Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


06:40 PM
Connect Directly

Ransomware Surge & Living-Off-the-Land Tactics Remain Big Threats

Group-IB's and Rapid7's separate analysis of attack activity in recent months shows threat actors are making life harder for enterprise organizations in a variety of ways.

Data from two new vendor reports summarizing threat activity over the past few months shows that ransomware and living-off-the-land attacks continue to top the list of threats facing enterprise organizations.

One of the reports, from Singapore-based Group-IB, is based on an analysis of data gathered by the vendor's computer emergency response team.

It shows that more than half (54%) of all malicious emails in the first six months of 2019 contained ransomware — a sharp increase from just 14% during the same period last year. Ransomware activity topped all other threats between January and the end of June this year.

Meanwhile, a report from Rapid7, based on an analysis of threat activity in the third quarter of 2019, shows attackers are continuing to heavily use legitimate tools and services — PowerShell — to build on and continue malicious campaigns. The security vendor's analysis shows that phishing continues to be the top reason for organizations getting breached, but most breach detections don't happen until the malware execution stage. Here are five takeaways from the vendor reports.

Ransomware Remerges as a Major Threat
Ransomware remerged as a major threat after seemingly being on the way out most of last year. In the first half of 2018, just 14% of the attacks that Group-IB tracked were ransomware-related, a sharp drop-off from the 40% recorded in 2017. Numerous vendor reports over the past year also have reported a steady decline in overall ransomware volumes and an increasing attacker focus on low-volume targeted attacks on enterprises. Group-IB's data for the first half of 2019 suggests that overall ransomware volumes have begun rebounding once again.

Alexander Kalinin, head of Group-IB's CERT, says a majority of the ransomware attacks observed in the first half of this year were of the mass-volume spray-and-pray variety that many had assumed was dying out.

However, many of these attacks showed certain similarities with targeted attacks in terms of their preparation, he notes. "The emails targeted [a] large number of people but within a specific industry," Kalinin says. Emails containing ransomware were often drafted to be relevant to targets within a specific industry — a feature that is typically associated with targeted attacks, he says.

The most prolific ransomware strain that Group-IB tracked in the first half of 2019 was Troldesh, a malware tool that attackers used not just to encrypt files but also to mine cryptocurrency and generate phony traffic for ad-fraud campaigns, according to Group-IB.

Attackers Are Increasingly Using Delayed Action Links for Downloading Malware
To try and evade antimalware systems, cybercriminals are increasingly eschewing malicious attachments for links in emails, which when clicked download malware. Twenty-nine percent of the emails that Group-IB encountered last quarter had links to malware rather than attachments. That was double the number compared with 2018.

The links are often inactive when a victim receives an email, Kalinin says. Clicking on the links would not result in any malware being downloaded. If anything does get downloaded, it is usually a benign file. Most anti-malware tools would scan the links in real time, mark them as safe, and send the email to the user's inbox.

The links get "activated" after the basic, initial vetting is over. If security checks are not performed over again, the victim receives an email marked as safe and can get infected, he notes. "Unlike attachments, the content accessible via links can be customized and replaced over time to bypass antivirus systems' checks," Kalinin says.

Once security checks are over, a cybercriminal can replace content accessible via a link with malware. "The content accessible via such links can also be customized, depending on the victim's location, operating system, and other parameters."

PowerShell Continues to Be an Attacker Favorite
Threat actors are increasing their use of legitimate admin, penetration testing, and other tools in attack campaigns. Among the most popular living-off-the-land tools that Rapid7 observed in use last quarter were cmd dot exe, ADExplorer dot exe, procdump64 dot exe, rundll32 dot exe, and mimikatz dot exe.

Few of the legitimate tools, though, were as popular as PowerShell. Rapid7 found that attackers are increasingly exploiting PowerShell to stay hidden when executing different attacks. Among the several tactics that attackers are using to exploit PowerShell include using old, less-restrictive versions of PowerShell and by bypassing policies set to restrict PowerShell using the ExecutionPolicy bypass switch, according to the vendor.

"PowerShell is installed on all systems and is extremely powerful," says Wade Woolwine, principal threat intelligence researcher at Rapid7. "Uninstalling old versions and configuring PowerShell to run in Constrained Language Mode are two mitigations," he says. Good endpoint detection and response capabilities are a must as well, he notes.

More Than 80% of Malicious File Were Disguised as .ZIP and .RAR files
Attackers sharply ramped up their use of .zip and .rar files to distribute malware in the first half of 2019. More than eight-in-10 malicious objects that Group-IB detected in the first six months of 2019 were delivered in password-protected archived files. The most common among them were .zip (32%) and .rar (25%).

The benefit for attackers is that such files make it hard for a majority of corporate security systems to automatically identify malware contained in them, Kalinin says. In many instances, the cybercriminals included the passwords for accessing the contents in the subject of the email, in the name of the archive, or in their subsequent correspondence with the victim. "Once unzipped and opened, it would download and install malware on a victim’s computer," Kalinin says.

Healthcare and Entertainment Industries Were Big Malware Targets
A majority of the breaches that Rapid7 investigated last quarter stemmed from phishing. When the initial compromise was not detected and contained, criminals executed malware — including ransomware — on target systems. Organizations in the healthcare and entertainment sectors were especially heavily targeted in such malware attacks.

Seventy-five percent of incidents that Rapid7 investigated at entertainment organizations and 62.5% of those at healthcare organizations involved some kind of malware. Both healthcare and entertainment organizations are popular targets because they have a reputation for paying ransoms, says Woolwine. "Attackers will always go after the easy money."

Others that were relatively heavily targeted in malware attacks included organizations in the manufacturing, retail, and real estate vertical markets.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "How Medical Device Vendors Hold Healthcare Security for Ransom."

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Moderator
11/20/2019 | 1:28:27 PM
Great Article! Interesting antivirus evasion tactics
Not surprisingly, attackers look at the security processes utilized by antivirus engines and, by understanding how they operate, craft attacks that evade detection and eventually achieve infection.

The use of direct links in emails so that initial link inspection creates a SAFE assessment, and then changing the linked file's content to malware later, means that antivirus and antimalware vendors need to implement a mechanism to spot linked content that was changed since it was last scanned. And then needs to rescan the linked file before allowing it to be opened by the user.

Obviously attackers will examine how linked file modification detection is performed and try to evade whatever algorithm is employed, so linked file change detection needs to be very robust. 

The direct linked file attack could only work if attackers have read/write/modify file access permissions on the server that the direct link points to. This implies that there are more whitelisted public facing file servers that have been stealthily compromised in ways that antivirus/antimalware companies have not been detecting with their whitelisting scanners. And this failure of accurate whitelisting renders root of trust in antivirus scanners very problematic.

Uninstalling old, less-restrictive versions of PowerShell and configuring PowerShell to run in Constrained Mode seem like very prudent security preventative measures to take in every security domain. More details on how to do these two security steps, perhaps in another article, would go a long way to helping security professionals to take concrete actions to eliminate these actively exploited vulnerabilities.

I love your security articles, especially when they include actionable references to concrete security steps that reduce attack surfaces.
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-05-06
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the...
PUBLISHED: 2021-05-06
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gai...
PUBLISHED: 2021-05-06
emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
PUBLISHED: 2021-05-06
** UNSUPPORTED WHEN ASSIGNED ** The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode wh...
PUBLISHED: 2021-05-06
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.