New modes of phishing and new security evasion tactic used in Advanced Persistant Threat (APT) attacks on businesses revealed
CIOL Bureau
BY Sharath Kumar
BANGALORE, INDIA: From mass compromises of WordPress to a spear-phishing attack on the White House, there is no doubt cyber criminals gained confidence and momentum from year 2012.
In an interaction with CIOL, Surendra Singh, regional director, SAARC India, Websense, reveals the new modes of phishing and new security evasion tactic used in Advanced Persistant Threat (APT) attacks on businesses. Excerpts:
CIOL: How do you see the evolution of targeted threat model?
Surendra Singh: The malware adoption life cycle shows a change to a reduced window of exposure from months to under a week. The best example that we can suggest is Aurora. Google announced the attack on January 12, and four days later, the code was publicly available. Within weeks, the exploit was in the wild. Just 18 months later, there were 5,800 exploits using the same code.
The targeted threat model has moved from targeting individuals to targeting data, often using the individual as the door into the company and introduces layers of abstraction between malware author and the victim.
Whether it is breaking into a security company to steal source code, or a giant search firm to steal login credentials, most advanced attacks have follow a seven-stage pattern: It starts with reconnaissance, wherein, hackers access credentials and research social media profiles to gain intelligence about the victim.
This is followed by the use of web or email lures which rely either on the human curiosity or seemingly typical trustworthy email content. After this, users are usually directed to a survey, a rogue anti-virus (AV) offer or a fake web page where an exploit kit is waiting.
Exploit kits such as Blackhole are used to deliver a malware dropper file, and this dropper file is sent only after a vulnerability is detected in a targeted system. If no vulnerability is detected, the user is redirected to a safe web page and the exploit kit remains hidden.
The dropper file uses dynamic packers for which no known signatures and patterns are available because of which few AV engines can detect it. The advanced attack then “calls home” to download malware and tools and send back valuable information. Unfortunately, most defenses do not analyze the outbound call-home communications sent from within an infected system.
The attackers are finally able to reach the data by bypassing the insufficient security defenses at the previous six stages.
