Continued increase in cyberattacks
Many modern malware tools already incorporate features for evading antivirus or other threat detection measures, but cyber adversaries are becoming more sophisticated in their obfuscation and anti-analysis practices to avoid detection.
For example, a spam campaign demonstrates how adversaries are using and tweaking these techniques against defenders. The campaign involves the use of a phishing email with an attachment that turned out to be a weaponized Excel document with a malicious macro. The macro has attributes designed to disable security tools, execute commands arbitrarily, cause memory problems, and ensure that it only runs on Japanese systems. One property that it looks for in particular, an xlDate variable, seems to be undocumented.
Another example involves a variant of the Dridex banking trojan which changes the names and hashes of files each time the victim logs in, making it difficult to spot the malware on infected host systems.
The growing use of anti-analysis and broader evasion tactics is a reminder of the need for multi-layered defenses and behavior-based threat detection.
The Zegost infostealer malware, is the cornerstone of a spear phishing campaign and contains intriguing techniques. Like other infostealers, the main objective of Zegost is to gather information about the victim’s device and exfiltrate it. Yet, when compared to other infostealers, Zegost is uniquely configured to stay under the radar. For example, Zegost includes functionality designed to clear the application, security, and system event logs. This type of cleanup is not seen in typical malware. Another interesting development in Zegost’s evasion capabilities is a command that kept the infostealer “in stasis” until after February 14, 2019, after which it began its infection routine.
The threat actors behind Zegost utilize an arsenal of exploits to ensure they establish and maintain a connection to targeted victims, making it far more of a long term threat compared to its contemporaries.
The attacks on multiple cities, local governments, and education systems serve as a reminder that ransomware is not going away, but instead continues to pose a serious threat for many organizations going forward. Ransomware attacks continue to move away from mass-volume, opportunistic attacks to more targeted attacks on organizations, which are perceived as having either the ability or the incentive to pay ransoms. In some instances, cybercriminals have conducted considerable reconnaissance before deploying their ransomware on carefully selected systems to maximize opportunity.
For example, RobbinHood ransomware is designed to attack an organization's network infrastructure and is capable of disabling Windows services that prevent data encryption and to disconnect from shared drives.
Another newer ransomware called Sodinokibi, could become another threat for organizations. Functionally, it is not very different from a majority of ransomware tools in the wild. It is troublesome because of the attack vector, which exploits a newer vulnerability that allows for arbitrary code execution and does not need any user interaction like other ransomware being delivered by phishing email.
Regardless of the vector, ransomware continues to pose a serious threat for organizations going forward, serving as a reminder of the importance of prioritizing patching and infosecurity awareness education. In addition, Remote Desktop Protocol (RDP) vulnerabilities, such as BlueKeep are a warning that remote access services can be opportunities for cybercriminals and that they can also used as an attack vector to spread ransomware.
Between the home printer and critical infrastructure is a growing line of control systems for residential and small business use. These smart systems garner comparably less attention from attackers than their industrial counterparts, but that may be changing based on increased activity observed targeting these control devices such as environmental controls, security cameras, and safety systems. A signature related to building management solutions was found to be triggered in 1% of organizations, which may not seem like much, but it is higher than typically seen for ICS or SCADA products.
Cybercriminals are searching for new opportunities to commandeer control devices in homes and businesses. Sometimes these types of devices are not as prioritized as others or are outside the scope of traditional IT management. The security of smart residential and small business systems deserves elevated attention especially since access could have serious safety ramifications. This is especially relevant for remote work environments where secure access is important.
Threat intelligence that is dynamic, proactive, and available in real-time can help identify trends showing the evolution of attack methods targeting the digital attack surface and to pinpoint cyber hygiene priorities. The value and ability to take action on threat intelligence is severely diminished if it cannot be actionable in real-time across each security device. Only a security fabric that is broad, integrated, and automated can provide protection for the entire networked environment, from IoT to the edge, network core and to multi-clouds at speed and scale.
Phil Quade, Chief Information Security Officer, Fortinet “The ever-widening breadth and sophistication of cyber adversaries’ attack methods is an important reminder of how they are attempting to leverage speed and connectivity to their advantage. Therefore, it is important for defenders to do the same and to relentlessly prioritize these important cybersecurity fundamentals, to position organizations to better manage and mitigate cyber risks. A security fabric approach across every security element that embraces segmentation and integration, actionable threat intelligence, and automation combined with machine learning is essential to enable these fundamentals to bear fruit.”
The latest Fortinet Threat Landscape Report is a quarterly view that represents the collective intelligence of FortiGuard Labs, drawn from Fortinet’s vast array of global sensors during Q2 2019. Research data covers global and regional perspectives. Also included in the report is the Fortinet Threat Landscape Index (TLI), comprised of individual indices for three central and complementary aspects of that landscape which are exploits, malware, and botnets, showing prevalence and volume in a given quarter. |
See also
Vietnamese firms attend IT, industrial expo in Germany
14:58 | 18/04/2023 Information technology
Import tax exemption to benefit domestic ICT industry
10:34 | 12/04/2023 Information technology
Vietnam, the Netherlands promote exports through digital environment
15:19 | 06/04/2023 Information technology
Ransomware top menace for enterprises in SEA
15:00 | 14/03/2023 Information technology
PM urges basic, comprehensive reform in digital transformation
06:00 | 06/03/2023 Digitalization
Vietnam’s AI leadership status improving
06:00 | 04/03/2023 Information technology
See more news
Managed security provides IT talent gap solution for businesses in SEA
16:34 | 30/01/2023 Information technology
Top 10 ICT developments in 2022
06:00 | 11/01/2023 Information technology
Cybersecurity resilience emerges as top priority for Vietnamese organizations
15:39 | 05/01/2023 Information technology
ETH Vietnam: The first hub for blockchain community to build and learn together
16:23 | 17/11/2022 Information technology
Wolfoo product sets certificated as standard content
16:15 | 01/11/2022 Make in Vietnam
Base.vn received the International Award ASOCIO 2022
18:05 | 31/10/2022 Make in Vietnam
Bkav, Excelpoint provide AIoT platform built on Qualcomm ecosystem
10:01 | 21/10/2022 Make in Vietnam
C.P. Vietnam’s HR digital transformation with SAP® SuccessFactors® Solution
21:18 | 13/05/2022 Digitalization
A “Make in Vietnam” communications programming platform
13:00 | 26/12/2021 Information technology
Vietnamese patents make imprints on international maps
06:00 | 22/05/2021 Digitalization
New Zealand announces new government scholarship for Vietnamese students
18:21 | 23/11/2024 Society
Vietnam prioritises education for youths on friendship, solidarity with Cambodia: NA leader
18:19 | 23/11/2024 Cooperation
Top Vietnamese leader concludes official visit to Malaysia
16:33 | 23/11/2024 News and Events
MM Mega Market hosts 2024 Customer Fair
16:29 | 23/11/2024 Companies
Exhibitions in Hà Nội downtown celebrate Heritage Day
13:55 | 23/11/2024 Culture
Multimedia
Strengthening Vietnam-Cambodia friendship and cooperation
09:00 | 22/11/2024 Infographic
Vietnam - Malaysia Strategic Partnership
10:54 | 21/11/2024 Infographic
Vietnam, Dominican Republic strengthening cooperation
08:45 | 20/11/2024 Infographic
Vietnam - Brazil strategic partnership
10:26 | 19/11/2024 Infographic
Nhon - Hanoi Station elevated urban railway comes into operation
09:04 | 18/11/2024 Infographic
New decree on using telecommunications accounts for payment proposed
09:29 | 22/11/2024 Policy
Parliament approves amendments to pharmacy law
08:54 | 22/11/2024 Policy
VAT tax reduction should continue until mid-2025: Ministry
17:15 | 21/11/2024 Policy
NA deputies scrutinise investment policy for North-South high-speed railway project
08:54 | 21/11/2024 Policy
Vietnam’s automotive supporting industry: A bright future ahead, riding the wave of growth
20:42 | 22/11/2024 Industry
VN's food processing industry struggles to improve quality and value chain integration
11:36 | 22/11/2024 Industry
Tra fish sector aiming for production, processing greening for sustainable development
15:38 | 20/11/2024 Industry
Solutions discussed to ensure coal supply for electricity generation in 2025
16:24 | 19/11/2024 Energy
Thai packaging giant takes 30-year lease for largest ready-built factory in Tay Ninh
16:58 | 22/11/2024 Investment
Workshop seeks ways to attract Japan’s green investment to Vietnam
09:43 | 20/11/2024 Investment
Government approves investment policy to build Cam Lien Industrial Park in Quang Binh
16:57 | 18/11/2024 Investment
Disbursement of public investment must be accelerated: Deputy PM
12:17 | 17/11/2024 Investment
HDBank wins three awards at Vietnam Listed Company Awards 2024
10:53 | 21/11/2024 Finance-Banking
VIB, Flywire partner to streamline cross-border payments for students from Vietnam
16:46 | 18/11/2024 Finance-Banking
Vietcombank issues 2 trillion VND worth of green bonds for first time
18:55 | 16/11/2024 Finance-Banking
UK stands ready to help Vietnam build international financial hub
17:13 | 13/11/2024 Finance-Banking
Significant progress in fisheries' environmental protection but challenges remain
09:35 | 22/11/2024 Environment
Hà Nội prepares for temperature drop as cold front approaches
16:56 | 21/11/2024 Environment
Hundreds of damaged irrigation reservoirs need repairing
09:02 | 20/11/2024 Environment
Greening e-commerce crucial for sustainable development
10:47 | 18/11/2024 Environment
Việt Nam and Korean NIPA strengthen tech cooperation
10:42 | 22/11/2024 Science - Technology
Cyberattack risks surge with AI advancements
10:39 | 22/11/2024 Science - Technology
People, community at heart of digital transformation: Deputy PM
09:26 | 21/11/2024 Science - Technology
AI is core technology of 4th Industrial Revolution: Minister
11:19 | 20/11/2024 Science - Technology
New Zealand announces new government scholarship for Vietnamese students
18:21 | 23/11/2024 Society
WB suggests five pillars for Vietnam’s electric transport plans
09:23 | 23/11/2024 Society
Association boosts insurance sector’s sustainable development
16:30 | 22/11/2024 Society
Vietnam, Venezuela step up educational cooperation
16:23 | 22/11/2024 Society
Doubling insurance product’s payout significantly benefits customers
16:22 | 22/11/2024 Vietnamese Brands
PJICO: 30 years of development
11:19 | 22/11/2024 Vietnamese Brands
VN takes part in food and beverage fair in Chicago
09:45 | 20/11/2024 Vietnamese Brands
Hòa Bình honey awaits reactions from UK
10:41 | 19/11/2024 Vietnamese Brands
Exhibitions in Hà Nội downtown celebrate Heritage Day
13:55 | 23/11/2024 Culture
Vibrant cultural rendezvous in Hanoi
15:30 | 22/11/2024 Lifestyle
Cultural activities celebrate Việt Nam Heritage Day
10:06 | 22/11/2024 Culture
Bac Ninh Province: Dong Ho folk painting needs urgent safeguarding
15:04 | 20/11/2024 Culture
Agritourism needs opportunities to “take off”
12:05 | 23/11/2024 Tourism
Golden time for community-based tourism development
10:38 | 22/11/2024 Tourism
Christmas Festival to entertain visitors to Đà Nẵng
09:53 | 22/11/2024 Tourism
How trekking the mountains lifted me up and above ... the clouds: conquering Lùng Cúng
09:45 | 22/11/2024 Tourism