04:55 PM
Connect Directly

Rise of Nation State Threats: How Can Businesses Respond?

Cybersecurity experts discuss nation-state threats of greatest concerns, different types of attacks, and how organization can prepare.

Foreign cybercriminals pose a growing threat to enterprise targets, making risk management critical for commercial and government organizations facing increasingly dangerous attacks, according to the findings of a new report detailing the changes in threat actors and their tactics, activities, and motivations over the past six months.

The Flashpoint mid-year update to its Business Risk Intelligence Decision Report aims to inform business decision-makers about different threats so they can prepare to respond.

Major cyber players listed in the report include Russia, China, Iran, North Korea, and Five Eyes (US, UK, Canada, Australia, New Zealand), though the report states Five Eyes does not use its cyber powers for destructive attacks against allied systems. Researchers also listed cybercriminals, disruptive and attention-seeking actors, hacktivists, and jihadi actors.

"Nation states are always going to be at the top of [cyber] capabilities," says Jon Condra, director of East Asian Research and Analysis at risk and threat intelligence firm Flashpoint. "They have the time, resources, everything to carry out these types of attacks."

Condra, who authored the report, specifies Russia and China as two entities "moving rapidly" to solidify their cyber sovereignty. Both are abolishing anonymity and gaining stronger control over content presented to citizens and traffic exiting the country, which he says has big implications for companies doing business in each country.

Iran and North Korea are also on experts' radar, albeit at a lower level than Russia and China. Iran, which doesn't currently have a vibrant cybercrime community, is on experts' radar because of its focus on critical infrastructure. North Korea is "incredibly active", says Condra, and the report cites its ability to hit targets in the US and South Korea.

Tom Kellermann, CEO of Strategic Cyber Ventures, acknowledges the growing trend of foreign entites using cybercriminal groups to launch attacks. This started in eastern Europe, he explains, and has been embraced by the Russians and the Chinese.

"You see other nation states utilizing the same model to increase their own capabilities," he says.

Nation-state actors have also begun to work together, Kellermann notes. The "tech transfer" between Russia and Iran, and between China and North Korea, is "enabling 'B' teams to become 'A' teams so they can collaborate internationally."

Researchers discovered that activity among disruptive actors has quieted in 2017 as law enforcement cracks down on key groups and historical targets improve their security practices. Cybercriminals continued to target organizations this year as a means of collecting personal data and money from large businesses, particularly in healthcare.


Motivations of nation-state actors vary across the players in the space. Financial gain isn't a major part of nation-state attacks for most players, says Condra, but North Korea is the exception.

Dmitri Alperovitch, cofounder and CTO at CrowdStrike, says while much of North Korea's cybercrime is directed towards South Korea, it's "notorious" for using cybercrime to monetize and fund their regime. The country has been suspected of targeting the banking sector as a means to steal from financial institutions.

Condra cites Russia's attempts at intervening in elections by targeting political organizations. This is driven less by financial gain and more by the goal of stealing intellectual property, which can be used to expose sensitive information or embarrass candidates. Examples of this have been seen in the US, France, and Germany, he explains. 

Alperovitch also acknowledges a focus on data theft among nation-state adversaries. Some actors may "moonlight" and conduct military espionage by day, then use the same capabilities to steal for their own benefit after hours.

Cybercrime isn't only about stealing data for geopolitics or espionage, says Kellermann. Cybercriminals also aim to change and destroy data, which can have broad implications for businesses. He likens this to a burglar burning down a house after taking what they want.

After hackers pillage a brand's intellectual property, they can use the brand and its customers' trust to turn consumers away through business email compromise, malware-laced emails, and other forms of cybercrime. Kellermann says this is increasing with attacks like WannaCry, which created a polymorphic campaign and hit several critical infrastructure systems.


"One of the biggest shifts we've been seeing, increasing steadily over the last few years, is the move to fileless attacks," says Alperovitch. "They're moving away from leveraging malware to using these types of methods."

Threat actors can bypass tools that rely on machine learning to detect signatures, instead using components already in place. Alperovitch says among Russian threat actors, he has noticed the trend of leveraging online cloud services to blend in with an organization's network traffic.

Once adversaries have a foothold in the business, he explains, some exfiltrate data using Microsoft OneDrive. Admins monitoring the network see encrypted Microsoft traffic but don't notice anything is amiss.

While more advanced strategies are on the rise, threat actors continue to rely on traditional and effective forms of breaking in. Spearphishing continues to work, says Alperovitch, and many cybercriminals don't see the need to deviate. Web exploitation and Web compromise are also popular hacking methods.

What can be done?

"There are three things you need to do that are really key to responding to any type of intrusion," says Alperovitch.

Businesses should assume they have been compromised and get a compromise assessment, invest in endpoint detection and response (EDR) for greater visibility, and use that insight to put themselves in the mindset of an attacker, he continues. Those who have a strong security program and leverage EDR are in a better place than those who ignore the problem.

High-profile attacks are motivating organizations to take these threats seriously, says Alperovitch, and business execs are starting to ask CISOs the tough questions: "Have we already been breached?" "How do you know if we have been breached?" "Are you ready?"

Kellermann advises using intrusion suppression to hunt for adversaries already in the network. This method requires businesses to alter their architecture for the purpose of detecting, deceiving, diverting, and containing adversaries who have broken in.

"We can't stop them at the wall anymore, not when they're using NSA capabilities put on dark web forums," he cautions.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Related Content:


Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
SEC: Companies Must Disclose More Info on Cybersecurity Attacks & Risks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  2/22/2018
Facebook Aims to Make Security More Social
Kelly Sheridan, Associate Editor, Dark Reading,  2/20/2018
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.