Home Blog Page 191

Russia-based APT29 Targets COVID-19 Vaccine Research

Russia-based APT29 Targets COVID-19 Vaccine Research

The U.K.’s National Cyber Security Centre (NCSC), Canada’s Communications Security Establishment (CSE), and the National Security Agency (NSA) of the U.S. stated that a cyber espionage group “APT29,” which is linked to Russian intelligence services, is trying to steal information and intellectual property related to the testing and development of Coronavirus vaccines.

In a joint advisory, the agencies stated that the APT29 group, also known as “the Dukes” or “Cozy Bear,” targeted several organizations that are working on COVID-19 vaccine development in Canada, the U.S., and the U.K.  The group is using its custom malware known as WellMess and WellMail and other techniques to target government entities, diplomats, think-tanks, health care providers, and companies under the energy sector.

“The group frequently uses publicly available exploits to conduct widespread scanning and exploitation against vulnerable systems, likely in an effort to obtain authentication credentials to allow further access. This broad targeting potentially gives the group access to a large number of systems globally, many of which are unlikely to be of immediate intelligence value. The group may maintain a store of stolen credentials in order to access these systems in the event that they become more relevant to their requirements in the future,” the advisory said.

The advisory also highlighted that the APT29 group continues to attack COVID-19 vaccine research and development centers for their financial or intellectual gains. The agencies strongly recommended organizations to use robust security measures to defend against cyberthreats.

NCSC and CISA Advisory on COVID-19 Threats

Recently, cybersecurity officials from the NCSC, the U.S. Department of Homeland Security (DHS), and the Cybersecurity and Infrastructure Agency (CISA) stated that cybercriminals and advanced persistent threat (APT) groups are targeting individuals and organizations with a variety of ransomware and malware attacks, thereby exploiting the COVID-19 outbreak for their personal gain. The security agencies have released a joint advisory describing the growing number of attackers and other malicious groups in the U.K. and the U.S. The NCSC and CISA stated that they are working with law enforcement and industry experts to prevent COVID-19 related cyber activities. It is said that the NCSC and the CISA have observed hackers scanning for vulnerabilities in remote working tools and exploited the increased use of video conferencing software.

 

EU-U.S. Privacy Shield Regarded Invalid by ECJ

EU-US Privacy Shield

In a landmark judgment, the European Court of Justice (ECJ) annulled the “EU-U.S. Privacy Shield,” which was introduced in July 2016. The ECJ found that the transatlantic data transfer framework did not abide by the data security rights of EU citizens as defined under the General Data Protection Regulation (GDPR) compliance. It stated that the U.S. Surveillance Law does not have strong data privacy measures to protect its citizens’ data and instead asked them to make use of the already implemented legal mechanism, the standard contractual clauses (SCCs), for the time being.

What is EU-U.S. Privacy Shield?

With a view of creating a safe passage for personal data transfer between European and U.S. companies, the U.S. Department of Commerce and the European Commission established the EU-U.S. Privacy Shield framework. As per their website, to join the privacy shield, a U.S.-based organization is required to self-certify to the Department of Commerce on its website and publicly commit to comply with the privacy shield’s requirements. Once committed the member will then be enforceable under U.S. law.

The ECJ’s Ruling

Prior to the EU-U.S. Privacy Shield, U.S.-based companies were using SCCs to authorize the transfer of data across the continents following the ECJ’s 2015 decision to strike down Safe Harbor, another EU-U.S. data transfer mechanism. However, with the GDPR coming into effect in 2018, the data privacy and protection standards have seen a stringent upscale. According to the ECJ’s ruling, the U.S. surveillance laws did not match this standard and also “the provisions do not grant data subjects actionable rights before the courts against the US authorities,” which again is a violation of the basic rights of its citizens.

On the other hand, the ECJ, even after approving the SCC, has added a few conditions in its exercise. It said that data protection authorities (DPAs) should suspend or prohibit a transfer of personal data to a third country if they believe that country cannot comply with the standard data protection clauses and GDPR.

The U.S. Department of Commerce was rather unhappy with this decision but withheld ECJ’s ruling and is looking forward to improving the personal data privacy quotient of the Privacy Shield. What would be interesting to see in the coming days is how it impacts the existing members of the shield, of which 70% are small and medium-sized enterprises (SMEs) that might not have enough resources in the current COVID-19 situation to revert back to SCCs.

Data Viper Servers Hacked; Over 8,000 Databases Leaked

106 million Thailand visitors

A hacker going by the name “NightLion” claimed to have stolen 8,200 backend servers of threat intelligence and data leak monitoring service Data Viper, according to a report from KrebsonSecurity. The hacker also alleged that they are selling around 2 billion records from Data Viper’s databases on the darknet forums.

The hacker emailed several cybersecurity reporters a link to a darknet portal where they published details about the servers’ hack.  He also provided the proof of the access to a list of 482 downloadable JSON files that are stolen from the breached servers. The hacker claims to have spent up to three months inside Data Viper servers and also posted advertisements on the Empire Dark Web marketplace selling 50 databases that Data Viper allegedly acquired via trading with others on cybercrime forums.

Vinny Troia, the creator of Data Viper and the security researcher at cybersecurity firm Night Lion Security admitted that the hacker group gained access to one of the DataViper servers. Troia stated that the hacker is actually selling their own databases, rather than any stolen data from their servers. He  stated that the hacker might be linked to other infamous hacking groups like TheDarkOverlord, Shiny Hunters, and GnosticPlayers.

Darknet Flood with Leaked Databases

In a similar research, security firm Cyble revealed that a hacking group Shiny Hunters is selling Wishbone.io database on darknet forums. The leaked database contained over 40 million records of Wishbone users–a social platform that allows users to compare social content via voting poll. It is found that the Shiny Hunters group was responsible for numerous data breaches including the breach of 73.2 million user records from over 11 companies. The hackers are also behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

 

BlackRock! A New Banking Trojan Debuts

Trojans, RAT, remote access trojan, Snip3 Crypter-as-a-Service

Security researchers from ThreatFabric discovered a new banking Trojan “BlackRock,” which is targeting Android banking apps and also stealing  login credentials from social networking sites, dating and cryptocurrency, and non-banking apps.

It is found that the malware targeted over 337 non-financial Android applications till now. The BlackRock malware is derived from the leaked code of the “Xerxes” banking malware, which is also a strain of the “LokiBot” Android banking Trojan that was active from 2016 to 2017.

Image Source: ThreatFabric

Most of the targeted banking apps are related to banks and financial institutions operating in Europe, Australia, the U.S., and Canada. In addition to financial apps, threat actors also targeted shopping, communication, and business apps related to German online car selling services, Polish online shopping sites, and email service providers.

How BlackRock Attacks

Once the malware installs on the device, it hides its icon from the app drawer and accesses the victim’s accessibility service privileges. The BlackRock then grants itself additional permissions to function without the victim’s knowledge. The malware receives commands from the C2 or C&C server and launches overlay attacks to steal login credentials.

Image Source: ThreatFabric

BlackRock Features

The researchers stated that BlackRock poses a variety of features, allowing it to remain in stealth mode and steal personal information from the victim’s device. The Trojan can perform:

  • Overlaying: Dynamic (Local injects obtained from C2)
  • Keylogging
  • SMS harvesting: SMS listing
  • SMS harvesting: SMS forwarding
  • Device info collection
  • SMS: Sending
  • Remote actions: Screen-locking
  • Self-protection: Hiding the App icon
  • Self-protection: Preventing removal
  • Notifications collection
  • Grant permissions
  • AV detection

“BlackRock offers a quite common set of capabilities compared to average Android banking Trojans. It can perform the infamous overlay attacks, send, spam and steal SMS messages, lock the victim in the launcher activity (HOME screen of the device), steal and hide notifications, deflect usage of antivirus software on the device and act as a keylogger. Interestingly, the Xerxes Trojan itself offers more features, but it seems that actors have removed some of them in order to only keep those that they consider useful to steal personal information,” the researchers said.

 

Navigating Cybersecurity in the New Normal

Zero Trust, cybersecurity

The worldwide COVID-19 pandemic has forced governments, organizations, and individuals to step up their capacities and make significant changes in how they work and live. And with that, the threat landscape has also evolved completely as cybercriminals continue to come up with newer techniques to exploit the global crisis in their social engineering strategies and attack people. Remote working, as well as distance learning have become a norm resulting in people spending more time online, which also opens doors to security risks.

By Dr. Moataz Binali, Vice President for Middle East & North Africa, Trend Micro

Cybercrime Outlook

During Q1 2020, Trend Micro discovered and blocked over 9,773 COVID-19 related cyber-attacks, in the Gulf region alone. These include 8,984 email spam attacks, the 4th-highest in Asia; 772 URL attacks, the 6th-highest in Asia; and 17 malware threats detected. Moreover, globally, our researchers observed a 220x spike in spam, and a 260% increase in malicious URL hits. .

It is also worth stating that Security Predictions for 2020 released last year, flagged that home offices and other remote-working setups will redefine supply chain attacks. Hence, decision makers will have to be wary of risks introduced by work-from-home arrangements and internet connected home devices that blur the lines in enterprise security. These increasingly sophisticated attacks will extend business email and process compromise well past simple redirection of funds or malware infection. Thus, the employee’s home environment can become a launch point for supply chain attacks.  

As such, it is important that all those in a cybersecurity role must consider how they are going to protect a significantly more vulnerable ecosystem and overhaul their postures.

Where do we go from here?

So, remote workers are vulnerable for two reasons – their unprotected machines and the fact that the region is a high-value target for attackers. To properly protect a remote-working setup, security professionals must look at a multi-layered approach that covers emails, networks, endpoints, servers, and cloud workloads. Collect enough information on those elements and feed it to AI-powered platforms, and one gets a highly accurate real-time view of the entire IT ecosystem. This allows better decisions and responses, less downtime, and safer environments.

Trend Micro has long taken an extended detection and response approach, known as XDR. By expanding the detection-and-response function to cover emails, networks, endpoints, servers, and cloud workloads, we can put advanced artificial intelligence to work in trawling that entire ecosystem looking for data points that correlate to those within Trend Micro’s global threat-intelligence data-pool. Such an approach delivers higher-fidelity alerts with fewer false positives, leading to better, earlier detection.

With Trend Micro’s XDR platform, security professionals are also presented with a single dashboard that allows easy, one-click drilldown into the most relevant events, with graphically clear representations of attack timelines and all related events. And with such visibility, they can get to the crux of an issue quickly, with minimal manual effort, determining its root cause and its impact on their organization. Capabilities such as these lead to wiser, more timely actions in real time and adjustments to strategy for the long-term benefit of the entire enterprise.

Unparalleled Security for Unprecedented Times

These times are challenging – during which governments and organizations in the region are doing their best to tackle challenges across every facet of work and life. Indeed, cybersecurity is a growing concern as more sophisticated attacks surface each day. If managed properly, we can still thrive enough so that we do not compound one crisis with another. And a sound cybersecurity strategy plays a vital role in that story.

To that end, our innovations have been built from the ground up to empower organizations to protect their journey from the endpoint – to the cloud. For example, our XGen security, which powers all of Trend Micro’s solutions – is a unique blend of cross-generational threat defense techniques that is continually evolving and optimized for each layer of security – user environments, networks and hybrid clouds – to best protect against the full range of known and unknown threats.

About the Author

Dr. Moataz Bin AliAs Vice President for Trend Micro Middle East and North Africa (MENA), Dr. Moataz Binali is responsible for spearheading the company’s strategy across the region, and advancing its position as a leader in cybersecurity that is passionate to make the world safe for exchanging digital information. A significant part of Dr. Binali’s role is to oversee Trend Micro’s efforts in enhancing the cybersecurity posture amongst governments and enterprises, contributing to the digital economy of MENA. Prior to joining Trend Micro, he held pivotal roles on regional level in global technology organizations such as SAP, IBM, and Microsoft.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

U.S. Tops in the ‘Significant Cyberattacks’ List; U.K. and India Follow Suit

Over 126 Mn People are Victims of Cybercrime Across U.S. and U.K.

A report from Specops Software stated that the U.S., the U.K., India, and Germany have suffered significant cyberattacks over the past 14 years. Specops defined “significant cyberattacks” as attacks targeted at a country’s government agencies, defense units, high-tech organizations — or economic crimes with losses more than a million dollars.

The report, which analyzed data from the Center for Strategic and International Studies (CSIS), found that the U.S. has experienced the most significant cyberattacks, totaling 156 attacks reported between May 2006 and June 2020. The U.K. ranked second-highest,  with 47 significant attacks reported during the same period. India ranked third, with 23 large scale attacks followed by Germany with 21 attacks. Next on the list was South Korea (18 attacks), Australia and Ukraine (both 16 attacks).  Whereas, the countries least exposed to cyberattacks were Vietnam, Turkey, and North Korea.

Image Source: Specops Software

According to the research, the majority of the attack techniques used by cybercriminals to launch significant cyberattacks were: Distributed Denial of Service Attack (DDoS), SQL Injection attack, man-in-the-middle (MitM) attacks, and phishing attacks.

Most Vulnerable Countries

A similar survey, “Cybersecurity Exposure Index (CEI) 2020,” by password security resource PasswordManagers.co  analyzed and ranked 108 countries based on their exposure to Trojans, malware, and phishing attacks. It also revealed the level of cybersecurity commitment across Europe, America, Asia-Pacific, and Africa.

According to the survey report, Finland is the least exposed country to cybercrimes, followed by Denmark, Luxembourg, Australia, and Estonia. Afghanistan topped the list as the most exposed country to cyberattacks, followed by Myanmar, Ethiopia, Palestine, and Venezuela. The survey measured the cybersecurity exposure score of each country from 0-1 (low-high exposure). It is found that Europe has the lowest exposure score (0.329), followed by North America (0.462). Nearly, 70.73% of European countries are classified in the low and very low exposure groups.

 

Media Industry Becomes a Common Ground for Credential Stuffing Attacks

Media Industry

A survey from Akamai Technologies found that credential stuffing attacks on the media industry have increased in the last two years. According to the survey reportAkamai 2020 State of the Internet / Credential Stuffing in the Media Industry,” 20% of the 88 billion total credential stuffing attacks were reported on media and video streaming companies, with 17 billion attacks reported between January 2018 and December 2019. The report also found a 63% year-over-year increase in attacks against the media sector, followed by broadcast TV (630%) and video sites (208%).

A Common Ground for Cybercriminals

A staggering 7,000% increase was reported in credential stuffing attacks on published content such as newspapers, books, and magazines. India was the most targeted country in 2019, with 2.4 billion credential stuffing attacks followed by the U.S. with 1.4 billion attacks, and the U.K. with 124 million. The U.S. was the primary source of credential stuffing attacks against media companies with 1.1 billion in 2019, an increase of 162% over 2018. France and Russia stood second and third with 393 million and 243 million attacks, respectively.

There was a major rise in malicious login attempts against European video service providers and broadcasters in Q1 2020. The number of cybercriminals sharing free access to newspaper accounts also increased during the same period.

Steve Ragan, security researcher at Akamai, said, “We’ve observed a trend in which hackers are combining credentials from a media account with access to stolen rewards points from local restaurants, and marketing the nefarious offering as date night packages. Once the criminals get a hold of the geographic location information in the compromised accounts, they can match them up to be sold as dinner and a movie.”

“As long as we have usernames and passwords, we’re going to have criminals trying to compromise them and exploit valuable information. Password sharing and recycling are easily the two largest contributing factors in credential stuffing attacks. While educating consumers on good credential hygiene is critical to combating these attacks, it’s up to businesses to deploy stronger authentication methods and identify the right mix of technology, policies, and expertise that can help protect customers without adversely impacting the user experience,” Ragan added.

 

Bitcoin Scammers Hack Twitter Accounts of Jeff Bezos, Bill Gates, Apple, and Many More

PM Modi Twitter

In a lethal strike to Twitter, Bitcoin scammers successfully hacked official accounts of many known personalities and brands to scam people into believing their money was soon going to be doubled. As many as 300+ transactions were recorded in the public ledger of bitcoin with the address mentioned in the Tweets. This consisted of a total transfer of 12 BTC that accounted for more than $100,000 (1 BTC valued at $9,200, as of July 15, 2020).

Such online scams are commonly observed on a daily basis, however, the extent of the number of accounts hacked and simultaneously used for scamming people has not been seen earlier. The list of individuals and brands whose official Twitter accounts were hacked include:

  • Jeff Bezos (Amazon CEO)
  • Bill Gates (Microsoft Co-Founder)
  • Elon Musk (Tesla and SpaceX CEO)
  • Warren Buffet (Berkshire Hathaway CEO)
  • Barack Obama (The Former U.S. President)
  • Michael Bloomberg (The Former New York Mayor)
  • Joe Biden (presumptive Democratic nominee for President)
  • Benjamin Netanyahu (Israeli Prime Minister)
  • Kanye West (Rapper) and wife Kim Kardashian (T.V. Celebrity)
  • Wiz Khalifa (Rapper)
  • Apple (Corporate Account)
  • Uber (Corporate Account) and many more.

Twitter Tweets…

Twitter was quick to follow-up on the incident and tweeted that they were “aware of a security incident impacting accounts on Twitter” and were taking steps to fix it.

As a temporary measure, Twitter had locked and suspended all operations of the affected accounts to investigate the cause and extent of the breach. It wanted to make sure whether any additional user information was compromised and if any backdoors were created for future account takeovers. It has also reported that significant steps were taken to keep internal systems and tools running with restricted access as the investigation is still on-going.

“In separate but probably related attacks, several notable Twitter accounts in the cryptocurrency space were also hacked in a mass coordinated attack.”

– Satnam Narang, Staff Research Engineer at Tenable

Satnam Narang, a Staff Research Engineer at Tenable, said that this was probably much bigger than its seen. He revealed that “In separate but probably related attacks, several notable Twitter accounts in the cryptocurrency space were also hacked in a mass coordinated attack. These included crypto exchanges like Coinbase, Binance, Gemini, KuCoin, Bitfinex, CEOs and founders like CZ_Binance, JustinSunTron, SatoshiLite, cryptocurrency accounts like TronFoundation, to promote a similar COVID-19 cryptocurrency giveaway scam.”

He further advised, “Users should never participate in so-called giveaways or opportunities that claim to double your cryptocurrency because they’re almost always guaranteed to be a scam.”

To stay updated on the ongoing investigation follow the Twitter Support account.

Cybercriminals Exploit Home Routers for Botnets: Research

Home Routers for botnets

Cybersecurity solutions provider Trend Micro warned users about a new wave of attacks targeting home routers. In its research report “Worm War: The Botnet Battle for IoT Territory,” Trend Micro revealed that cybercriminals are using home routers to build botnets. The research found a surge in cyberattacks by exploiting routers, particularly in Q4 2019. Attackers made brute force log-in attempts against routers by using automated software to try common password combinations. The number of attacks increased from around 23 million in September to nearly 249 million attacks in December 2019. In March 2020, around 194 million brute force login attacks were reported.

The research stated that attackers used three types of botnet malware variants namely “Kaiten,” “Qbot,” and “Mirai”. Using these three bot source codebases, the attackers created other botnet malware variants to compromise routers and other IoT devices. The compromised routers’ details are sold on hacking forums or used to launch cyberattacks like Distributed Denial of Service (DDoS) attacks, click fraud, data theft, or account takeover.

Image Source: Trend Micro

“Kaiten, Qbot, and Mirai demonstrate the capabilities that allow botnet malware to compete for dominance over connected devices. To grow a botnet and maintain its size, botnet malware families and variants need to be able to infect as many devices as possible while defeating other usurpers. Botnet malware can search for vulnerable devices and use well-known tactics such as brute force to take control of a device,” the report said.

“With a large majority of the population currently reliant on home networks for their work and studies, what’s happening to your router has never been more important. Cybercriminals know that a vast majority of home routers are insecure with default credentials and have ramped up attacks on a massive scale. For the home user, that is hijacking their bandwidth and slowing down their network. For the businesses being targeted by secondary attacks, these botnets can totally take down a website, as we have seen in past high-profile attacks,” said Jon Clay, director of global threat communications for Trend Micro.

Mitigation Measures

Trend Micro also recommended certain security measures to home router users, these include:

  • Manage vulnerabilities and apply patches as soon as possible. Vulnerabilities are the main way malware infects devices. Applying patches as soon as they are released can limit the chances for potential exploits
  • Apply secure configuration. Users must ensure that they are using the most secure configuration for their devices to narrow openings for compromise
  • Use strong, hard-to-guess passwords. Botnet malware takes advantage of weak and common passwords to take over devices. Users can circumvent this tactic by changing default passwords and using strong passwords

 

Know Thy Enemy: Why Company-Centric Threat Intelligence is a Critical Element of Cybersecurity

threat intelligence

Today’s defenders can have reams of information and log data available to them, with databases chronicling known threats and attack patterns. Unfortunately, the information available in these databases is most effective against documented threats or those with extremely well-established baselines. If an attacker does something different — especially when targeting a specific company, segment, or vertical—the information in these databases is often no longer sufficient or reliable.

By Carolyn Crandall, Chief Deception Officer and CMO at Attivo Networks

The sheer volume of available attack data can also be daunting, and while some may believe that more data is better, the truth is that concise and more precise information is what is really needed. Swiftly gathering and correlating company-centric threat intelligence has become an increasingly important aspect of cybersecurity and can make the difference between a small infection, outbreak, or breach.

Putting Defenders in a Position to Gather Better Intelligence

When it comes to collecting highly specific adversary intelligence, deception technology has proven to be a pivotal asset to companies seeking to stop, eradicate, and prevent the successful return of attackers. Whereas most security tools are designed simply to deflect an attack, deception technology redirects them to decoys where attackers believe they are still attacking a production system or advancing their attack with stolen credentials or other bait. Defenders can then observe the attacker’s movement through the deception environment, gathering information on their tactics, tools, and strategies. Using decoy documents for counterintelligence purposes can result in gaining knowledge of what an attacker is targeting. This enhanced visibility provides the security teams with unique insight into the attacker’s intent and approach, specific to the network they are attempting to infiltrate, accelerating investigations and analysis and ultimately decreasing the organization’s risk of future compromise and data loss.

Look at it this way: if you simply deflect the attack, you’ll never learn anything about how it behaves or how to stop it truly. If attackers encounter security tools designed only to remove them from the network, they can (and likely will) simply come back — and with each subsequent attempt, they will gain new intelligence on their target. Attackers can be very patient, gathering information over a long period as they acquire a fuller picture of the network and learn to circumvent its defenses. Tools like deception technology flip the script, alerting defenders to the presence of an attacker while enabling them to gather adversary intelligence, rather than the other way around.

Combining the General and the Specific to Visualize the Complete Threat Landscape

Gathering adversary intelligence is a central activity in everything from sports to law enforcement. Most companies seek to gain intelligence information by subscribing to threat intelligence feeds, which pull data from threat intelligence vendors who share it with subscribers. Typically, software patches will have already incorporated this information. It is often not specific enough, and attempts to pattern match can result in a flood of threat information that can be difficult to sift through. In contrast, the information provided by deception technology offers live insight into what is actually happening inside a company’s network. With cyber deception, businesses receive up-to-date, relevant indicators of compromise (IoCs) as well as the adversary’s tactics, techniques, and procedures (TTPs). With this information, they can defend against current and future attacks quickly and with a high degree of accuracy.

This level of specificity augments the more general public threat databases, to which the organization can append its self-generated adversary intelligence. Organizations capable of this level of intelligence gathering can create precise attack profiles unique to a given attacker, resulting in extensive information that provides insight into attack methods and prevention options. Concise, accurate, and highly specific information allow organizations to determine more quickly what actions they need to take. It can also automatically feed into other systems, which can save on both the time and resources required for incident response and refined threat hunting.

Valuable Adversary Intelligence Can Emerge Even in Simulations

Cyber deception can provide insights into security exposures during security risk assessments and in prep for compliance audits. With Red Teams acting as proxies for attackers and Blue Teams using deception, they can log their movements as in a real attack, tracking their path through the network and identifying potential vulnerabilities. These exercises can also demonstrate the network’s resiliency and confirm that things are working as they should. Deception holds an impressive track record of cases where Red Teams believed they had fully compromised a network’s Active Directory or other assets, only to learn after the exercise was over that they were in a deception environment the entire time.

Armed with company-specific attack data, defenders can quickly assemble actionable response plans. Additionally, by using deception technology’s unique ability to collect in-depth information about attack patterns and escalation they can build a powerful active defense, fortify defenses, and identify and stop attacks early in the attack lifecycle.

Putting That Adversary Intelligence to Use

Gaining more specific insight into how an adversary attacks within their particular network arms defenders with the information they need to protect themselves more effectively and gain insights across a wide variety of attack vectors and surfaces. By placing added focus on internal visibility — which, by design, prevention controls lack — defenders can better identify the specific tactics that attackers are deploying against their network and gather valuable information on the attacker’s entry point, IoCs, and potential targets.

Although removing the attacker from the network is pivotal to security, savvy companies are adding depth to their security programs by gathering adversary intelligence. Such information provides them with not only a safety net for detecting in-network attackers, but also the critical insights needed to understand what controls attackers bypassed and how. No cybersecurity technology is a silver bullet — comprehensive security requires layers of defense with multiple solutions working together — however deception’s ability to make life harder for attackers makes it a unique and indispensable tool for defenders.

About the Author

Carolyn CrandallCarolyn Crandall holds the roles of Chief Deception Officer and CMO at Attivo Networks. She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies. She has held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate. Crandall has received many industry recognitions including Top 25 Women in Cybersecurity 2019 by Cyber Defense Magazine, Reboot Leadership Honoree (CIO/C-Suite) 2018 by SC Media, Marketing Hall of Femme Honoree 2018 by DMN, Business Woman of the Year 2018 by CEO Today Magazine, Cyber Security Marketer of the Year 2020 by CyberDojo (RSA), and for 9 years a Power Woman by Everything Channel (CRN).

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.