What is going on with Lapsus$?

What’s going on with Lapsus$

By Adam Parsons, CYFIRMA Cyber Threat Intelligence

 

 

Lapsus$ has hit the headlines recently partly due to the mega-corporations that they appear to have successfully hacked and partly due to the claims that they are or were led by a 16-year-old.

Indeed, there have been a number of arrests, most recently a 16-year-old and a 17-year-old appeared in court in the UK charged with a number of cyber offenses. However, as the above post on their telegram chat group shows they have no intention no of stopping.

The telegram channel was their only official communication method where they have published stolen data, and in at least one instance, held a vote on who to attack next.

The group chat is used to share stolen data (not linked to Lapsus$), tools and requests for hacking help. However, the channel is not quite a wild west…there are rules:

  1. No porn
  2. Not too much trolling
  3. No spam

But outside of these rules anything goes…

The channel is not just for English speakers, there are a significant number of users communicating in Portuguese. This is potentially a throwback to the first few public victims of Lapsus$ being the Ministério da Saúde do Brasil (Ministry of Health of Brazil) and latterly Portugal’s Impresa media group.

Given that the rise of Lapsus$ has coincided with the downfall of Raidforums, a popular entry-level hacking forum, it appears that the Lapsus$ chat has attracted a significant number of like-minded individuals.

The telegram group still bears the name of its initial victim (https://t.me/saudechat), we can assume that it was initially set up to share the stolen data from the Ministério da Saúde do Brasil. That has long since passed, but still, the attacks keep coming even after what many thought would be arrested that would bring about their downfall. Likewise, the doxing of one of the supposed main members of the group has also not stopped their progress.

Given the naming of the telegram channel, we can assume that their ongoing activity was not planned. One would expect that they are making it up as they go along, thinking barely one step ahead. This may be one reason law enforcement is having such problems shutting them down. There is no plan, victims are targets of opportunity and profit is not the main motivation.

It has been reported that members of the group originate from the Sim Swapping world, a relatively small sub-section of the hacking community that is specifically focused on illegally obtaining control of phone numbers and subsequently control of their linked social media accounts. These social media accounts have then been used in several high-profile scams often involving crypto. Alternatively, sim swaps have been used to gain control of specific users’ social media accounts due to a unique Twitter or Instagram handle that can then be sold in online forums. Much like Lapsus$, individuals arrested in sim swapping are largely of a similar youthful age.

This might explain the brazen attacks against mega-corporations and so far their lack of interest in regularly using these attacks for financial gain or at least it does not appear to be their main motive. Hacks of Okta and Microsoft are by far more valuable than even the most high-profile Twitter handle. The reasons for these attacks are quite bizarre. The hack of Nvidia was followed by a demand to remove all Lite Hash Rate (LHR) limitations to its Graphics Processing Unit (GPU) hash rate that prevents faster crypto mining activities. It also wanted Nvidia to publish the base codes of its GPU drivers as open-source, making them publicly accessible and openly modifiable forever. Neither of these demands would directly benefit Lapsus$ and seem more targeted at pleasing their fans and enhancing their reputation amongst the community.

 

How are they doing….what they do!

There have been a number of in-depth reports on how Lapsus$ has evaded the defenses of their victims. Researching the group, we discovered how incredibly simple some of their methods were.

The technical skills and social engineering techniques bear resemblance to those used in the sim swapping world, which is after all where they first got started.

Lapsus$ group put out a call on their telegram channel to employees at potential victim companies, as seen below:

 

Whilst this was widely mocked in cybercriminal communities for the lack of hacking prowess it takes to recruit insiders to simply give you access, it has been reported that this was in fact the reason Microsoft fell prey to the attack. Lapsus$’s approach may seem less sophisticated compared with advanced threats groups, but as we have witnessed, they are a force to be reckoned with. Given that Lapsus$ appears to have used this technique as early as November 2021, we can easily assume that it has been more successful than reported.

Aside from this, Lapsus$ techniques are a throwback to their sim swapping days and revolve around social engineering techniques.

 

Lapsus$’s methods – they seem so easy

 

Sim swapping involves obtaining control of a victim’s phone number by tricking the phone service provider to transfer the phone number and therefore control to another device as per the above illustration. This method requires a significant level of knowledge of potential questions posed by the phone service provider and their requisite and often personal answers. Lapsus$ likely makes use of openly available data through social media and previously breached data to answer these questions.

Once the number has been transferred, threat actors can then get access to most if not all the victim’s linked accounts through password resetting via the transferred phone number where the phone number is used as a method of recovery. Email accounts often hold valuable information, including account details, passwords and answers to security questions. Lapsus$ has also been reported to deploy Redline malware, a password and session token stealer.

There is another avenue much like sim swapping where it requires the threat actor to make a call impersonating the victim. The hacker will call the employee’s IT department and attempt to have their password reset. Depending on the security stance of the organization, this often requires answering numerous questions which are personal to the victim.

Once the victim’s password has been obtained, there is another line of defense.

Multifactor Authentication (MFA) or 2-factor authentication (2FA) comes in many forms as it is an additional security measure should a password be leaked or otherwise obtained by an unauthorized party. MFA requires the approval or authentication on an additional device to grant access.

Once an employee password is known, the group would need to pass MFA. Should they have access to the victim phone number and MFA is linked to the compromised number, access can be obtained. If this is not the case, then there are a number of other methods that can be used.

Spamming employees with push requests and automated calls to get MFA approval is one such method. Lapsus$ even brag about this technique on their channel “Call the employee 100 times at 1 AM while he is trying to sleep, and he will more likely to accept it. Once the employee accepts the call, you can access the MFA enrolment portal and enroll another device”

Whilst bombarding an employee with MFA requests creates a lot of noise and could potentially alert the victim, there are other stealthy methods at play. One such method involves sending MFA push requests a few times a day, hoping the employee’s guard drops momentarily.

Opting for more advanced MFA such as FIDO2 provides a higher degree of security. FIDO2 requires the authentication to be performed on the device that is used to log in, making remote logging in on any other device ineffective.

Of course, awareness by employees of these techniques is key. Suspicion should immediately be raised if an unrequested MFA notification is received. Likewise, IT staff must remain vigilant to suspicious password resets requests. Staying updated on what is shared online on social media and awareness of any personal data that has been leaked will help avoid becoming a victim.

 

So what’s next from Lapsus$?

As we have seen, law enforcement coming down on Lapsus$ has not stopped the group’s activities. We can assume a leadership group is controlling the telegram channel rather than an individual. One would expect that it is a point of pride that the channel stays up despite law enforcement action. The group has a plan to use Element.io instant messaging platform as a backup should their Telegram channel shut down.

In the meantime, the channel continues to grow, as Lapsus$ have triumphantly noted that their telegram chat group now has over 30,000 members. Should the leadership group be taken down, it would not be out of the question for one of these members to form their own Lapsus$ franchise if they have not already done so. The added humiliation of a multinational corporation being hacked by a group most associated with teenagers doing it for the ‘Lolz’ would make the Lapsus$ name an attractive brand.

APTS have imaginative animals as their mascot, Hacktivists have Guido Fawkes masks, will malicious teenagers use the Lapsus$ name as their logo?

If we were to illustrate a picture of the Lapsus$ group based on their history and current trajectory, we should draw a multi-headed hydra, each head laughing as Law Enforcement arrests teenager after teenager, and the regrown heads hack their way through the sophisticated defenses of company after company……just for the Lolz.

 

A New World Order in the Making – Observations on the Latest Geopolitical Development and the Impact on Cybersecurity

A New World Order in the Making – Observations on the Latest Geopolitical Development and the Impact on Cybersecurity

 

Ongoing Ukraine – Russia conflict could well be the straw that finally breaks the camel’s back. Slowly but surely battle lines are being drawn, awkward allegiances abandoned, muscles are being flexed, and old compromises and conflicts are being scratched back into existence. While Russia is being increasingly cut-off from the global community, it is finding allies in its own backyard with established resentment towards the current world order where the United States and its allies are considered the global pack leaders. Especially, the United States, with its status of being a Mecca of capitalism, and the self-appointed global policeman, has historically often been at odds with Russia. With the United States and its affluent allies in Europe, Asia, the Americas, and Africa clearly enjoying an economic advantage and thanks to pacts like the North Atlantic Treaty Organization (NATO), a higher grade of collective military security, their domination is configured to remain unchallenged. However, in recent times, some so called ‘antagonistic’ nations have started leveraging the unlimited reach and anonymity of the internet to level the playing field.

 

Recent Seeds of Dissent – A New Axis of Power in Asia

In June 2021, after critical infrastructure installation in the United States bore the brunt of suspected Russian cyberattacks in the previous months, US President Joe Biden “informed” Russian President Vladimir Putin that certain critical infrastructure should be “off-limits” to cyberattacks. Immediately, security analysts decried the futility of Biden’s efforts – that the idea of creating safe zones and ethical practices for online conduct is an improbability. A month later, the US and its allies – including NATO, the European Union, Australia, Britain, Canada, Japan, and New Zealand – accused China of instigating a global hacking spree. China fought this accusation – terming the claim as “fabricated” and asserting that it opposes all forms of cyber-crime. Further, the Asian powerhouse claimed that the US had got its allies to make “unreasonable criticisms” against China. Russian officials have repeatedly denied carrying out or tolerating cyberattacks.

Aside from communism, Russia and China have a lot of things in common. An unsure bilateral relationship with the US is definitely a Top-5 item on this list. As if to forge an alignment amid their status as ‘suspect’ countries in the US and its allies’ collective radar, China and Russia announced in June 2021 the extension of the China-Russia Treaty of Good-Neighborliness and Friendly Cooperation. This could be interpreted as two regional powers building an Asian stronghold, importantly, there are also wider benefits: Russo-Chinese relations will be unsettling for the US and its Western partners, complicating strategic calculations, especially in terms of their strategies for the Asian continent.

 

Russia and China’s Recent Spying Spree

A reportedly Russian hacking campaign involving SolarWinds – a supply chain attack on the latter’s IT performance monitoring system called Orion – resulted in the compromise of at least nine US government agencies and thousands of organizations around the world. This was followed by a far-reaching campaign exploiting a vulnerability in Microsoft Exchange Server to break into victims’ email inboxes and later propagate laterally across the organization. This was allegedly led by the suspected Chinese hacker group Hafnium. The collective toll of these espionage campaigns is still being assessed and according to researchers, it may never be conclusively affirmed. A wealth of the world’s intellectual data was tapped into, siphoned off, and the perpetrators and their alleged benefactors may have walked away scot-free.

Aside from financial motives and a sneaky way to benefit the organizations in their own country to match up to the evolving international standards, these exhaustive intrusions can be viewed as a means to question the status quo. Especially, challenging the US and European countries’ standing as global superpowers, champions of capitalism, and influencers to many Asian countries that are drawn by the former’s appeal and are not ready to view the realignment of power in favor of local behemoths Russia and China.

 

Appeasement Fueling Confidence?

As of now, the Western powers are playing nice. NATO had underplayed the aforementioned situation by noting that its members “acknowledge” the allegations being leveled against China by the US, Canada, and the UK. Meanwhile, the European Union (EU) “urged” China to control “malicious cyber activities undertaken from its territory” – an ambiguous statement that implies that the Chinese government was itself innocent of directing the espionage. While the US has been much more specific – formally attributing intrusions such as the one that affected servers running Microsoft Exchange to hackers affiliated with China’s Ministry of State Security – the retaliation, according to official sources, could include economic sanctions and an executive order from the President to harden the federal government networks against future attacks. These sanctions, just as the many imposed before them, were not expected to be effective deterrents.

Could appeasement or leniency prove to be a roadblock here? While there is a line of thinking in the US administration that the usual sanctions are unlikely to force Russia or China onto the negotiation table, the fear is that calling these countries outright could elicit a strong cyber response. Many believe that the Russian and Chinese intrusions resulted in more than just espionage. Back doors have clearly been planted and the same can be leveraged at a future date for more destructive purposes, including modifying or wiping out critical data.

By all accounts, the next big war will be fought in cyberspace. US’s cyberattack on Iran’s missile system, the Russian company Internet Research Agency’s intrusion to spread misinformation through the US presidential elections, the ‘routine’ cyber compromise of mega-corporations leading to distinct societal impact, are all early hints that the powers-that-are have begun to consider the cyber route as a potent weapon. How long before the niceties are abandoned completely and a full-scale war – arising from accusations, sanctions, and isolation of problem entities, as is currently the case – will be underfoot?

 

Cybercriminals and ‘Rogue’ Governments – Hand in Glove?

In October 2021, in response to the growing menace of ransomware attacks and to collaborate more on cyber intelligence, heads of governments and think tanks came together in what could be described as the unprecedented first step towards a global collective against cybercrime. The endeavor was spearheaded by the United States and involved 30 nations (including Japan) while ominously excluding both Russia and China. In a possible response to this and similar developments, CYFIRMA researchers monitoring a dark web forum observed ransomware operators unite as one against the US and its allies’ interests and potentially target them. Details of the post are provided below:

Loosely translated to English: “In our difficult and troubled times, when the US government is trying to fight us, I urge all affiliate programs to stop competing. Unite and start to destroy the state sector of the United States, show this dementia old man who is the boss who is the boss and will be on the Internet. While our guys were dying on honeypots Sachkov from rude aibi squeezed his own … but he was rewarded with higher and now he will sit for treason, so let’s help our state fight such ghouls as cybersecurity firms that are sold to amers like state structures of the USA, I urge you not to attack Chinese companies, because where do we need to worry if our homeland suddenly turns its back on us, only to our good neighbours – the Chinese! I believe that all zones in the US will cope all blacks will go and f**k this f***ing Biden in all the cracks, I myself will personally make efforts.”

The above post very clearly indicates the following pointers:

  1. Potential collaboration between Chinese and Russian threat actors and/or Ransomware operators.
  2. Chinese threat actors using Ransomware-as-a-Service (RaaS) with various ransomware operators.
  3. Attacks on US interests could include the US & its allies like NATO, Japan, etc.

This isn’t an isolated incident. In the recent Ukraine-Russia conflict, the infamous Conti ransomware gang has fully backed Russia and promised retaliation if the West targeted Russian critical infrastructure. These examples highlight a deep nexus between organized cybercrime and governments willing to wield this strategic weapon, while simultaneously enjoying total immunity from possible repercussions via plausible deniability. While China, Russia, and North Korea are the most visible examples of this phenomenon, the trend is finding a lot of takers, especially in Asian countries. From Vietnam, South Korea, Pakistan, to India, everyone is eager to exploit cyberspace for their own agenda where real-world alignments and standings can be ignored in favor of who can compile the most potent and evasive malware code.

 

The New “Democratic World Order”

In modern-day geopolitical equations, every real-world conflict is likely to trigger the unleashing of more unresolved resentment. While Russia has tried to justify its stand on the Ukraine conflict on the world stage, it has found few supporters. Meanwhile, China has assumed a neutral position yet for observers, it is staunchly behind its closest Asian ally. Experts also note that the outcome of current Ukraine – Russia conflict, especially how the world governments respond and try to de-escalate this situation, could inspire China to handle its own ‘issues’ relating to Taiwan, Hong Kong, and disputed assets in the South China sea. On the sidelines of the Ukraine situation, Russia has already started talking about drafting a new “democratic world order” with China. With the availability of such a platform, other marginalized nations like North Korea and Iran – themselves alleged connoisseurs in the cybercrime game – are likely to join in and further divide the world into two distinct factions.

 

Sources:

 

Look Inside Ransomware Gang Through Conti Leaks

Conti gang is one of the largest cybercrime syndicates in the world. Third-party blockchain analysis of their bitcoin wallets estimates up to USD 200 million of annual revenue. Recently leaked chat logs of the group provide unprecedented insight into the life and operations of the gang. From asking leave approval to internal cybersecurity or TTPs used in attacks, these leaks are sure to be studied by analysts for weeks and months to come. Our research team at CYFIRMA has focused mainly on extracting IOCs and TTPs but has also observed interesting insights about the gang’s inner workings.

How are they organized?

After the arrest of REvil members, the Conti gang is now dominating the scene of so-called “big game hunting” groups (focused only on large companies with above USD 100m in annual revenue). Insights into their leaked conversations confirm what threat researchers, including at CYFIRMA – as part of our 2022 Predictions [https://www.cyfirma.com/cyfirma-cybersecurity-predictions-2022/] – have suspected and speculated. Top cybercriminal gangs are organized and operate as a business within their little industry of cybercrime. This includes outsourcing, for example, initial access brokers, typical HR problems, physical offices, and of course, performance reviews.

With the RaaS business booming, the need for reliable talent from low-level programmers to highly skilled pentesters has grown as well. In leaked chat logs, there are conversations of dedicated HR personnel and promotions of referral programs with bonuses. Particularly fascinating and shady is the practice of abusing legitimate headhunting services to hire employees who have no idea who they really are working for. The pressing matter appears to be talent retention as the pay is not too great, working hours are grueling and work is a repetitive cycle of monotonous tasks at Conti “company”.

Also discussed are operational issues of inconsistency and struggle to maintain its infrastructure. Domains, VPNs, and other services are not being properly tracked and renewed on time, causing issues for networks of compromised hosts calling said domains and so on. High turnover of employees also seems to cause human errors in the malware itself, where simple misconfigurations result in unsuccessful breaches and loss of profit.

 

How do they operate?

Before we jump into hacking and tools used, it is noteworthy to mention the use of business intelligence by Conti to learn about their victims. They are particularly interested in reported revenue and information about available cash or if an organization has ransomware/cybersecurity insurance. They also look for contacts of executives or board members in order to harass them and force out the ransom. Two paid tools that were specifically mentioned were ZoomInfo and Crunchbase.

Another interesting observation is shopping for all sorts of cybersecurity products. Naturally, they want to protect themselves against being hacked by the competition or law enforcement, so they buy Antivirus products and EDR solutions for their defense. At the same time, they are buying licenses of all major cybersecurity products to test their own malware and TTPs to keep it functional and stay at least one step ahead in this never-ending cat and mouse race.

The final point is their suspected collaboration with Russian government agencies. While there is still no concrete evidence even with these leaks, there are mentions of the FSB agency and Conti allegedly attacking an organization to gather information for FSB.

 

How do they attack – TTPs?

From extracted IOC and TTPs by CYFIRMA, there is a clear absence of any initial access materials implying heavy reliance on initial access brokers and affiliates to take care of this side of the business. From the snippet below it appears that Conti’s focus is on the speed of lateral movement and access to emails.

The snippet of GitHub repositories mentioned in leaked Conti chat logs

Download the links Conti Ransomware_Mar 2022_GitHub.

While there are a lot more TTPs and CVEs that the CYFIRMA research team extracted from the leaks on GitHub and beyond, this snippet illustrates some of Conti’s favorites. It is clear that they are not trying to re-invent the wheel, rather relying heavily on existing and readily available tools. Their coders focus on locker code and botnet networks.

Combining the previously leaked playbook of Conti, with these recent chat leaks, we can quite clearly see preferred protocols and systems to exploit and tools used for it. Once initial access is obtained, usually, from 3rd party brokers, Conti is well equipped to establish persistence and move laterally for maximum damage in the shortest amount of time possible.

Here are observations of the CYFIRMA research team.

  1. Native OS commands, tools, and PowerShell have become a universal way to execute the most or even entire attack flow. They are already present in victims’ networks increasing crucial speed and detection evasion. Nearly all tools leveraged are being used in their PowerShell versions, including Mimikatz and PowerSploit.
  2. Heavy reliance on Cobalt Strike and its malleable C2 configuration. A large portion of observed GitHub repositories were all dedicated to Cobalt Strike and its configurations, including better menu options for the framework.
  3. SMB and RDP are protocols of choice for lateral movement in Conti’s arsenal of tools for both scanning these protocols and directly exploiting their vulnerabilities. Conti has been particularly quick to adopt the latest vulnerability SMB and RDP exploits, such as PrintNightmare.
  4. In the initial stages of an attack, Conti seems to prefer the Kerberoasting attack if a large volume of more than 3k hosts is discovered. They refer to bots and shares dumping continuity/stability as it is hours long process during network discovery and enumeration.
  5. Mimikatz, UAC Bypass, and Zerologon are a privilege escalation holy trinity with some help of NTDS dumps. These tools and TTPs appear to be a reliable toolkit that works for most of their victims. There are a whole plethora of other mentions, but these and especially PowerShell Mimikatz are the gold standard for the gang.
  6. As no surprise comes the frequent presence of MS Exchange RCE exploits. If attackers could pick one data set to extort the victim for money, it would be the email.
  7. When it comes to data exfiltration, usage of the Mega.io platform with the “rclone.exe” tool has been the top choice of the gang for some time. We have also found the DNS Tunneling PowerShell tool “Invoke-DNSteal”.

 

Conclusion and look into the future

It has been very insightful to see the Conti gang’s preferred methods and tools and how they operate. Like anyone else, they like to stick to what works and incrementally make changes to ensure it keeps working without drastically changing any part of their playbook. From a threat research and defense perspective, this provides valuable information on what to focus on. Notable is the universal adoption of OS native tools and PowerShell, which is very likely going to evolve further into living off the land.

From the organizational perspective, their somewhat impressive and unexpected “ordinary business” structure still has major problems and clearly struggles with issues of efficiency and consistency. However, we can expect that these will get ironed out and consequently, the gang will continue to get better and more dangerous to organizations around the world.

Finally, many are speculating if this is the end of Conti. And it likely is not. They have had leaks before and from the size of their operation, it seems they are almost too big to fail. There is also a suspected connection to the Russian government which makes the discontinuation of Conti even less likely. If it comes to the worst, they are most likely to go with the time-proven strategy of taking a break and coming back stronger than ever with a re-brand.

 

 

Ways to Prevent Cyber Crime Even as IoT Technology Becomes Increasingly Prevalent in 2022

Ways to Prevent Cyber Crime Even as IoT Technology Becomes Increasingly Prevalent in 2022

As we move towards a “smarter” world, the adoption rate of IoT (Internet of Things) and IIoT (Industrial Internet of Things) has grown exponentially. A leading market research firm predicts that the IoT platform market, alone, is all set to grow by USD 12.52 billion by 2025. When it comes to the IIoT data collection and device management market, 39% of the growth is expected to originate from North America alone. Since Growth is very quick, it is very important to avoid Cyber Crime through IoT.

While, on the one hand, these facts and figures highlight the potential of these technologies – on the other hand, the sheer numbers reflect the huge treasure trove of data these devices hold. This also means that the footprint of potential access points for cybercriminals will grow exponentially.

We have found the most powerful way to avoid Cyber Crime:

Secure your Mobile Device with DeFNCE

To put things into perspective, towards the end of 2021 a botnet named BotenaGo targeted millions of routers and IoT devices with 33 exploits which is the most powerful way to avoid Cyber Crime. With a rather low antivirus detection rate, the malware manages to evade defense solutions successfully. What this attack resulted in for businesses was not only potential loss of critical data and finances but also operational disruption and possible dent to their hard-earned reputation.

According to our threat intelligence team, botnets are just one of the many ways in which cybercriminals launch attacks. Denial of Service (DoS), Man-in-the-Middle, Ransomware, Privilege Escalation, Brute Force, Firmware Hijacking, Data Encryption, Eavesdropping, and most of all Physical Attacks are other ways in which threat actors target IoT and IIoT devices.

As per our cybersecurity predictions, in 2022 we will continue to see an increase in business adopting of IoT/IIoT devices and increased number within our homes. We will also witness the attacks on IoT/IIoT and its continued convergence of OT devices, edge computing devices – where data is operated on as close as possible to the point it is collected, as well as a centralized cloud infrastructure that is vulnerable.

Here are some ways to protect your infrastructure:

Move beyond the traditional model of security awareness towards improved simulation and training exercises that mimic real attack scenarios, account for behaviors that lead to compromise, and are measured against real attacks the organization encounters.

Block exploit-like behavior. Monitor endpoints memory to find behavioral patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new. This will be able to provide effective protection against zero-day/critical exploits and more, by identifying such patterns.

Minimize network exposure for all control system devices and/or systems and unless there is a business requirement make sure they are not exposed to the Internet.

Locate control system networks and remote devices behind firewalls and isolate them from the business network.

IoT device owners should keep their software and applications up to date and use complex, unique passwords for accounts associated with their devices. Further, they should avoid connecting to vulnerable devices from untrusted networks, such as public Wi-Fi.

IoT device manufacturers should apply controls around Web APIs used to obtain Kalay UIDs, usernames, and passwords, as this would decrease attackers’ ability to access the data, they need to remote access target devices.

Get Agile Digital Risk Discovery and Protection with DeTCT

 

Cyber Threat Landscape Expands with State-Sponsored Cyber Attackers

Cyber Threat Landscape Expands with Collaboration Between State-Sponsored Groups

By CYFIRMA Research

 

As Ukraine faces hybrid warfare, it is clear that the era of state-sponsored cybercriminals is close to its zenith. For the uninitiated, a state-sponsored cyber attack is a form of defense strategy adopted by nations to target governments, critical infrastructure, as well as the civil society of hostile states.

One incident which is oft-quoted as the best example of a state-sponsored cyberattack is the Stuxnet attack on Iran which was discovered in 2010. This weaponized digital attack against industrial control systems (ICS) was reportedly launched by Israel’s Unit 8200, U.S. Central Intelligence Agency, and the National Security Agency (NSA).

Fast-forward 2022, CYFIRMA’s cyber threat intelligence team has observed state-sponsored groups evolving, innovating, and enhancing their capabilities in the use of malware, ransomware, and TTPs (tactics, techniques, and procedures). It is suspected that these groups have managed to enhance their internet hacking strategy by collaborating with other cyber threat actors, sharing, and benefitting from their experiences and skills.

25% of the campaigns tracked by our team were seen to be launched by the Russian ransomware groups who hired state-sponsored groups affiliated to China (and vice-versa) through the RaaS model (Ransomware-as-a-Service). At the same time, close to 20% of the campaigns highlighted that North Korean hacking groups were hired by Chinese groups under the HaaS (Hacking-as-a-Service) model, making Cybersecurity even more challenging.

So, two aspects have gained prominence in the digital threat landscape with this constant collaboration between state-sponsored groups. The first aspect, undoubtedly, is how cyber warfare is no longer something you see only in a sci-fi movie. It is rather the new uncomfortable reality. Governments across the globe understand how instead of ragging wars across boundaries, crippling the very economy, infrastructure, and manpower of the enemy nation is far more lethal, far more cost-effective, and most of all the best non-violent way to tackle the enemy nation. Though the shift to cyber kinetic does throw light on the violent face of cybercrime, most state-sponsored groups are non-violent in their online crimes.

 

Defense and Deterrence: The Two Building Blocks of a Potent Strategy Against State-Sponsored Groups

 

As per our Cyber Threat Intelligence Team, the collaboration amongst state-sponsored internet threat actors is expected to increase in 2022. Realizing the political agenda of their state masters is the primary goal of these cybercriminals. At the same time, one can not ignore how these groups have built a rather profitable business model by availing of RaaS and HaaS. For instance, our monitoring of the dark web forums highlights that several Chinese cyber threat actors including state-sponsored outfits are hiring North Korean groups as part of HaaS for exfiltrating sensitive details from organizations in return for financial benefits.

Therefore, it is safe to conclude that state-sponsored digital threat actors will find more ways of collaborating across boundaries to further the geo-political-economic agenda of their state masters, and at times also justify their domestic authoritarian policies for wider adoption.

The best way to tackle this condition is to build a viable defense and deterrence strategy. This would mean thoughtful investments in cyber intelligence infrastructure and the global collaboration of nation-states against such cyber attacks. At an organizational level, here are some critical recommendations to protect the critical infrastructure against such internet crimes:

  1. Implement a holistic cyber security strategy that includes controls for cyber attack surface reduction, effective patch management, active network monitoring through next-generation cybersecurity solutions, and ready to go incident response plan.
  2. Establish a robust plan to identify assets by leveraging a Risk-based approach along with the Defence-in-Depth (DiD) method as part of the organization’s cyber security strategy to minimize the cyber risk exposure of vulnerabilities to an acceptable level for an organization.
  3. Implement network traffic or cybersecurity monitoring, cybersecurity incident detection, notification, and alerting by leveraging SIEM (Security Information and Event Monitoring) solutions.

 

DeCYFIR is a Powerful Cyber-Intelligence Platform with Six Threat Views on a Single Pane of Glass for Complete Understanding of External Threat Landscape

Six pillars of cyber threat views include attack surface discovery, vulnerability intelligence, brand intelligence, digital risk discovery and protection, situational awareness and cyber-Intelligence.

DeTCT automatically discovers your digital footprint, proactively monitors the web and social media platforms 24/7, and secures your digital ecosystem.

DeFNCE is your trusted Cyber Defence tool for individuals and businesses. With DeFNCE you can Protect your device & digital footprint, Discover leaked personal data and Stay secure.

 

AvosLocker is Turning the Double-Extortion Ransomware Scheme Lethal

Subscribe for Latest Updates

AvosLocker is Turning the Double-Extortion Ransomware Scheme Lethal

By CYFIRMA Research

The world of ransomware double-extortion schemes is changing. The extortion model, which started back in 2019 by the operators of the Maze ransomware group, is now being improvised into an even more profitable money-making model. AvosLocker, a RaaS (ransomware-as-a-service) group, has revamped its website by creating a system through which they plan to auction data of the victims who refuse to pay the ransom.

Typically, in a double-extortion ransomware model, if a victim does not pay the ransom, threat actors release sensitive files for free on the dark web through “leak sites”. But by adding the auction feature, AvosLocker is changing the landscape of this type of ransomware attack.

 

AvosLocker: A Ransomware Group Which Can Cause Havoc

Recently, a report quoted AvosLocker among three other emergent ransomware groups which have the potential to create havoc in the cyber world with their targeted attacks.

The modus operandi this ransomware group starts with data encryption and moves on to adding its own extension “GET_YOUR_FILES_BACK.txt” to each of the folders having these encrypted files. Based on the discussions on dark web forums, CTI observes that the group is looking for affiliates, at the same time just like its competitors AvosLocker does provide technical support to its victims which providing the decryption tool.

While a small section of the threat intelligence fraternity believes that given that AvosLocker carries less than 10 attacks in a week and thus the auction feature should be taken lightly; we can not deny the fact that the group has launched some major attacks in Belgium, Spain, Lebanon, UAE, UK, and the USA.

Recommendations

Prioritize resources (based on classification, criticality, and business value) and understand the true scope and impact of a potential ransomware event. It is an important factor in contingency planning for future ransomware events, emergency responses, and recovery actions allowing an organization to prioritize the response and recovery activities.

Implement competent security protocols and encryption, authentication, or access credentials configurations to access critical systems in the organization’s cloud and local environments.

Consider using security automation to speed up threat detection, improved incident response, increased visibility of security metrics, and rapid execution of security checklists.

Employ User and Entity Behavior Analytics (UEBA) in tracking, collecting, and analyzing user and machine data to detect threats within an organization.

Implement least privilege access in the system to locations that could potentially have critical information and be targeted by ransomware.

For a further discussion, reach out to [email protected].

Subscribe for Latest Updates

 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.