‘Tick’ing Time Bomb: Critical Analysis of the Tick Threat Actor Group

In today’s world, Japan is a favourite target for globally placed threat actors looking to deal massive financial and reputational damage or conduct corporate espionage. Japan is already a powerhouse of digitalization and adoption of technology, but still on the learning curve where cybersecurity is concerned. Thus, presented with top-notch digital infrastructure and baseline security, threat actors are presented with expansive attack surfaces that can be exploited for vulnerabilities. The list of threat actors looking to spearhead this digital attack on Japan is a long one, owing to the country’s booming economy and complicated geo-political placement.

Tick is one of the prominent Chinese threat actor group leading the malicious online charge against Japan. This group is also known by other aliases, including ‘BRONZE BUTLER‘ and ‘REDBALDKNIGHT.’

・

What is the Tick threat actor group?

Active since 2012, Tick is a Chinese cyber-espionage group linked to the Chinese government. In a classic example of state sponsored cyberattacks, Tick exfiltrates critical data, such as intellectual property, product details, and corporate information, from unsuspecting victim enterprises, for the benefit of the Chinese government. Aside from Japan, Tick has also routinely targeted organizations in South Korea. This threat actor’s primary agenda has been to inflict financial and reputational damage and likes to particularly target the heavy manufacturing and the food & beverages industry in Japan.

・

Attack methodology of the Tick threat actor group

It has been observed that Tick employs customized tools for each campaign, through some attack patterns remain the same, including the threat actor’s use of infrastructure, especially the preference for certain Command and Control (C2) domains. The following lists the other commonalities employed by Tick as part of its attack methodology.

  • Spear phishing attacks with Flash animation attachments executing the Daserf malware.
  • Leveraging on Adobe Flash zero-day vulnerability for SWC attacks.
  • xxmm: A backdoor that possesses the capability to exfiltrate sensitive information from the victim’s machine.
  • Datper: Backdoor Trojan designed to provide covert access to a compromised system. It exfiltrates data and downloads additional payload.
  • Daserf: Backdoor that helps the attackers gain full access to the infected system.

・

Recent threat activities by Tick threat actor group

Throughout 2018, the Tick threat actor group was noticed launching attack against Japanese technology and retail organizations using increasing variants of malwares and phishing attacks. This group’s modus operandi included the usage of secure USB drives to target critical air-gapped systems as part of its cyber espionage campaigns.

CYFIRMA’s Cyber Threat Intelligence (CTI) team made critical breakthroughs by leveraging tactical resources across the surface web, deep/dark web, and obscure forums frequented by hackers, to expose Tick’s escalating malicious activities against Japanese commercial interests. Subsequently, early warnings were issued for each of these instances. Listed below is one such early warning issued by CYFIRMA’s CTI team.

Data Leak Monitoring, 24 June 2018: CYFIRMA raised an alert about a possible data leak impacting a large Japanese Technology house. Chinese hackers claimed to possess Facial Recognition Software source code to affect the hack. Later, the involvement of Chinese threat actors Stone Panda and Tick was confirmed.

In 2019, the Tick threat actor group’s activities have only escalated, as can be figured from the early warning from Japan CERT as listed below.

On 19 February 2019, Japan CERT discovered that the suspected threat actor continued to leverage the Datper malware through RSA encryption as communication technique to target enterprises in Japan via targeted attack mail and by exploiting vulnerabilities present in the Asset Management Software.

・

CYFIRMA’s CTI Efforts: Effective protection against the Tick threat actor group

In the case of Tick, as also other similarly placed threat actor groups, innovation and persistence is the key. These groups are forever refining and deploying uniquely configured threat attacks that are difficult for conventional security systems to identify and mitigate. Additionally, Tick’s position as a state sponsored cyber threat outfit ensures that it is flush with resources and can afford to be persistent, and target high-tech, technologically organized establishments too.

CYFIRMA’s Cyber Threat Intelligence (CTI) capabilities ensure that threat actors like Tick are never allowed to vanish from the intelligence radar. Sourcing relevant information from the deep/dark web, specialist hacker forums, obscure chatter over the surface web, and employing bleeding edge technologies like artificial intelligence and machine learning, ensures that the faintest hints about potential threat attacks are retrieved in time and analysed for relevancy. If attacks are being planned, malicious tools being hired, developed or deployed, ‘hackers-for-hire’ being sourced, or older attack methods being outfitted with new proficiencies, CYFIRMA’s CTI team will be in the know. This applies to both an individual organization being attacked, or the overall industry being targeted.

Further, CYFIRMA’s CTI team issues notifications and recommendations that will help the organizations better manage the incoming threat. This includes mitigation techniques such as:

  • Block malicious, suspicious, spam emails and its attachments using an email gateway solution.
  • Unknown attachments with extensions such as scr, .exe, .pif, .cpl, zip, rar etc. should be blocked and not transmitted over email as part of the security best practices.
  • Maintain secure hardening guidelines in the operating system and the applications to prevent malicious code executions.
  • Client-side exploitation can be minimized using application micro segmentation and virtualization.
    And, strategies to detect an incoming Tick cyberattack, including:
  • Network intrusion detecting systems, Email gateway filtering should be used to identify compressed and encrypted attachments and scripts.
  • Network sensing, endpoint sensing solutions should be potentially used to detect malicious activities once an attachment is opened.
  • URL reputations analysis can be performed by firewalls and proxies checking for potential malicious domain or parameters.

Summarily,

COMMON IDENTIFIERS/NAMES BRONZE BUTLER, REDBALDKNIGHT and Tick.
PREFERRED TARGETS Enterprises in Japan and South Korea.
ACTIVE SINCE 2012
PREFERRED TARGETS Heavy manufacturing and the food & beverages industry in Japan.
PREFERRED ATTACK TOOLS xxmm, Datper, and Daserf malwares.

Concerned about threat actor groups like Tick showing up in your own security landscape?

Know more about the CYFIRMA’s Cyber Intelligence Analytics Platform (CAP):
https://www.cyfirma.com/products-services/about-cyber-intelligence-analytics-platform/

CYFIRMA’s products & services line-up: https://www.cyfirma.com/products-services/

Tactical Threat Intelligence: CYFIRMA Helps Cyber Defenders View Their Security Landscape Authoritatively

As we noted in our earlier posts on Strategic Threat Intelligence and Management Intelligence , Cyber Threat Intelligence may seem like a single comprehensive discipline, but really, it comprises of multiple modules that address individual steps in the overall cyber threat intelligence process. Herein, while strategic threat intelligence is suited for an audience inclusive of key decision makers, CEOs, board members etc, who may not necessarily be proficient in the topic of cybersecurity, Tactical Threat Intelligenceis specifically compiled for an audience that understands the finer technical details that contribute to the organization’s security landscape.

What is Tactical Threat Intelligence?

Tactical intelligence enables SOCs to proactively respond to cyberthreats and supports day-to-day detection and response to improve the enterprise’s cyber posture by using malicious IP, malware signatures and mutex, phishing domains, command and control centers, and YARA rules.

Tactical intelligence enables the organizations to:

  • Formulate correct rules and policies to blacklist, detect and restrict malicious traffic.
  • Detect infiltration and system infection.
  • Minimise phishing emails from reaching end-users.
  • Protect against sensitive data leaks.
  • Apply whitelisting/blacklisting proactively.
  • Avail real-time updating of AV malware signatures.
  • Ensure file integrity and desktop/endpoint monitoring.

Who is the target audience for Tactical Threat Intelligence reports?

Operators like CIRT, SOC, NOC and any other interfacing teams. Essentially, personnel who are part of the organization’s security setup and tasked with proactively responding to cyber threats, support detection and response to improve the organization’s cybersecurity posture by using malicious IP, malware signatures & mutex, phishing domains, botnet command and control centers.

What are the common sources employed by CYFIRMA to source Tactical Threat Intelligence?

CYFIRMA employs robust mechanisms for information collection and interpretation to obtain Tactical threat intelligence from the following sources:

  • Malware analysis
  • Open source and closed source
  • Real world communication
  • Data enrichment obtained from passive scanning and crawling

Why source Tactical Threat Intelligence from CYFIRMA?

Offering such key insights as tactics, techniques and procedures (TTPs) adopted by malicious actors, operational/tactical threat intelligence from CYFIRMA helps an organization’s IT team understand how a potential cyberattack will play out. Additionally, this helps cyber defenders decide on mitigation strategies, including detection techniques that are more suited for the job, enlist permissions from decision makers, identify and correct obvious vulnerabilities, etc.

n the context of CYFIRMA, tactical threat intelligence helps organizations safeguard their cyber posture by blocking known malware signatures, malicious domains, command and control centres or indicators of compromise. Using its proprietary Cyber Intelligence Analytics Platform (CAP), CYFIRMA offers tactical threat intelligence to assist organizations in cyber strategy, process and security control, predicting future cyber-attacks and business risks, and recommending proactive measures.

Importantly, CYFIRMA’s approach lays more emphasis on quality rather than quantity. CYFIRMA offers its clients a limited number of, yet highly researched and analysed IOCs that highlight a threat actor’s targeting of a specific industry and/or organization. This is in contrast to the common trend amongst cybersecurity companies wherein millions of irrelevant and poorly researched IOCs are offered.

Suggested Reading:Cyber Intelligence Analytics Platform (CAP) from CYFIRMA, the most intuitive, and responsive threat intelligence management system for your money.

In most organizations, the key decision makers like CEOs, Board of Directors, etc., are the secondary audience to these tactical threat intelligence reports. Thus, a technical representative (CISO, CTO, etc.) will have to act like a liaison to help the decision makers understand the finer details of these reports. Further, this representative’s recommendations will serve as the basis for the eventual decision coming from the leadership group. CYFIRMA’s on-point reporting helps streamline this conversation.

Listed below are some case-studies that further establish CYFIRMA’s proficiency as a robust aggregator of Operational/Tactical Threat Intelligence.

Case Study 1: CYFIRMA’s Tactical Intelligence Offering helped a Large US-based Financial Conglomerate Improve its Responses to Emerging Cyber Threats

Recently, CYFIRMA helped a large US-based financial institution with a sophisticated cyber threat center, identify and mitigate smartly targeted cyber threats in quick time. CYFIRMA helped the organization’s Security Operation Team to mitigate DDOS, malware Implants, DNS hijacking and data-stealing attempts by initiating daily updates to the cyber operation center to keep security controls current with the latest threat vectors (firewall, IDS/IPS, antivirus, proxies, SIEM).

Case Study 2: CYFIRMA’s Tactical Intelligence Offering helped a Well-Known Japanese Corporation Identify Complex Cyber Threats and Data Breaching Attempts

CYFIRMA was contracted by a large Japanese corporation with footprint in heavy industry, financial services, retail, and food and beverage domains to better understand cyber risks and mitigate them efficiently and effectively. CYFIRMA helped the organization’s security operations to mitigate ransomware, cryptojacking malware implants and data-stealing attempts by providing daily updates to the cyber operations center to keep security controls current with the latest threat vectors (firewall, IDS/IPS, antivirus, proxies, SIEM).

Additionally, the following highlights CYFIRMA’s Tactical recommendations to organizations. These insights help the organizations make the best use of their security assets.

  • Ensure End Point Detection and Response (EDR) solutions are enriched using our IOCs/IOAs to detect the threat actors proactively.
  • Fine tune the existing use cases in Security Information and Event Monitoring (SIEM) tool to detect the IOCs / IOAs.
  • Improve the detection signatures of Intrusion detection and preventions systems with custom rules to monitor and alert network intrusions.
  • Ensure the email security gateways, Email SPF, DKIM, DMARC, Advanced Threat protection systems, Firewall rules and network proxy controls are configured appropriately to detect the attacks in real time.
  • Classify and Segregate the organization business critical system a.k.a as Crown jewels and have a special security monitoring of those assets.
  • Identify user behavioural anomalies including privileged account monitoring, user account elevation, credential dumping, brute force attack, RDP connections and tunnelling, password spray attacks, malicious command line arguments that are detected and investigated by the cyber security team.

Further, the following lists CYFIRMA’s Tactical recommendations pertaining to IOCs:

  • Immediately apply IoC to IPS/IDS systems to thwart inbound packets that may be suspect.
  • Apply filters based on IoC to SIEM systems to detect inbound or outbound traffic on systems that contain sensitive information; particularly intellectual proprietary data.
  • Immediately analyze reported phishing/smishing email contents and test link access in air-gapped sandbox systems; filter and stop access to reported phishing emails or similar addresses by applying regular expression filters on mail relay systems.
  • Immediately block all known or reported phishing sites.
  • Establish closer perimeter monitoring on unusual ports, and ports provided by the attacker’s TTP.
  • Observe endpoint data movement alerts through email attachments, HTTP upload, or FTP upload.

Curious about what Tactical Threat Intelligence can do for your business?

Also, read the earlier blog posts in this three part series on Strategic Threat Intelligence and Management Intelligence.

Management Intelligence: CYFIRMA is Empowering Cyber Threat Intelligence for a Robust Security Landscape

As part of this blog series, we are discussing the three subcategories of Cyber Threat Intelligence (CTI). The primary focus here is to understand how threat data is collected, analysed and employed to enhance security at an organizational level.

In our last post we discussed Strategic Threat Intelligence.This post explains Management Intelligence as offered by CYFIRMA.

What is Management Intelligence?

Management intelligence allows the integration of insights on threat actor campaigns, attack mechanisms and tools, alongside internal processes like incident management process, change, configuration and release, and Patch management process.

Management intelligence enables the organizations to:

  • Implement reliable and effective decisions for security processes, policies, and response.
  • Assess the organization’s attack surface, threat, and vulnerabilities.
  • Improve and maintain the efficacy of security controls.
  • Update the organization’s overall risk register, including risk prioritization.
  • Update information security compliance matrix based on threat actor profile, method, and activities.

Who is the target audience for Management Intelligence reports?

CISO, Security Managers and Cybersecurity leads, and CSIRT leader. Effectively, individuals who can push the deductions received from analysis and deep insights into the organization’s security framework.

Why source Management Intelligence from CYFIRMA?

Often, organizations are forced to accommodate incomplete data as the security tools they employ may not assign a risk or threat accurately without correlation from additional sources of information.
Additionally, where data is collected from multiple sources, the huge volume of information may overwhelm analysts, thereby making it difficult to translate insights into actions. CYFIRMA’s management intelligence allows for the merging of data from multiple sources, followed by automated analysis to draw actionable insights. Thus, organizations can arrange risk on a prioritization scale, selectively deploying organizational resources to detect, prevent and remediate potential threats.

Suggested Reading: Cyber Intelligence Analytics Platform (CAP) from CYFIRMA, the most intuitive, and responsive threat intelligence management system for your money.

How can key decision makers ensure an organizational impact with management intelligence?

CYFIRMA advices that all threat intelligence themed activities undertaken by the organization are tuned for actionability. The leadership group can consult its specialists and invest in a threat intelligence management system to simplify the flow of cybersecurity related data through the organization, and simultaneously, educate its workforce against ignoring obvious red-flags raised after the analysis of such data, for example, CYFIRMA reports spear phishing campaign targeting specific organization and Security leader can use the intelligence to alert toward their employee.
Importantly, the key decision makers are responsible for funding the build-up of the ideal security landscape, one that best serves its specific cybersecurity use cases.

Listed below are some case-studies that further establish CYFIRMA’s proficiency as a robust aggregator of management intelligence.

Case Study 1: CYFIRMA’s Management Intelligence helps a Large Japanese Corporation Draw the Maximum Productivity out of its Cyber Security and Risk Management team

Recently, a large Japanese corporation with footprint in the heavy industry, financial services, retail, food and beverage sectors contracted CYFIRMA to better understand cyber risks and mitigate them efficiently and effectively. CYFIRMA helped the organization’s Cyber Security and Risk Management team to understand threat actors’ profiles and risk to organization, leading to the Compliance matrix being made stricter related to the end user policy, alongside the updating of the incident reporting process.

Case Study 2: CYFIRMA’s Management Intelligence Offering helps a US-based Financial Institution Update its Risk Register and Incident Management Routines

A large US-based financial institution with a sophisticated cyber threat center contracted CYFIRMA to streamline their risk identification and management procedures. CYFIRMA helped the organization’s risk management team to incorporate broader risk around cybersecurity issues, eventually resulting in the updating of the organization’s risk register and incident management plan.

Curious about what management intelligence can do for your own business?

Also, read our earlier post in this three part series on Strategic Threat Intelligence.

Stay tuned for our final post in this series addressing Tactical Threat Intelligence.

Strategic Threat Intelligence: CYFIRMA Helps Organizations Understand Their Security Landscape

At the onset, from an organization’s perspective, Cyber Threat Intelligence (CTI) may seem like a single comprehensive discipline, but in reality, it can be broken down into subcategories that address individual steps in the overall cyber threat intelligence process. These subcategories include Strategic Threat Intelligence, Management Threat Intelligence and Tactical Threat Intelligence.

As part of this blog series, we will address these subcategories individually. The primary focus here is to understand how threat data is collected, analysed and employed to enhance security at an organizational level.

Let us start with Strategic Threat Intelligence.

What is Strategic Threat Intelligence?

Strategic Intelligence offers insights into cyber risks by attributing threat actors, their background, motives, tools and techniques. It allows the organization’s to apply cyber intelligence to strategy, governance and policies. This is primarily consumed by the key decision makers within the organization.

In more detail, Strategic Threat Intelligence offers risk-weighted threat intelligence applied to an organization’s overall business strategy thereby enhancing its ability to proactively and continuously optimize the security posture based on its risk profile.

Strategic intelligence enables the organizations to:

  • Identify active and imminent threats and risks to the organization’s industry and brand.
  • Determine the cyber risk profile and mitigation actions.
  • Prioritize cybersecurity investments and initiatives based on risk to critical components of the organization such as people, processes and technologies.
  • Qualify and quantify the cybersecurity risks relevant to the organization.
  • Optimize and maintain the organization’s security posture.

Who is the target audience for Strategic Threat Intelligence reports?

Senior leadership, Security Director, C.I.S.O, etc. CYFIRMA’s strategically put together reports should help clarify a clearer picture about cyber risks, the business decisions associated with them, and the implication of these threats to the organization. Armed with this strategic CTI report, business owners can better direct cybersecurity efforts and associated investments to ensure they are in line with the business’s top priorities.

What are the common sources employed by CYFIRMA to source Strategic Threat Intelligence?

  • Online sources spread across the surface web and deep/dark web.
  • Media, both print and online, locally and nationally.
  • Policy documents released by governmental organizations, and specific groups of interest.
  • Social media activity involving groups or individuals of interest.
  • Free online documents released by security organizations.
  • Industry specific publications, etc.

Why source Strategic Threat Intelligence from CYFIRMA?

The greatest limitation when dealing with Strategic Intelligence’s role in CTI is the quantum of available information and how the same can be processed to fit a strategic report. Availability of high-value sources (across the deep/dark web, surface web, etc.) ensures that there will be a tremendous amount of information to examine. Additionally, if the available source is in a foreign language then the resultant insights can be impacted by poor translation.

CYFIRMA employs a mix of cutting-edge technology, analytics and expert personnel to examine lots of such high-value sources in quick time and helps businesses optimize resource allocation and risk-management initiatives by understanding the threat actors most likely to target them. The assimilated insights address such concerns as might be raised by a key decision maker, including, risk scores, cyberattack history of a particular geographical region or industry, and expected outcomes for a specific business action.

Listed below are some case-studies that further establish CYFIRMA’s proficiency as a robust aggregator of Strategic Threat Intelligence.

Case Study 1: CYFIRMA’s Strategic Intelligence offering helped a Japanese Conglomerate finetune its Security Profile

A little while back, CYFIRMA helped a large Japanese corporation with footprint in the heavy industry, financial services, retail, and food and beverage sectors, better understand cyber risks and mitigate them efficiently and effectively. As the standard approach, CYFIRMA helped the organization’s CISO to better understand the cyber threat profile, leading to the updating of cyber governance and policies to incorporate internal risk and breach scenarios.

Case Study 2: CYFIRMA Strategic Insights helped a Large US Financial Institution Refine and Upgrade its Security Strategies

A large US-based financial institution with a sophisticated cyber threat center needed to refine their security policies for a more inclusive and expansive response against ever emerging cyber threats. CYFIRMA helped the organization’s CISO to better plan cyber initiatives and policies, leading to the updating of their cyber strategy with an integrated plan to incorporate Advanced Persistence Threat (APT) and data-loss protection controls.

Additionally, the following highlights CYFIRMA’s strategic recommendations to organizations. These insights help the organizations make the best use of their security assets.

  • Plan periodic Red Team exercise to measure the effectiveness of the people, processes, and security technologies used to defend the environment. Red Team exercise helps organizations to improve security controls detection, enhance defensive capabilities, and measure the overall effectiveness existing security operations.
  • Perform yearly Cyber Benchmarking exercise to benchmark the security performance against industry peers, measure the impact of risk mitigation efforts, and report security progress and results to Boards of Directors more clearly and effectively.
  • Enable emerging security solutions like deception technology powered with machine learning helps in real-time breach detection and prevention.

Curious about what strategic threat intelligence can do for your business?

Stay tuned for our next blog post in this series addressing Management Intelligence.

‘AI’ming Higher: CYFIRMA Named in Enterprise Security Magazine’s “Top 10 Artificial Intelligence Solution Providers – 2019

It looks like CYFIRMA’s quest to emerge as the absolute market leader when it comes to the integration of bleeding edge Artificial Intelligence (AI) techniques into the Cyber Threat Intelligence routine has received a massive shot in the arm. The influential Enterprise Security Magazine has selected CYFIRMA as part of its “Top 10 Artificial Intelligence Solution Providers – 2019” listing.


Source: Enterprise Security Magazine, April-2019 edition, pages 16 & 17

In a world where AI is gaining wide applications across an ever incrementing number of business verticals, CYFIRMA is actively employing AI and Machine Learning (ML) to power its unparalleled Cyber Threat Visibility and Intelligence product and service offerings. The commitment to this next iteration of the global cybersecurity landscape where AI/ML are key contributors, witnesses CYFIRMA as a pioneer and an innovator, driving highly intuitive, relevant, prioritized and accurate cyber insights that apply to the customer’s specific environment and industry.

View the associated article on the Enterprise Security Magazine: https://artificial-intelligence.enterprisesecuritymag.com/vendors/cyfirma/2019

The Latest Feather in CYFIRMA’s Cap

Thus far, 2019 has been a highly productive year for CYFIRMA where accolades, recognitions and exciting new undertakings and partnerships have been the norm. Fresh off CIOApplications’ listing of CYFIRMA as part of its “Top 25 Innovative Cybersecurity Companies 2019” and being featured on Cyber Startup Observatory© – Japan CyberSlide© and Singapore CyberSlide©, this citation from Enterprise Security Magazine is further vindication of CYFIRMA’s growing posture amongst the global fraternity of cybersecurity analysts, experts and industry leaders.

The “Top 10 Artificial Intelligence Solution Providers – 2019” list is compiled by a distinguished panel, comprising of noted security experts, leaders in the cybersecurity space, and eminent board members overseeing the Enterprise Security Magazine. This marks CYFIRMA’s debut as part of this influential listing.

“Looking at the eminent list of awardees, we are very excited to be featured as one of the Top 10 Artificial Intelligence Solution Providers – 2019,” said Kumar Ritesh, CYFIRMA Chairman and CEO. “Advance AI engines are at the heart of our solution, which picks up early attack indicators from multiple sources and applies our proprietary algorithms to predicts the next potential cyberattack.”

The Road Ahead

Currently, CYFIRMA is in the final stretches of launching its proprietary Cyber Intelligence Analytics Platform (CAP) v2.0 to customers in Japan and across the world. The latter helps organizations with real-time insights into emerging threats, including such information as attack motives and methods utilized. CAP automatically aggregates, correlates and analyses cybersecurity information and events, as derived from thousands of data sources, including the deep/dark web and obscure hacker forums. The targeted intelligence thus obtained helps organizations be ready for cyberattacks that are professionally put together and effectively manage related cyber risks before they actually occur.

Know more about the CAP: https://www.cyfirma.com/products-services/about-cyber-intelligence-analytics-platform/

CYFIRMA’s products & services line-up: https://www.cyfirma.com/products-services/

About ENTERPRISE SECURITY:

Constituted to help organizations adapt to the deep-seated changes taking place in their cybersecurity landscape, ENTERPRISE SECURITY shortlists and speaks about security solutions which can help organizations prepare for radical changes and mainstream attacks. It follows a unique learn-from-peer approach where chief security officers and decision makers share their innovative solutions along with their industry expertise and wisdom.

For more information, visit http://www.enterprisesecuritymag.com/

CYFIRMA’s CTI and CTV Offerings Put the ‘Customer First’ and Embraces a Dynamic Approach to Cybersecurity

Today, organizations cannot rely on just basic tools like antivirus and firewalls to ensure complete protection from threat actors and the ever evolving cyberattacks. A static approach, one where security systems are waiting to detect an ongoing attack, tackle it, and hopefully mitigate it, renders critical systems and sensitive information at constant risk. Further, leading to financial and reputational loss.

CYFIRMA’s Cyber Threat Intelligence (CTI) and Cyber Threat Visibility (CTV) offerings put the ‘customer first’ and offer highly relevant, pointed and customized insights on the customer’s individual cybersecurity landscape, alongside a broad snapshot of the latest news and happenings with regards to threat actors and cyberattacks from across geographies.

Let’s begin by understanding what these key concepts are and how CYFIRMA’s CTI and CTV themed products and services are differentiated in this very competitive space.

What is Cyber Threat Intelligence (CTI)?

Cyber Threat Intelligence (CTI) is an area of cybersecurity that engages in the identification, collection and analysis of information relating to current and probable cyberattacks that are likely to endanger the confidentiality, integrity, and safety of an organization, or its assets.

Threat intelligence is proactive, thereby intercepting cyber threats before they have manifested to causing data breaches and costly damage control measures thereafter. CTI is consumed by organization and institutions to assess the threats posed to them directly, thereby leading into streamlining the cyber security strategies to protect their brand, reputation, business operations, infrastructure, etc. Inputs offered as part of the CYFIRMA’s CTI feeds are actionable, current, and aim to future proof organizations and institutions against similarly recurring risks.

What is Cyber Threat Visibility (CTV)?

Cyber Threat Visibility (CTV) is an essential component of Cybersecurity. CYFIRMA through this service provides visibility on a variety of cyber threats and minimizes the potential impact of a cybersecurity event to organizations and institutions.

Predictive, Relevant and Prioritized: Why CYFIRMA’s CTI and CTV are the difference makers?
As the global cybersecurity landscape is constantly challenged by threat attacks and malicious actors that are continually getting smarter and better at hiding their activity, an organization’s defensive tactics must also evolve and get smarter at an equivalent rate. Herein, CYFIRMA’s CTI and CTV offerings- powered by Artificial Intelligence (AI) and Machine Learning- offer a distinct edge. Additionally, the following features sets CYFIRMA’s products and services apart from its competition.

Always ‘On’ approach to Threat Intelligence

Traditional vulnerability scans, while potent, leave you in the dark until the next scheduled scan. With CYFIRMA’s proprietary Cyber Intelligence Analytics Platform (CAP), customers can eliminate the waiting cycle by accessing the latest threat intelligence from a carefully assembled online dashboard.

CTI highlights the threat actors and their malicious activities prevalent in the customer’s cybersecurity landscape. Additionally, it prioritizes vulnerabilities based on risk and lists actionable steps to mitigate the highlighted issues.

With CYFIRMA’s threat intelligence and vulnerability assessment, hints about potential cyberattacks and data breaches based off the initial Indicators of Compromise (IOC) are unearthed. Next, these are tallied with external threat intelligence to offer the customer context, and identify the potential threat actor, attack method and the attacker’s motivation.
Know more about the Cyber Intelligence Analytics Platform (CAP), HERE.

Deep insights from the Deep/Dark web and hacker forums

With cybercriminals indulging in inventive new malicious strategies like employing threat tools for hire, signing up fellow hackers for big-ticket jobs with professionally compiled contracts, and the growing instances of state sponsored threat attacks, conventional threat intelligence measures may not be able to source the bigger picture and identify these tell-tale signs of a dynamic hacker ecosystem.
CYFIRMA’s expertise in listening into hacker conversations across the deep/dark web, and similarly influential but secretive hacker forums has allowed it to successfully predict emerging trends in cyberattacks and offer substantially more effective techniques to its customers to plug vulnerabilities in their cybersecurity posture and avoid interest from these cybercriminals. In fact, thousands of online sources contribute to CYFIRMA’s intelligence pool.

Highly actionable insights offered as Strategic, Management and Tactical intelligence

CYFIRMA segregates its CTI into strategic, management and tactical intelligence to facilitate role based consumption of these insights. CYFIRMA pays close attention to ensure that the sourced insights be received and digested immediately, while the audience absorbs the intensity of the information at their own comfort levels.
For example, strategic intelligence offers a broad overview of the customer’s threat landscape, without naming threat actors or their attack strategies, and thus, is appreciated by the top management, the CEO and the board, who may not otherwise understand the technicalities involved. Meanwhile, tactical intelligence analyses real-time investigations, events and provides day-to-day operational support. This information is more in line with what a on-the-ground IT team will require to address an incoming threat.

Unparalleled proficiency in early warnings

Importantly, powered by its teams of experienced cybersecurity analysts wielding cutting edge technologies and tools, CYFIRMA boasts of an enviable threat detection rate. In 2018, out of CYFIRMA’s 16 early warnings, 11 were confirmed to be active in the wild. This allows its CTI- a fair mix of predictive and prescriptive insights- to be highly sought after amongst organizations across a wide range of business verticals. In 2019, CYFIRMA’s influence has grown steadily, in Japan- its home base, and elsewhere.

Faster analysis leading to confident responses

Detrimental cyber threats to businesses and institutions have a habit of manifesting rapidly. While organizations banking on the ‘this-cannot-happen-to-us’ logic are left unawares, businesses that subscribe to cyber threat intelligence and cyber threat visibility are employing a proactive approach to emerging threats.
Especially, with CYFIRMA’s CAP, the automation saves on time, allowing for faster analysis of threat intelligence, leading to a more confident response to potential cyberattacks.

Does the CAP sound like an ideal addition to your cybersecurity infrastructure?

View CYFIRMA’s product and services portfolio @
https://www.cyfirma.com/products-services/ ; https://www.cyfirma.jp/products-services/

Breaking the Perimeter: CYFIRMA at the Security Days Spring 2019, Tokyo

If you are a professional or an entity in the cybersecurity space, the Security Days Spring 2019 that was held at the JP Tower, Tokyo, from 6th-8th March 2019, would have definitely commanded your attention. A robust platform for cybersecurity firms to exhibit their products and services, Security Days 2019 was expected to be of particular interest considering the escalating cases of cyber threats that were witnessed in 2018, and the corresponding developments from top players in the global cybersecurity landscape.

This year, CYFIRMA was highlighted center stage, as a sponsor and exhibitor at the event. Additionally, on the final day, 8th March, CYFIRMA Chairman and CEO Kumar Ritesh was slated to present a keynote lecture highlighting the Japanese cybersecurity landscape, emerging industry trends, and CYFIRMA specific developments, amongst other details of interest.

Suggested Reading:Understanding the Japanese Cyber Threat Landscape and Corresponding Defensive Strategies: Preview of CYFIRMA’s Keynote Lecture at Security Days 2019


CYFIRMA’s aesthetically appointed booth at the Security Days 2019

Day 1, 6th March: Gaining a semblance of CYFIRMA’s popularity amongst its peers

CYFIRMA is based out of Japan and Singapore, thus its resourceful employees from the Japan office were at hand to interact with the horde of industry specialists and cybersecurity enthusiasts that were streaming through the door. There was a lot to unpack too, including its well-received Cyber Threat and Risk Predictions for 2019 and the updated version (v2.0) of its proprietary Cyber Intelligence Analytics Platform (CAP).


Cybersecurity 101: Engaging visitors with insights, information and an introduction to CYFIRMA

 


Putting the best foot forward: Team CYFIRMA at the Security Days Spring 2019 event

The opening day of the event highlighted two important things from CYFIRMA’s perspective: the general awareness pertaining to CYFIRMA’s brand and offerings, and the growing maturity amongst a predominantly Japanese customer base in terms of new-age cybersecurity concepts, tools and methodologies. There was plenty of excitement and interactions at the CYFIRMA booth and potential customers and partners were engaged in insightful discussions that highlighted CYFIRMA’s constantly upgrading expertise in this competitive space.

Day 2, 7th March: Building on the momentum and interacting with a knowledgeable audience



The CYFIRMA booth was constantly in the thick of things

In recent times, the Japanese market has been particularly susceptible to cyber threats that aim to disrupt its social order, business domination and overall reputation. As more and more Japanese businesses wake up to the need for robust cybersecurity solutions, firms like CYFIRMA are discovering an attentive and inquisitive audience. This fact was perfectly demonstrated on the second day of the Security Days 2019 event as a throng of interested professionals, clients and partners visited CYFIRMA’s booth to understand its take on predictive three layered cyber threat visibility and intelligence.

Day 3, 8th March: Kumar Ritesh’s keynote lecture steals the show!



Packed to the rafters: Kumar Ritesh’s keynote lecture at the Security Days Spring 2019

With 20+ years of experience in the enterprise security space, CYFIRMA Chairman and CEO, Kumar Ritesh, is an authority when it comes to cybersecurity and its application across the modern IT infrastructure. His much anticipated keynote lecture was a sold-out event, wherein he addressed such topics as Japan’s growing posture as a target for cyberattacks, why CYFIRMA is focused on Japan, major cyber threats impacting the Japanese industry and society, and holistically, why Cyber Threat Intelligence is important in the current scheme of things.

Additionally, this lecture highlighted the importance of Cyber Threat Intelligence based countermeasures that can be employed against hackers targeting organizations and institutions, especially in Japan, and was very well received by the assembled audience. Again, CYFIRMA, as a brand, was able to connect effectively with the highly knowledgeable audience and promote its products and services as a future-proof, all-inclusive cybersecurity solution for organizations and institutions.


Scenes from the keynote lecture: Kumar Ritesh offering insights from CYFIRMA’s Annual Cyber Threat Intelligence Report

CYFIRMA’s participation at the Security Days Spring 2019 event was a resounding success. While thanking the visitors, fellow participants and the organizers for putting together a professionally executed event, CYFIRMA reiterates its intention to be associated with future editions of Security Days.

CYFIRMA is Recognized in the prestigious Cyber Startup Observatory©- Singapore CyberSlide©, March 2019

The updated Cyber Startup Observatory© – Singapore CyberSlide© highlights cybersecurity startups and innovative established companies with solutions for the financial services, healthcare, e-commerce, education, critical infrastructures, manufacturing, transportation, law enforcement and intelligence agencies verticals. In the Singapore CyberSlide©, CYFIRMA was listed under the following categories:

  • Training and Education
  • Cyber Intelligence
  • Artificial Intelligence
  • Cyber Posture
  • Incident Response and Forensics

 

CYFIRMA is excited that its unparalleled cyber threat visibility and intelligence suite of product and services is getting noticed and acknowledged. Equipped with CYFIRMA’s relevant and prioritized cyber threat insights, organizations and institutions can keep their cybersecurity posture up-to-date, resilient and ready against upcoming cyber-attacks.

Know more about CYFIRMA’s products and services.

About Cyber Startup Observatory©

The Cyber Startup Observatory© is an initiative to connect state of the art cybersecurity startups coming from the most dynamic innovation hubs from all around the world with the financial services, healthcare, e-commerce, critical infrastructures, public sector, manufacturing, technology & consulting, law enforcement and education verticals globally.
Visit website | View Singapore CyberSlide© on Cyber Startup Observatory© website

CYFIRMA is Recognized in the prestigious Cyber Startup Observatory©- Japan CyberSlide©, March 2019

The updated Cyber Startup Observatory© – Japan CyberSlide© highlights cybersecurity startups and innovative established companies with solutions for the financial services, healthcare, e-commerce, education, critical infrastructures, manufacturing, transportation, law enforcement and intelligence agencies verticals. In the Japan CyberSlide©, CYFIRMA was listed under the following categories:

  • Cyber Intelligence
  • Artificial Intelligence
  • Incident Response and Forensics
  • Cyber Posture
  • Training and Education

CYFIRMA is excited that its unparalleled cyber threat visibility and intelligence suite of product and services is getting noticed and acknowledged. Equipped with CYFIRMA’s relevant and prioritized cyber threat insights, organizations and institutions can keep their cybersecurity posture up-to-date, resilient and ready against upcoming cyber-attacks.

Know more about CYFIRMA’s products and services.

About Cyber Startup Observatory©

The Cyber Startup Observatory© is an initiative to connect state of the art cybersecurity startups coming from the most dynamic innovation hubs from all around the world with the financial services, healthcare, e-commerce, critical infrastructures, public sector, manufacturing, technology & consulting, law enforcement and education verticals globally.
Visit website | View Japan CyberSlide© on Cyber Startup Observatory© website

CYFIRMA Named in CIOApplications ‘Top 25 Cybersecurity Companies – 2019’

PRESS RELEASE
TOKYO & SINGAPORE, March 12, 2019- CYFIRMA, a cybersecurity start-up and an industry leader in Cyber Threat Visibility and Intelligence, has been recognized as one of the “Top 25 Innovative Cybersecurity Companies 2019” by CIOApplications, a technology print magazine based in Florida, US. The recognition is awarded to CYFIRMA for its unparalleled Cyber Threat Visibility and Intelligence product and services suite, specifically its:

  • Ability to predict attacks that are most likely to occur in an industry and client environment
  • Unique approach to present risks and threat indicators at the planning stage, versus the execution and exploitation phase of a cyber-attack
  • Capability to provide a client-tailored view of cyber threat landscape using three-layered comprehensive cyber intelligence (strategic, management and tactical).

This is CYFIRMA’s first appearance in CIOApplications’ coveted annual list. The companies making up this list are selected by an eminent panel consisting of members of the CIOApplications’ editorial board and industry experts with an aim to recognize and promote innovation and technological entrepreneurship across business verticals.

“We are glad and very excited to be featured as one of the Top 25 innovative Cybersecurity Companies 2019. Thankful to our clients, partners, employees and investors for their continued trust and belief in CYFIRMA,” said Kumar Ritesh, CYFIRMA chairman and CEO. “Cyber Threat Visibility and Intelligence is not a technical control, it is a business control which should be applied at all levels of organizational governance including an organization’s business drivers, investment decisions, resource planning, strategy, governance, policies, security controls and people.”

The age of random attacks is going away; time is upon us to face planned cyber-attacks. Today, hackers and perpetrators are sponsored to launch innovative and gruesome cyber-attacks against a target while organizations have limited resources. It is the right time to integrate and adopt Cyber Threat Visibility and Intelligence into an organization’s Information and Cybersecurity functions and Risk Management, Regulatory and Compliance verticals to provide a holistic intelligence-driven approach to cybersecurity.

“CYFIRMA is in the midst of rolling out its proprietary AI/ML-enabled Cyber Intelligence Analytics Platform (CAP) v2.0 to customers in Japan and globally. We are committed to helping organizations and institutions to decipher the next move of potential cyber-attackers and undertake proactive measures in advance by incorporating cyber threat visibility with threat hunting, attribution, automation and orchestration to deliver real-time insights into emerging threats, attack motives and methods,” said Kumar Ritesh.

About CYFIRMA:
Headquartered in Singapore and Tokyo, CYFIRMA is a cybersecurity company that provides Cyber Threat Visibility and Intelligence products and services by aggregating, correlating and analysing threat information from thousands of sources using its proprietary ML/AI-enabled Cyber Intelligence Analytics Platform. Equipped with CYFIRMA’s relevant and prioritized cyber threat insights, organizations and institutions can keep their cybersecurity posture up-to-date, resilient and ready against upcoming cyber-attacks. View CYFIRMA’s product and services portfolio: www.cyfirma.com ; www.cyfirma.jp

About CIOApplications:
CIOApplications is a technology magazine, published from Florida, US, that is a prime platform for CIOs to discuss innovative enterprise solutions. It is a medium that helps upcoming enterprise IT vendors to engage and showcase their solutions for enterprises. CIOApplications helps technology leaders by providing analysis on new technologies and gives a better understanding of the role that enterprise solutions play in achieving business goals.

For more information, visit http://www.cioapplications.com/ and https://www.cioapplications.com/magazines/March2019/CyberSecurity/

Footnote:
This press release was originally published on March 12, 2019, HERE.

Read the original article from CIOApplications titled ‘CYFIRMA: Delving into the Secrets of the Deep, Dark Web’ featuring our Chairman & CEO, Kumar Ritesh, and exploring CYFIRMA’s unique proficiency in new age cybersecurity strategies.

Download the article here

Understanding the Japanese Cyber Threat Landscape and Corresponding Defensive Strategies: Preview of CYFIRMA’s Keynote Lecture at Security Days 2019

As part of the ‘Security Days Spring 2019’, scheduled from 6th through 8th March 2019 at the JP Tower, Tokyo- a coming together of the global cybersecurity fraternity- CYFIRMA’s Chairman & CEO, Kumar Ritesh, will conduct a keynote lecture echoing the importance of Cyber threat intelligence based countermeasures that can be employed against hackers targeting organizations and institutions in Japan and across the world.

This lecture is slated to offer a high-level view of the cybersecurity trends in 2019. Registrations are open. To signup for the event and source additional details visit: https://lnkd.in/f-29ZQf

Attendees can expect a wealth of information, veritable insights into the workings of the modern day hacking machinery, as disclosed by one of the most prominent and reputed figures in the global cybersecurity landscape. As an entrée, herein is a sample of topics that will be explored:

  • Background of malicious intent towards Japanese organizations: A strategic overview of the threat landscape that is bearing down on the Japanese organizations, institutions and public entities.
  • Threat attacks on Japan in 2018: An insightful recap of the threat attacks and actors that wreaked havoc on Japanese organizations and institutions in 2018. Who did what, when, and how?
  • An insight into 2019: Based off CYFIRMA’s Annual Cyber Threat Intelligence report for 2019, explore the potential cyber threats, threat actors, attack types and malicious tools that will impact the Japanese businesses and industrial infrastructure in 2019.
  • Know your enemy: Sounds simple enough but seeped in the cyber threat intelligence routines and the rapidly innovating manners of the average threat actor, knowing the enemy is crucial for any organization that is susceptible to cyberattacks. Kumar Ritesh hopes to reiterate this very basic rule.
  • Introducing the Cyber Intelligence Analytics Platform (CAP) v2.0: CYFIRMA’s primary cybersecurity product, CAP is a comprehensive, dashboard driven application that helps organizations identify, understand and mitigate cyber threats that are targeting them.
  • Predicting potential cyber threats tailored to specific organizations with CAP: Kumar Ritesh will expound on the advantages, both in terms of current threat intelligence and understanding of future cyber threat possibilities, when organizations employ CYFIRMA’s CAP application. Importantly, attendees will view the relative ease with which potentially harmful cyberattacks towards specific organizations can be anticipated and shielded against.
  • Success stories, the positive impact of CAP with existing clients: Understand the nuances of the fully kitted Cyber Intelligence Analytics Platform (CAP) by way of examples from CYFIRMA’s existing clients, and specifically, the unique conditions presented by individual industries that our clients are nestled under.
  • LIVE demonstration of the aforementioned Cyber Intelligence Analytics Platform (CAP) v2: Deep dive into the sophisticated UI that will help your organization identify its cyber enemies, their attack methodologies, the malicious tools they will likely use, and a plethora of similar details.
  • Case Study: How a prominent Japanese manufacturing conglomerate used and benefitting from CAP, thanks to a set of advanced and sophisticated use cases.
  • Explore the CYFIRMA Ecosystem: A detailed analysis of how, CYFIRMA and its esteemed business partners can improve, streamline and future-proof your organization’s cybersecurity posture.

Join up to know more. For details, visit: https://lnkd.in/f-29ZQf

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.