Home Blog Page 335

Cybersecurity firm Trend Micro opens new operations center in Singapore

Trend Micro

Trend Micro, a Taiwanese cybersecurity and defense company, recently launched its new  headquarters in Singapore for Asia-Pacific, Middle East and Africa (AMEA) operations. The latest facility will be a part of Trend Micro’s new managed detection and response (MDR) security operations center across North America, Europe, and Southeast Asia.

Trend Micro stated its new center comprises an executive briefing area to host cybersecurity sessions for customers and government officials in the AMEA region. The company is also offering Certification Programs in IT Security to train the security officials in Singapore, Straitstimes reported.

Based out in Japan, Trend Micro is a major player in the information and network security landscape. Founded in 1988, the company holds a variety of cybersecurity merchandise for multiple operating systems, including threat detection, and antivirus products. Hybrid cloud security, network defense, user protection, and small business products are at the core of its product line.

“With Singapore serving as the command post, we hope to foster closer collaboration between different teams in AMEA, serve our regional customers better, and tap unexplored growth opportunities the region has to offer,” said Dhanya Thakkar, AMEA vice-president at Trend Micro.

In order to strengthen the country’s financial sector technology, the Monetary Authority of Singapore (MAS) recently announced the launch of S$30 million (US$22 million) cybersecurity capabilities grant.  The new allocation helps Singapore’s financial institutions strengthen their cyber resilience and upskill local talent through cybersecurity-related training programs like security operations, cyberthreat surveillance, computer forensics, malware analysis, and cyberthreat hunting.

The grant provided under the Financial Sector Technology and Innovation Scheme (FSTI) will co-fund up to 50 percent of expenses in Singapore-based financial institutions to establish their global or regional cybersecurity centers of excellence in the country. It would also support the organizations with regional cybersecurity centers to expand their cybersecurity capabilities globally.

Also, the governments of Singapore and the United States joined hands to strengthen their collaboration in the infrastructure sector, digital economy, and cybersecurity. Both countries renewed their Collaboration Platform Memorandum of Understanding (MOU) and signed a Declaration of Intent (DOI) to work together on a Singapore-US Cybersecurity Technical Assistance Program for ASEAN.

Google fined for $57 million for violating GDPR

Google Cybersecurity Action Team Google, EU warns Google

Search engine giant Google has been fined for 50 million euros (around $57 million) by the French data regulator CNIL (National Data Protection Commission) for violating the General Data Protection Regulation (GDPR) law. The data protection watchdog stated it had levied the fine for Google’s lack of transparency and valid agreement regarding ads personalization. The regulator also said that Google didn’t sufficiently inform the people about how it collected the users data to personalize ads.

The issue started when CNIL received complaints from the associations, None of Your Business (NOYB) and La Quadrature du Net (LQDN) in May 2018. The associations complained on Google for not having a valid legal basis to process the personal data of the users for ads personalization, as mandated by the GDPR.

“On 21 January 2019, the CNIL’s restricted committee imposed a financial penalty of 50 Million euros against the company GOOGLE LLC, in accordance with the General Data Protection Regulation (GDPR), for lack of transparency, inadequate information and lack of valid consent regarding the ads personalization,” CNIL said in a statement.

“This is the first time that the CNIL applies the new sanction limits provided by the GDPR. The amount decided, and the publicity of the fine, are justified by the severity of the infringements observed regarding the essential principles of the GDPR: transparency, information and consent,” the statement added.

The inspections carried out by the CNIL’s restricted committee found that Google has violated two core privacy rules of the GDPR- Transparency, and Consent. The committee notified that the information provided by Google is not easily accessible for users and the structure of the information does not comply with the data regulations. It also declared the users are not able to understand the processing operations carried out by the search engine giant.

Google is facing severe backlashes in recent times. The latest survey from Menlo Labs revealed that cybercriminals are using the Google Cloud to attack Financial Services Companies. The company stated that employees at financial services firms in the United States and the United Kingdom are being targeted by a malicious email campaign. The researchers revealed that cybercriminals are storing malicious payloads on storage.googleapis.com, the domain of the Google Cloud Storage service. The email campaign might have been active in the United States and the United Kingdom since August 2018.

Technical glitch leaks data of 141 international airlines’ fliers

Airlines

A bug in the Amadeus online ticket booking system exposed passengers’ private data, allowing potential attackers to view and change information. According to the security researcher Noam Rotem at Safety Detective research labs, the security flaw could let anyone manipulate someone’s ticket reservation for any airline which has used the Amadeus reservation system.

Amadeus is one of the largest reservation systems that serves around 141 airlines including customers of British Airways, Air France, Icelandair, United Airlines, Lufthansa, Air Canada, and Qantas. The company provides searching, pricing, booking, ticketing, and other processing services to international travelers and travel agencies.

Rotem stated that he discovered the issue after receiving an error code from the ticketing system while booking. He said, he was able to view customers’ Passenger Name Records and change account details, assign seats and meals, and update the customer’s email and phone number by exploiting that code.

“After running a small and non-threatening script to check for any brute-force protections, none of which were found, we were able to find PNRs of random customers, which included all of their personal information. We contacted ELAL immediately to point out the threat and prompt them to close the breach before it was discovered by anyone with malicious intentions,” Safety Detective said in a post.

Amadeus fixed the vulnerability after Safety Detective reported the data leak. Confirming the same Amadeus stated, “At Amadeus, we give security the highest priority and are constantly monitoring and updating our systems. Our technical teams took immediate action and we can now confirm that the issue is solved. To further strengthen security, we have added a Recovery PTR to prevent a malicious user from accessing travelers’ personal information. We regret any inconvenience this situation might have caused,”

In a similar incident, the Singapore Airlines (SIA) services recently reported that a software glitch possibly exposed personal information of 285 members who used its services. The Singapore flag carrier stated that a bug in its website caused a data leakage of KrisFlyer, a regular flyer program of Singapore Airlines. The bug exposed KrisFlyer customers’ personal information, including the member’s full name, email address, membership tier, account number, the accumulated miles/rewards, travel history, passport, and flight information.

Massive data breach exposes millions of emails and passwords

"db8151dd" An Untraceable Data Breach: 22 Mn Emails Compromised

A massive data breach leaves around 773 million email addresses and more than 21 million passwords unprotected online. According to the security researcher Troy Hunt, the person behind the breach notification service website Have I Been Pwned, a huge database that includes records from more than 2,000 hacked databases was exposed online.

The breached data, which Troy Hunt dubbed it as Collection #1, include around 773 million (772,904,991) unique email addresses and 21 million (21,222,975) unique passwords. Sized around 87 GB, the breached records also included 1,160,253,228 unique combinations of breached email addresses and passwords. Hunt stated the data breach is made up of various individual data breaches from thousands of other sources.

“I found a combination of different delimiter types including colons, semicolons, spaces and indeed a combination of different file types such as delimited text files, files containing SQL statements and other compressed archives,” Troy Hunt said in a post.

Hunt stated that he discovered the data leak after one of his contacts pointed him to a hacking forum, where the hacked data was being kept for sale.

“Last week, multiple people reached out and directed me to a large collection of files on the popular cloud service, MEGA (the data has since been removed from the service). The collection totaled over 12,000 separate files and more than 87GB of data. One of my contacts pointed me to a popular hacking forum where the data was being socialized,” Hunt added.

Hunt stated that people can find out if their email and password were among the impacted accounts using his breach notification service Have I Been Pwned. He also suggested to change their passwords on an immediate basis.

Internet has seen multiple data leaks in the first month of 2019. Recently, social media platform Reddit alerted its users that some of their accounts were locked out because of suspicious activity. The US-based news aggregator stated that it received many requests for new passwords that may indicate unauthorized access. Also, Germany saw a massive data breach where personal data and documents of several eminent public personalities including the Chancellor Angela Merkel were published online.

ICYMI: 6 Top Stories (Jan 14-20)

2.6 Mn scrapped data exposed

Due to ongoing high-profile data breaches, cybersecurity is a trending topic in all
kinds of media. It is imperative that information security executives are updated
about the incidents around them. Read on for the most important cybersecurity
stories of the last week.

1. Amazon India suffers data breach; sellers’ financial information exposed

Amazon

E-commerce giant Amazon has again suffered another technical glitch on its India portal that affected its sellers and vendors. The Seattle-based e-tailer stated that a bug in its website caused a data breach on January 08, 2019, that exposed sensitive financial information, including sales, category-wise split and inventory data of its sellers and vendors. Having around 400,000 online vendors and sellers across the country, Amazon said the issue was resolved within a few hours, but, the exact figure of affected members is not yet discovered.

Read more

2. Unprotected server exposes personal info of job seekers in China

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

An unprotected MongoDB server exposed a database that contains resumes of 202 million Chinese people online, according to a researcher.

Bob Diachenko, Director of Cyber Risk Research at HackenProof, discovered that the unsecured server was left visible online without a password, thus exposing the resumes that contained personal details such as mobile phone number, email, marital status, driver license, literacy level, salary expectations, skills, and work experience. The leaky server was secured soon after Diachenko publicized the issue via a Twitter post.

Read more

3. Reddit notifies users about potential data breach

Reddit

Social media platform Reddit has alerted its users that some of their accounts have been locked out because of suspicious activity. The US-based news aggregator stated that it received many requests for new passwords that may indicate unauthorized access.

Reddit said that its security officials are working on to fix the issue. It suggested the users update their passwords and also advised to use the latest email address for Reddit accounts, enabling automated password resets and two-factor authentication for additional protection. The company notified the affected users and allowed them to reset the passwords to restore the accounts.

Read more

4. Check Point acquires security startup ForceNock

Acquisition

Cybersecurity solutions provider Check Point Software Technologies recently acquired Web Application and API Protection (WAAP) provider ForceNock. Check Point offers cybersecurity solutions to private and government enterprises globally. The company claims that its multi-level security architecture enables its clients to defend against malware, ransomware and other targeted attacks across all networks, cloud and mobile operations. Check Point stated the latest deal will strengthen its machine learning protection capabilities.

Read more

5. OneLogin raises $100 million to expand its Unified Access Management services

startup

OneLogin, an access and identity management startup, recently raised $100 million investment in a financing round led by Greenspring Associates and Silver Lake Waterman along with the existing investors CRV and Scale Venture Partners. The California-based startup stated the new funds will be used to accelerate the adoption of its new products like Multi-Factor Authentication (MFA) to serve enterprises in the new Unified Access Management (UAM) sector. OneLogin also said the funds will be used to extend its footprints in North America and Europe regions.

Read more

6. 15 top cybersecurity searches on Google last year

malicious PDFs

When Google revealed its top searches of 2018 list, it was mainly focused on pop culture.

And while that’s cool, the team really wanted to know about the hottest cybersecurity search topics of the year, so we went digging into what people in the U.S. were searching for regarding InfoSec.

Read more

Cloud data management startup Rubrik raises $261 million

Funding round

Rubrik, a cloud data management startup, recently raised $261 million in a Series E funding round led by Bain Capital Ventures along with the existing investors Lightspeed Venture Partners, Greylock Partners, Khosla Ventures, and IVP. The California-based startup stated the new investment will be used for corporate purposes, future innovation, and to support the launch of its new products and services.

Founded in 2014 by Arvind Jain, Arvind Nithrakashyap, Bipul Sinha, and Soham Mazumda, Rubrik helps enterprises to protect and manage their data across private and public clouds with its cloud data management platform.

Rubrik provides live data access to enterprises for recovery and application development by combining enterprise data management with web-scale IT. The company claims that most organizations rely on its Polaris SaaS platform to combine data for security, governance, and compliance. Rubrik holds a wide range of business partners including Microsoft, Cisco, AWS, SAP, Nutanix, Oracle, VMware, Google Cloud, and Pure Storage.

Speaking on the new investment Bipul Sinha, Co-founder and CEO at Rubrik said, “Our previous fundraising in 2017 was focused on global expansion and increasing our reach into the enterprise market. Now, with thousands of customers around the world, industry-leading customer satisfaction ratings, and numerous analyst and industry awards, we have customers asking us to solve new challenges. This new capital will speed the introduction of exciting new products in 2019 that will solve those customer challenges and significantly expand our strategic footprint in the enterprise.”

“Rubrik has won the trust and loyalty of large enterprise customers around the globe by offering a simple and reliable solution that solves the challenge of protecting and managing data in a hybrid cloud world. When we met Bipul, we were instantly impressed with his vision as well as the skill and tenacity of his team. Given my experience leading the largest enterprise data protection company, we are confident that Rubrik is positioned to win and be the market leader in enterprise cloud data management,” said Enrique Salem, Partner at Bain Capital Ventures.

ECS partners with enterprise search company Elastic

Partnership

ECS, a cloud and cybersecurity solutions provider, recently announced that it’s entering into a partnership with Elastic, an enterprise search engine company. The new alliance enables ECS to leverage Elastic’s technology to enhance the security, reliability, and speed of its big data solutions. The integration of the ECS and Elastic technology solutions will improve the security and enable machine learning for customers across federal civilian, defense, and commercial sectors.

ECS helps enterprises with its advanced services in the cloud, cybersecurity, artificial intelligence, IT modernization, and engineering segments. The U.S. based company claims that it has a collaborative approach in resolving critical issues in public and private sector, defense, intelligence, and commercial industries across the country.

Elastic provides technology solutions for powering search functions and is the creator of the Elastic Stack, (that’s Elasticsearch, Kibana, Beats, and Logstash) a group of open source products intended to help users explore data regardless of format and source. The company claims that its software suite embedded with self-managed and SaaS offerings enables users to search in real-time, logging, security, analytics, and visualization of data.

“Given ECS’ early and continued adoption of machine learning, our partnership with Elastic is a natural fit,” said Aaron Faulkner, vice president of cybersecurity and manager of the ECS Cyber Center of Excellence. “Our data scientists, cybersecurity analysts, and systems engineers are leveraging Elastic’s open-source technology in ways that change how our customers use and act on data.”

“Elastic is powering the next generation of capabilities for search, monitoring, and analysis across virtually every vertical of government, defense, academia, industry, and critical infrastructure,” said George Wilson, president of ECS. “As our customers are seeking an ever-greater return on their investments, they have fully embraced open source technologies to deliver value, lower their cost of solutions, and chip away at decades of vendor lock-in. We are excited to partner with Elastic and contribute to the vibrant open source community.”

“SOCs help organizations in optimizing controls”

Akshay Aggarwal

Akshay Aggarwal is Cloud Specialist Director – Manageability & Security at Oracle Asia Pacific region. In this role, Akshay is responsible for business development for all the solution specialist product lines of Oracle including AppDev, Mobility, Digital Experience, Integration, Manageability and Security in all the entire Asia Pacific region.

In a discussion with CISO MAG’s Augustin Kurian, he talks about evolving threat landscape, the need of SOC for an organization, and changes GDPR brought to businesses.

How do you see the threat landscape evolving?

The security landscape is evolving more quickly than ever before. The network perimeter has dissolved, even as the number of devices, services, and people allowed to access applications and data, have increased. Automated threats—where it’s not a human being sitting behind a console trying to compromise an IT environment, but rather an automated program running scripts in an attempt to infiltrate systems—have become ordinary. Just a few years ago, concerns about data security and privacy prevented some organizations from adopting cloud-based business models. Today, many of these concerns have been alleviated. IT leaders are migrating their applications and data to the cloud in order to benefit from security features offered by some cloud providers. Both private enterprises and governments have come to realize that traditional IT infrastructure can no longer cope with new-age security threats, which rapidly continue to grow. Current infrastructure and processes can be challenged to protect different varieties of data moving much faster throughout the entire technology stack. Security operations centers (SOCs) are bombarded with millions of alerts; it is not humanely possible to keep pace without new paradigms to triage, automate, and respond to them all.

With hybrid environments, do you think companies are ill-prepared against handling breaches?

The hybrid cloud environment enables business to quickly modernize, transform and innovate; but at the same time, it can pose multiple security threats. Companies need to be able to ingest high amounts of operational and security telemetry and analyze data real-time and embed built-in machine learning (ML) solutions to tackle security breaches. They should also focus on reducing human intervention and automate the entire cyber-defense system.

How is Oracle equipped in averting advanced persistent threats?

Oracle closely works with customers on an ongoing basis, advising them to secure their data against advanced threats, irrespective of the place where the data is stored. We have developed an advanced cyber-defense system running on the cloud that not only encrypts the data but also uses threat intelligence systems to stop any attack on the cloud. Oracle has also introduced an identity security operations centre (iSOC), which includes a remedy system that takes action real time as and when a security breach or any incident that takes place.

Now let me tell you about the management of data itself and Oracle’s approach in this regard. Oracle Autonomous Database—the world’s first self-driving, self-securing and self-repairing database—is redefining the way businesses manage and secure their data. Powered by ground-breaking ML, Oracle Autonomous Database takes the complexity out of running a business-critical database to help businesses realize unprecedented availability, high performance and security – all at a significantly lower cost. With adaptive intelligence-enabled cyber threat detection and remediation, as well as automatic data encryption and with security patches getting automatically applied, Oracle Autonomous Database provides unparalleled security for your critical business data. In fact, there are significant security advantages that automated patch management can bring in. Per a recent study by Verizon, it was estimated that a majority of security breaches that occurred, were primarily because the updated security patches weren’t applied – though available.

What according to you are best practices to be established?

While there is no ‘one size fits all’ approach to security, here are some steps organizations can take to begin with, to thwart cyber threats:

  • Ensure policies and mechanisms are in place to meet compliance requirements across the cloud
  • Enhance cybersecurity policies/programmes that augment network security controls with strategies, skills and processes
  • Look at built-in ML and automated systems to respond to threats with confidence and dramatically combat security challenges
  • Review the security posture of all SaaS, PaaS, and IaaS projects for industry best practices
  • Identify risks where security requirements cannot be fully addressed
  • Look for opportunities where security can be optimized and enhanced

Tell us a bit about the Oracle Trust Fabric. What all vectors are covered by the suite?

The Trust Fabric is powered by our decades of experience of safeguarding the world’s most important data. With the Trust Fabric, Oracle is bringing autonomous security, enabled by AI/ML solutions into the enterprise. The Oracle Trust Fabric offering includes cloud infrastructure analytics and monitoring along with identity and access management for customers. It also allows additional visibility into how an identity is being used and how activities can be monitored to help identify atypical/aberrant behaviours.

Integrated in a cloud-first fashion (as the delivery model), Oracle Trust Fabric provides a single view of the operational security risk and can handle these risks in a much better way, by managing all the systems running on-premises or on cloud.

Can you tell us how are SOCs better than a Security Team? When should an organization realize it needs a SOC? What are the required and concerned parameters for the same?

Today’s attacks have increased in sophistication. Threats are multi-vector now, utilizing multiple entry points. Unlike before, where the attack focus used to be indiscriminate, it is now targeted – which makes user awareness and attribution invaluable in detection. Early detection is now the key as threats no longer last for an hour or two, but are rather persistent and can affect a system for even days, weeks or months. In such conditions, a traditional security team might not be fully equipped or might lack the scale, pace and bandwidth to fight against each and every challenge that arises. This is where AI/ML powered advanced security solutions make the difference.

With sophisticated security processes, SOCs will be able to sail through the many ‘false positives’ or red flags and zero in on only the subset of threats that really need to be managed. SOCs will improve cost efficiency of the organizations and will help in optimizing controls. It will also help the IT teams to consolidate technologies, tools and processes to improve preparedness and adapt strategic cyber-defense solutions.

There’s one caveat though—every organization might not be in a position to have a robust, dedicated SOC that’s constantly learning and updating skillsets to keep pace with (and counter) the ever expanding threat landscape. This is where end-to-end security providers like Oracle come in by providing it as a cloud service.

Extensive deployment of AI/ML seems to be the easy and immediate remedy. But what are the immediate challenges that accompany this?

To secure enterprise IT assets and protect against increasingly sophisticated attacks, forward-looking organizations are adopting cybersecurity technologies that are continuously learning and adapting, in real-time, and are inherently intelligent. They rely on AI/ML algorithms to manage configurations, monitor who has access to what resources, and encrypt sensitive data to protect IT assets. An advanced security system can adapt to changing conditions, driven by ML that automatically detects and fixes problems without human agents – a capability we refer to as adaptive response.

Security operations boil down to two fundamental metrics: how quickly can you detect a breach, and how quickly can you respond to a known attack – known as mean time to detect (MTTD) and mean time to respond (MTTR), respectively.

AI/ML can help companies correlate events and apply heuristics to detect patterns, trends, and anomalies in the data: including detecting new alerts, adding context to those alerts, and responding quickly to address and resolve incidents. An automated cloud security solution can continuously evaluate millions of patterns and uncover anomalies and suspicious activity. ML algorithms scale well to accommodate large volumes of data when deployed in the cloud. Due to the massive amount of data involved, on-premises solutions quickly turn into large infrastructure sets requiring constant expansion to address compute and storage needs. An AI algorithm processes the data to identify patterns, create audit reports, and detect security risk indicators based on pre-defined threat models, baseline risk indicators, abnormal events, and suspicious user behaviour activity.

Contrary to the popular belief that AI/ML brings in complexity and is difficult to manage, Oracle’s self-driving cyber defense system is able to run autonomously without any human intervention to provide self-driving, self-learning, self-patching, self-securing and self-remediation capabilities. Hence, now, security teams can spend their time qualitatively on analyzing real threats linked to user identity instead of spending hours and hours sifting through a plethora of false positives (the superset of alerts that get flagged).

With GDPR in place, how does Oracle address regulatory and compliance mandates on behalf of third parties?

With data privacy concerns being a priority for organizations dealing with data and stern regulatory compliance procedures like GDPR coming into force, organizations are required to redefine the way they approach data management. A good first step would be to put in place a cohesive IT architecture, whose systems and applications are built to work seamlessly as an integrated unit. The data can then be organized in such a way that it’s easier to find, change, transfer, erase and comply with regulatory requirements.

Oracle has been the undisputed leader in data security for decades. With a long history and proven record of securing data and systems, Oracle has led the data security spectrum for years. Oracle security includes a full set of hybrid cloud solutions, from the chip to applications, that help prevent, predict, detect and respond to security threats. We have an extensive value proposition to help address GDPR requirements that impact data inventory, risk awareness, application modification, and architecture integration.

Do you think several key government bodies of India, U.S, and UK needs SOCs to protect their critical infrastructure?

Most definitely yes. Most of the government bodies of India, US and UK already have SOCs running at different state and national levels to protect their critical infrastructure. The challenge remains how fast they are able to keep pace with the changing technology and threat landscape to ensure citizen data is secured at all times, irrespective of where it resides. Hence, leveraging brand new cyber-defense systems which use AI/ML capabilities is extremely important for them as well as they too are adopting technologies which run in the private and public cloud to provide cutting edge services to the citizens of their country.

Onapsis acquires ERP cybersecurity company Virtual Forge

Acquisition

ERP cybersecurity solutions provider Onapsis recently announced that it has entered into a decisive agreement to acquire Germany-based cybersecurity firm Virtual Forge. The proposed agreement, which is expected to close in the first quarter of 2019, will help Onapsis to expand its reach in the global market by leveraging Virtual Forge’s international reputation and strengthen Onapsis’s leadership in ERP cybersecurity.

Onapsis cybersecurity solutions automate the protection of ERP business-critical applications to protect the vital information and systems. The company claims that its software platform is the most widely-used security solution that protects the ERP systems and business-critical applications.

Founded in 2006, Virtual Forge is the provider of security solutions that prevent, detect, and remediate cybersecurity and compliance risks in SAP platform and cloud business applications. The integration of Onapsis and Virtual Forge will allow customers to have unparalleled visibility, incident response, management, and compliance for businesses.

Speaking on the new acquisition move, Mariano Nunez, CEO, and Co-founder at Onapsis said, “Organizations are continuously extending their cloud and on-premise ERP applications to support evolving business requirements, which introduces serious cybersecurity and compliance risks if not properly managed. With this acquisition, organizations will have one single partner and one single platform to secure and protect their SAP infrastructure, including segregation of duties, custom code analysis, vulnerability assessments, secure change management, compliance automation, and continuous monitoring. We are excited to combine the unique technology, talent and domain expertise of our companies to help organizations further secure the critical applications that run their business.”

“We are excited to join Onapsis in the shared vision of protecting the world’s business-critical applications. Together, we will have the most comprehensive technology portfolio in the industry, global scale and a strong team of over 300 experts in the ERP and cyber security domains,” stated Dr. Markus Schumacher, CEO, and Co-Founder, Virtual Forge.

West African banks and financial firms suffer cyber-attacks: Symantec

Bank cyber-attack

Multiple banks and other financial companies in several West African countries have suffered from different hacking attacks, which are underway since mid-2017

According to a report published by Symantec, financial institutions in Cameroon, Congo (DR), Equatorial Guinea, Ghana, and the Ivory Coast have been hit by multiple cyber-attacks in 2017 and 2018. Symantec stated the intruders who are behind these attacks were unknown.

Symantec stated that it has detected four distinct hacking campaigns targeted against financial firms in Africa. The first attack started in mid-2017, and has infected computers with a malware known as NanoCore (Trojan.Nancrat). The second type of attack began in late 2017, in which cybercriminals used malicious PowerShell scripts and credential-stealing tool Mimikatz (Hacktool.Mimikatz) to exploit their targets.

The third attack was targeted at banks in Ivory Coast using a malware called Remote Manipulator System RAT (Backdoor.Gussdoor), alongside Mimikatz and two custom Remote Desktop Protocol (RDP) tools. The fourth attack started in December 2018. The intruders used a malware known as Imminent Monitor RAT (Infostealer.Hawket) to attack banks in Ivory Coast. Symantec stated that all the four attacks were discovered through alerts generated by its Targeted Attack Analytics (TAA), which uses artificial intelligence to analyze and spot targeted attacks.

“A growing number of attackers in recent years are adopting “living off the land” tactics—namely the use of operating system features or network administration tools to compromise victims’ networks. By exploiting these tools, attackers hope to hide in plain sight, since most activity involving these tools is legitimate. However, in each case, a TAA alert was triggered by the attackers maliciously using a legitimate tool. In short, the attackers’ use of living off the land tactics led to the discovery of their attacks,” Symantec said in a statement.

In a similar finding, Symantec revealed that cybercriminals are rapidly adding cryptojacking to their arsenal and creating a highly profitable new revenue stream, as the ransomware market becomes overpriced and overcrowded. The cybersecurity company provided a comprehensive view of the threat landscape, including insights into the global threat activity, cybercriminal trends, and motivations for attackers.

The report analyzes data from the Symantec Global Intelligence Network, the largest civilian threat collection network in the world, records events from 126.5 million attack sensors worldwide and monitors threat activities in over 157 countries and territories.