Threat actors are increasingly 'living off the land,' using publicly available management and administration tools to conceal malicious activity.
July 18, 2019
Cybercriminals have long used legitimate management and administration tools to break into enterprise networks, move laterally within them, and maintain persistence.
Lately, though, use of these so-called living-off-the-land tactics has increased substantially.
Positive Technologies recently analyzed the tools that 29 advanced persistent threat groups are currently using in their campaigns worldwide. Its study shows that more than half of them leverage legitimate, publicly available penetration testing and systems administration tools to develop their attacks after gaining an initial foothold on a network.
The reason? Such tools allow attackers to hide their activities in a sea of legitimate traffic. "Threat actors increasingly leverage dual-use tools or tools that are already preinstalled on targeted systems to carry out cyberattacks," said Fortinet in a recent report.
This makes it harder for defenders to spot malicious activity and makes attack attribution much more difficult. "Unfortunately, adversaries can use a wide range of legitimate tools to accomplish their goals and hide in plain sight," Fortinet said.
Here, according to security experts, are eight of the mostly commonly abused legitimate utilities and tools.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024