a security researcher at Kaspersky. “In addition, once a city has been attacked, the whole infrastructure is compromised and requires an incident investigation and a thorough audit. This inevitably results in costs that are in addition to the ransom requested. Based on our observations, cities might be inclined to pay because they usually cover the cyber risks with help of insurance and allocating budgets for incident response. The better approach would be to invest in proactive measures like proven security and backup solutions as well as regular security audit. While the trend of attacks on municipalities is only growing, it can be stifled by adjusting the approach to cybersecurity and what is more important by the refusal to pay ransoms and broadcasting this decision as an official statement.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...