{"id":33008,"date":"2019-08-19T08:46:45","date_gmt":"2019-08-19T07:46:45","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/08\/19\/cyber-adversaries-up-the-ante-on-evasion-and-anti-analysis-to-avoid-detection\/"},"modified":"2019-08-20T09:32:26","modified_gmt":"2019-08-20T08:32:26","slug":"cyber-adversaries-up-the-ante-on-evasion-and-anti-analysis-to-avoid-detection","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/08\/19\/cyber-adversaries-up-the-ante-on-evasion-and-anti-analysis-to-avoid-detection\/","title":{"rendered":"Cyber adversaries up the ante on evasion and anti-analysis to avoid detection"},"content":{"rendered":"\n<p>Fortinet,\na global leader in broad, integrated and automated cybersecurity solutions, has\nannounced the findings of its latest quarterly&nbsp;<em><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/fortinet-q2-2019-threat-landscape-report.html\">Global Threat Landscape Report<\/a><\/em>.<\/p>\n\n\n\n<p>The\nresearch reveals that cybercriminals continue to look for new attack\nopportunities throughout the digital attack surface and are leveraging evasion\nas well as anti-analysis techniques as they become more sophisticated in their\nattempts.<\/p>\n\n\n\n<p>The\nThreat Landscape Index crossed a milestone this quarter. It is up nearly 4%\nfrom its original opening position year-over-year. The high point during that\nyear-long timeframe is the peak and closing point of Q2 CY2019. The upsurge was\ndriven by increased malware and exploit activity. <\/p>\n\n\n\n<p>\u201cThe\never-widening breadth and sophistication of cyberadversaries\u2019 attack methods is\nan important reminder of how they are attempting to leverage speed and\nconnectivity to their advantage,\u201d said Phil Quade, Chief Information Security\nOfficer, Fortinet. <\/p>\n\n\n\n<p>\u201cTherefore,\nit is important for defenders to do the same and to relentlessly prioritise\nthese important cybersecurity fundamentals, to position organisations to better\nmanage and mitigate cyber-risks. <\/p>\n\n\n\n<p>\u201cA\nsecurity fabric approach across every security element that embraces segmentation\nand integration, actionable threat intelligence and automation combined with Machine\nLearning is essential to enable these fundamentals to bear fruit.\u201d<\/p>\n\n\n\n<p>Highlights\nof the report follow.<\/p>\n\n\n\n<p><strong>Upping\nthe ante on evasion tactics<\/strong><\/p>\n\n\n\n<p>Many\nmodern malware tools already incorporate features for evading anti-virus or\nother threat detection measures, but cyberadversaries are becoming more\nsophisticated in their obfuscation and anti-analysis practices to avoid\ndetection. <\/p>\n\n\n\n<p>For\nexample, a spam <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/excel-variable-targeting-japanese-users.html\">campaign<\/a>\ndemonstrates how adversaries are using and tweaking these techniques against\ndefenders. The campaign involves the use of a phishing email with an attachment\nthat turned out to be a weaponised Excel document with a malicious macro. <\/p>\n\n\n\n<p>The\nmacro has attributes designed to disable security tools, execute commands\narbitrarily, cause memory problems and ensure that it only runs on Japanese\nsystems. One property that it looks for in particular, an xlDate variable, seems\nto be undocumented.<\/p>\n\n\n\n<p>Another\nexample involves a variant of the Dridexbanking trojan which changes the names\nand hashes of files each time the victim logs in, making it difficult to spot\nthe malware on infected host systems.<\/p>\n\n\n\n<p>The growing use of anti-analysis and broader evasion tactics is a reminder of the need for multi-layered defences and behaviour-based threat detection.<\/p>\n\n\n\n<p><strong>Under\nthe radar attacks aim for the long-haul<\/strong><\/p>\n\n\n\n<p>The Zegostinfostealer\nmalware is the cornerstone of a <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/zegost-campaign-targets-internal-interests.html\">spear\nphishing campaign<\/a> and contains intriguing techniques. Like other\ninfostealers, the main objective of Zegost is to gather information about the victim\u2019s\ndevice and exfiltrate it. Yet, when compared to other infostealers, Zegost is\nuniquely configured to stay under the radar. For example, Zegost includes functionality\ndesigned to clear event logs. <\/p>\n\n\n\n<p>This\ntype of cleanup is not seen in typical malware. Another interesting development\nin Zegost\u2019s evasion capabilities is a command that kept the infostealer \u2018in\nstasis\u2019 until after February 14, 2019, after which it began its infection\nroutine. <\/p>\n\n\n\n<p>The\nthreat actors behind Zegost utilise an arsenal of exploits to ensure they\nestablish and maintain a connection to targeted victims, making it far more of\na long term threat compared to its contemporaries.<\/p>\n\n\n\n<p><strong>Ransomware\ncontinues to trend to more targeted attacks<\/strong><\/p>\n\n\n\n<p>The\nattacks on multiple cities, local governments and education systems serve as a\nreminder that ransomware is not going away, but instead continues to pose a\nserious threat for many organisations going forward. <\/p>\n\n\n\n<p>Ransomware\nattacks continue to move away from mass-volume, opportunistic attacks to more\ntargeted attacks on organisations, which are perceived as having either the\nability or the incentive to pay ransoms. In some instances, cybercriminals have\nconducted considerable reconnaissance before deploying their ransomware on\ncarefully selected systems to maximise opportunity. <\/p>\n\n\n\n<p>For\nexample, RobbinHoodransomware is designed to attack an organisation&#8217;s network\ninfrastructure and is capable of disabling Windows services that prevent data\nencryption and to disconnect from shared drives.<\/p>\n\n\n\n<p>Another\nnewer ransomware, called Sodinokibi, could become another threat for organisations.\nFunctionally, it is not very different from a majority of ransomware tools in the\nwild. It is troublesome because of the attack vector, which exploits a newer\nvulnerability that allows for arbitrary code execution and does not need any\nuser interaction like other ransomware being delivered by phishing email.<\/p>\n\n\n\n<p>Regardless\nof the vector, ransomware continues to pose a serious threat for organisations\ngoing forward, serving as a reminder of the importance of prioritising patching\nand infosecurity awareness education. <\/p>\n\n\n\n<p>In\naddition, Remote Desktop Protocol (RDP) vulnerabilities, such as <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/cve-20190708-remote-desktop-protocol-and-code-execution-bluekeep.html\">BlueKeep<\/a>\nare a warning that remote access services can be opportunities for\ncybercriminals and that they can also be used as an attack vector to spread\nransomware.<\/p>\n\n\n\n<p><strong>New\nopportunities in the digital attack surface<\/strong><\/p>\n\n\n\n<p>Between\nthe home printer and critical infrastructure is a growing line of control\nsystems for residential and small business use. These smart systems garner\ncomparably less attention from attackers than their industrial counterparts,\nbut that may be changing based on increased activity observed targeting these\ncontrol devices such as environmental controls, security cameras and safety\nsystems. <\/p>\n\n\n\n<p>A\nsignature related to building management solutions was found to be triggered in\n1% of organisations, which may not seem like much, but it is higher than\ntypically seen for ICS or SCADA products.&nbsp;&nbsp;\n<\/p>\n\n\n\n<p>Cybercriminals\nare searching for new opportunities to commandeer control devices in homes and\nbusinesses. Sometimes these types of devices are not as prioritised as others\nor are outside the scope of traditional IT management. The security of smart\nresidential and small business systems deserves elevated attention especially\nsince access could have serious safety ramifications. This is especially\nrelevant for remote work environments where secure access is important.<\/p>\n\n\n\n<p><strong>How\nto protect your organisation \u2013 broad, integrated and automated security<\/strong><\/p>\n\n\n\n<p>Threat\nintelligence that is dynamic, proactive and available in real-time can help\nidentify trends showing the evolution of attack methods targeting the digital\nattack surface and to pinpoint cyberhygiene priorities. <\/p>\n\n\n\n<p>The value and ability to take action on threat intelligence is severely diminished if it cannot be actionable in real-time across each security device. A <a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/enterprise-security.html?utm_source=blog&amp;utm_campaign=2018-security-fabric\">security fabric<\/a> that is broad, integrated and automated can provide protection for the entire networked environment, from IoT to the Edge, network core and to multi-clouds at speed and scale. <\/p>\n\n\n\n<p><strong>Report and index overview<\/strong><\/p>\n\n\n\n<p> The latest Fortinet Threat Landscape Report is a quarterly view that represents the collective intelligence of <a href=\"https:\/\/www.fortinet.com\/fortiguard\/threat-intelligence\/threat-research.html?utm_source=nreleaseblog&amp;utm_campaign=2018-q2-fortiguardlabs-cta\">FortiGuard Labs<\/a>, drawn from Fortinet\u2019s vast array of global sensors during Q2 2019. Research data covers global and regional perspectives. <\/p>\n\n\n\n<p>Also included in the report is the Fortinet Threat Landscape Index (TLI), comprised of individual indices for three central and complementary aspects of that landscape which are exploits, malware and botnets, showing prevalence and volume in a given quarter.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet, a global leader in broad, integrated and automated cybersecurity solutions, has announced the findings of its latest quarterly&nbsp;Global Threat Landscape Report. The research reveals that cybercriminals continue to look for new attack opportunities throughout the digital attack surface and are leveraging evasion as well as anti-analysis techniques as they become more sophisticated in their [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":33092,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[13182,2411,3881,1844,4704,13183],"class_list":["post-33008","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-cyber-adversaries","tag-global-threat-landscape-report","tag-machine-learning","tag-malware","tag-phishing","tag-threat-landscape-index"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=33008"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33008\/revisions"}],"predecessor-version":[{"id":33079,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/33008\/revisions\/33079"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/33092"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=33008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=33008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=33008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}