Attacks/Breaches
1/21/2014
08:49 PM
50%
50%

Politically Motivated Cyberattackers Adopting New Tactics, Report Says

Organized cybergroups from China, Syria, and Russia are finding new ways to breach enterprises, CrowdStrike reports

Organized and politically motivated cyberattackers are changing their methods, finding new, less direct methods of launching targeted attacks on enterprises and government agencies, according to a report issued today.

The report, issued today by threat intelligence company CrowdStrike, offers a detailed look at the motivations, methods, and practices of five organized cyberattack groups -- including the Syrian Electronic Army as well as groups in China, Iran, and Russia -- during 2013.

The methods of these politically motivated groups are changing, according to the report. While targeted attacks historically have begun with phishing attacks directly on members of the targeted organization, more sophisticated groups are now using more indirect methods -- attacking third parties and collecting information from targeted users by infecting their favorite websites.

Using specific examples from recent attacks, the CrowdStrike report illustrates recent shifts in attacker strategy, such as the trend toward making targeted attacks by infiltrating a trusted third party. The report outlines details of exploits by the SEA -- a group that CrowdStrike calls Deadeye Jackal -- in which critical user data was extracted through the breach of third-party communications platforms and applications, such as Truecaller, TangoME, and Viber Media.

"Expect to see adversaries targeting third-party vendors [in 2014] in an attempt to compromise the ultimate target," the report states. "Third-party vendors often have less-robust security than their larger customers, and their networks offer an avenue through which those customers can be compromised."

Similarly, many organized cybergroups have changed their methods for tricking users into downloading malware, CrowdStrike says. While many attackers traditionally have sought to infect the user through by sending a fake email -- sometimes called a phishing attack -- some organized groups are now using strategic Web compromises (SWC), the company reports.

SWCs -- sometimes called "watering holes" -- are legitimate websites that have been infected by an attacker in order to steal the personal data of those who frequent the site. For example, an attacker looking to collect data on political officials might infect the site of a conference or event that is attended by those officials.

"Where these groups used a lot of spearphishing in the past, we have seen many more SWCs in the last year," says Dmitri Alperovitch, co-founder and CTO of CrowdStrike. SWCs are harder to detect and remediate than phishing attacks, and it's harder to identify who launched them, he notes.

SWCs played key roles in recent attacks by organized Chinese hacker groups on the U.S. Department of Labor and the Council on Foreign Relations, the CrowdStrike report says.

Organized attackers often find that an indirect route to a target is easier than a direct attack, according to CrowdStrike. A China-based group that CrowdStrike has dubbed Emissary Panda is focusing much of its attention on compromising the systems of foreign embassies, rather than going after government systems in their home country. Similarly, a China-based group that CrowdStrike calls Numbered Panda has been conducting spearphishing attacks under the guise of the G20 Summit, an event that attracts top government officials from most of the world's top industrialized nations.

"Targeted intrusion operators like to leverage major events in their operations," the report states. In 2014, organized groups will likely build phishing attacks and SWCs around events such as the Winter Olympics, the World Cup, the G20 Summit, and upcoming national elections in Egypt, Iraq, Tunisia, and Turkey, CrowdStrike warns.

One group that targeted national elections in 2013 was an organized cel in Iran that CrowdStrike calls Magic Kitten. The group attempted to affect the outcome of Iran's elections through a series of attacks targeting political dissidents and those supporting Iranian political opposition, according to the report. The group’s preferred attack vector is spearphishing, accompanied by malicious Word documents and image files, which enabled the attackers to retrieve information about victims' computers, do keylogging, file execution, voice recording, and file exfiltration.

CrowdStrike, which is currently monitoring more than 50 groups of cyberattackers in countries all over the world, predicts that such politically motivated groups will continue to evolve their tactics to avoid detection and take advantage of vulnerabilities in new technologies, such as the emerging generic top-level domains (gTLDs) that are scheduled to go into operation this year.

"These gTLDs will be used by adversaries to support more effective phishing attacks," the report says. "CrowdStrike also expects new vulnerabilities to be discovered and exploited in network-facing software with regard to handling gTLD hostnames."

"One of the things we tried to do with this report is to look forward at potential future attacks, rather than just looking back at the year," Alperovitch says. "With good threat intelligence, every organization should be able to do predictive analytics based on its history and the history of security events. If you know what your attacker did last year, you can get a sense for what he might do this year."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jries921
50%
50%
jries921,
User Rank: Apprentice
1/23/2014 | 5:22:53 PM
re: Politically Motivated Cyberattackers Adopting New Tactics, Report Says
One question I've had for a while is how many of these "hacktivist" groups based in authoritarian/totalitarian states are actually controlled by the ruling parties or intelligence services of their respective governments. It's not like any of these countries are known for independent political action.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?