#InfosecurityEurope: Experts Highlight Evolving Attack Techniques

Cybercriminals are notorious for their ability to pivot quickly in the face of improved defenses, and keeping up with evolving tactics, techniques, and procedures (TTPs) is a major challenge for security professionals.

During Infosecurity Europe 2023, Information security Magazine spoke to various security experts about the attack trends they’re observing and that organizations should be aware of. These mostly revolved around his two main areas: malicious use of AI tools such as ChatGPT and identity-based attacks.

ChatGPT and AI abuse

Craig Terron, Insikt Group Global Issues Director at Recorded Future, said financially motivated cybercriminals have so far used AI tools much more extensively than state actors, and these technologies have enabled criminal activity. said the barriers to entry are low. cyber crime.

“As soon as ChatGPT was launched, cybercriminals started talking about it on various forums. They saw the opportunity as quickly as we did,” he said. Information security.

One of the main ways AI chatbots are being used today is through the use of malware. Terron explained that this puts him in two categories. One is to help build new malware, and the other is AI-embedded malware. The latter is “where malware decides how best to compromise a particular victim, and now it’s more on the AI-powered side,” Theron commented.

Of particular concern is ChatGPT’s role in creating polymorphic malware that uses cryptographic keys to change its shape and signature to evade detection. Terron added, “He has seen several cases where ChatGPT has been used to develop polymorphic malware that overcomes antivirus solutions.”

Another trend is the use of ChatGPT to aid more sophisticated phishing campaigns. “You can ask ChatGPT to create emails that appeal to authority, urgency, and emotion,” he said.

Adenike Cosgrove, vice president of cybersecurity strategy for EMEA at Proofpoint, said cybercriminals are using tools like ChatGPT and Bard to create country-specific phishing campaigns that break down language barriers. I was. “They are using these tools to create linguistic phishing messages, so they are creating more compelling country-specific lures,” she said. rice field.

Terron also highlighted the growing use of deepfake voice cloning technology for fraud and misinformation. Deepfake voices and videos are still relatively easy to recognize, but voice spoofs of celebrities who have given many street speeches are now very accurate because they are “based on the data out there.” .

identity-based attack

Cosgrove observed that while cybercriminals have long targeted individuals to evade technological controls, the techniques they use to do so are changing.

In particular, we are finding new ways to overcome privileged access management (PAM) and multi-factor authentication (MFA) to continue targeting individual identities.

“They are using that individual’s trusted identity to install malware, gain access to domains, elevate privileges, and access other parts of the organization,” she outlines. In 2023, your ID will be the crown jewel,” he added.

One of the MFA bypass techniques Cosgrove highlighted was reverse proxies. This allows the threat actor to steal the user’s credentials and her MFA code by redirecting the user to her similar website.

Harman Singh, managing director and consultant at Cyphere, has observed an increase in “MFA bombing” attacks as a means of bypassing additional layers of authentication. This is where the attacker repeatedly sends second-factor authentication requests to the target victim’s email, phone, or registered device until they finally accept the request.

That’s why Richard Meeus, Akamai’s Director of Security Technology and Strategy EMEA, describes MFA as “both a blessing and a curse.” While this reduces the risk of compromise, it can also leave organizations content to believe it’s a silver bullet when it’s no longer the case.

Another approach to identity-based attacks that Cosgrove and Singh have seen is compromising the credentials of third-party suppliers into the target organization, which is very difficult to detect.

Citing the example of a multi-stage man-in-the-middle attack (AiTM) against banks and financial services organizations, Singh said, “Attacks start with a trusted vendor that has been compromised, and then the threat actor infiltrates through AiTM, leading to multiple attacks. It conducts business email compromise (BEC) attacks across organizations.” ”

“This is an attack vector for trust abuse between suppliers, vendors and partners,” he added.

During Infosecurity Europe 2023, Bitdefender released a new report analyzing custom malware called RDStealer. The malware makes use of his DLL sideloading technique, which Richard De La Torre, technical and marketing manager for Bitdefender, said the technique “provides ways for attackers to exploit vulnerabilities in various operating systems. is increasing,” he said.

In the case of the RDStealer malware, De La Torre pointed out that it is aimed at stealing passwords and intercepting tokens. outlined.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *