Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/22/2018
02:44 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Cybercriminals Battle Against Banks' Incident Response

'Filess' attacks account for more than half of successful breaches of bank networks, new data shows.

Financial institutions traditionally have established some of the most secure perimeters and defenses against cybercriminals and nation-state actors, but new studies show how they often struggle to detect or quell ongoing attacks that have infiltrated their internal networks.

CISOs from major financial firms surveyed and interviewed recently by Carbon Black say they're seeing attackers moving across their networks under the cover of legitimate applications and tools such as Windows PowerShell (89%), Windows Management Interface (59%), and SSH (28%). Those camouflaged, memory-based attacks – aka file less attacks – were used in more than half of successful breaches of the bank networks, according to Carbon Black.

In addition to the usual Windows utility suspects, Google Drive, unsigned digital certificates, and legit processes hiding malicious code (aka process hollowing), each were found in about 10% of cases at banks.

Leigh-Anne Galloway, cybersecurity resilience lead at Positive Technologies, says these methods work for the bad guys because banks often don't pay close attention to the security of their internal networks. Her firm, which provides penetration testing to banks in Europe and elsewhere, uses legitimate tools in those engagements. "When doing pen tests, we try to act as close as possible to the actions of the attacker - including 'living off the land' - so that the organization can understand how well its internal monitoring tools for attacks like SIEM or SOC work," she says.

The pen testers run Mimikatz PowerShell version as well as the "procdump" utility, where they copy operating system memory. "You can extract passwords from this dump on your laptop, which naturally will go unnoticed by the protection systems. Such methods show high efficiency," she days, with the pen testers able to steal passwords from the operating system memory using Mimikatz in 100% of banks they tested.

Persistent attackers aren't backing down when banks detect them and launch their incident response processes, either. One in four bank CISOs in the Carbon Black study say their institution faced attackers fighting back when they got spotted, trying to deter defenses and the investigation into the attack.

"They are leaving wipers or destructive malware to inhibit [IR], deleting logs, and inhibiting the capacity of forensics tools," for example, says Tom Kellermann, chief cybersecurity officer at Carbon Black. "Sometimes they are using DDoS to create smokescreens during events."

These counter-IR activities are forcing banks to be be more proactive and aggressive as well, he says. "They need to have threat hunting teams. You can't just rely on telemetry and alerts."

While banks are often relying on their IR playbooks, attackers have the freedom to freelance and counter IR activities. They're changing their malware code on the fly when it gets detected, deleting activity logs to hide their tracks, and even targeting bank security analysts and engineers to help their cause. Carbon Black found in its study that one in ten bank victims say they spotted secondary command-and-control infrastructure set up in their networks – which can make response even more difficult.

Positive Technologies' Galloway says attackers also encrypt their data transmissions over the victim's network, falsify time-stamps in files, and employ file compressors and anti-debugging methods that can thwart discovery of their activity and tools.

While 90% of banks in the Carbon Black survey said they had experienced a ransomware attack threat, Kellermann says another data point appears more ominous: one in ten had spotted destructive attacks that were not ransomware-related.  "I think that's going to grow," he says, as attack groups use destructive malware such as data-wipers to "burn the house down" on their way out for cover or to send a message.

"The real dangers to financial institutions isn't just dealing with identity fraud and wire fraud," Kellermann says.

Pen testers at Positive Technologies, meantime, found gaping holes in their bank client networks: 75% of banks had employees who opened links in phishing attack tests, and 25% of them provided their credentials in a phony authentication form in the test. Positive Technologies' analysts were able to access banks' financial applications in 58% of their engagements, and compromise ATM management workstations in 25% of the cases, according to a report published this week.

And banks weren't savvy at catching the pen-tests, either. "The actions of pen testers were noticed by security employees in less than 10% of banks that we tested," Galloway says.

Related Content:

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RobiP
50%
50%
RobiP,
User Rank: Strategist
6/14/2018 | 5:50:11 PM
Better Network Forensics
This post validates the re-energed focus on better network forensics.  Attackers will find the unprotected hosts and hide, but it's harder to hide movements on the network.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
'Unkillable' Android Malware App Continues to Infect Devices Worldwide
Jai Vijayan, Contributing Writer,  4/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-1633
PUBLISHED: 2020-04-09
Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, le...
CVE-2020-8834
PUBLISHED: 2020-04-09
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc__tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to...
CVE-2020-11668
PUBLISHED: 2020-04-09
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
CVE-2020-8961
PUBLISHED: 2020-04-09
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can construct an event that will modify a file at a specific loc...
CVE-2020-7922
PUBLISHED: 2020-04-09
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are u...