Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

1/31/2018
04:20 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Lazarus Group, Fancy Bear Most Active Threat Groups in 2017

Lazarus, believed to operate out of North Korea, and Fancy Bear, believed to operate out of Russia, were most referenced threat actor groups in last year's cyberattacks.

The busiest threat actor groups of 2017 were Sofacy (otherwise known as Fancy Bear or APT28) and the Lazarus Group, security experts report. As these groups ramped up activity, threat actors operating out of China became quiet.

Analysts at AlienVault leveraged data from its Open Threat Exchange (OTX) threat intelligence sharing platform to take a broad look at threat patterns from last year. They found the most frequently referenced threat group in 2017 was Sofacy.

Ten years ago, Sofacy primarily targeted NATO and defense ministries. Over the past three years its operations have expanded to target businesses, individuals, and elections in the United States and France. Leaked information from the US government, and an official report from the German government, indicate the threat group is associated with Russian military intelligence.

The second most active group was Lazarus, which is believed to operate out of North Korea (or Democratic People's Republic of Korea, DPRK).

"In the past, security researchers thought DPRK cyber adversaries were unsophisticated compared to more traditional nation-state adversary groups, like China or Russia," says Dmitri Alperovitch, cofounder and CTO at CrowdStrike.

"However, the North Korea regime has invested significant resources in training and development in recent years and their cyber capabilities have matured significantly as a result." Alperovitch points out that in 2017, cyber operations were linked to DPRK almost monthly. Lazarus was linked to WannaCry and has hacked into banks and cryptocurrency exchanges.

Crowdstrike found Lazarus is comprised of four groups: Silent Chollima, Stardust Chollima, Labyrinth Chollima, and Ricochet Chollima. Most adversaries focus on targeted attacks or cyberespionage; DPRK threat actors aren't as particular. While they primarily focused on South Korean targets in 2017, they have been known to hit organizations in other regions.

What usually motivates these groups? John Bambenek, manager of threat systems at Fidelis Cybersecurity, says financial gain is often a driver. "You're dealing with organized crime, in essence," he explains. "There's a payday at the end of it."

Attackers, specifically those in North Korea, have begun turning to cryptocurrency. More are targeting consumer devices and leveraging their computing power to mine crypto. "For a nation that is highly sanctioned with currency requirements, Bitcoin and its related cousins provided great means to capitalize," Bambenek points out.

The goals of nation-state threat actors will vary from group to group. Those looking for money could target cryptocurrency exchanges while those seeking to disrupt election cycles could target social media to spread disinformation. "It depends on the geopolitical circumstances," he says.

Why Chinese threat groups fell silent

AlienVault's data shows Stone Panda, also known as APT10 or CloudHopper, fell in tenth place for 2017 activity. This is the highest-ranked group operating out of China, and AlienVault threat engineer Chris Doman notes its ranking "would have been very different three years ago."

The last year saw a significant decrease in the number of targeted attacks from China-based threat groups against Western businesses. While this followed political pressure and agreements to stop activity, it's also possible their attacks have become tougher to detect. CloudHopper is known to hit targets by compromising major IT service providers, a method that's difficult to detect for vendors and government agencies.

"We may continue to see reported activity from groups in China drop further," Doman writes, adding that UPS (also known as Boyusec or APT3) switched from Western to domestic targets.

What should you worry about?

Alperovitch warns businesses to worry about the danger North Korean threat groups pose to their brands and networks. "These adversaries have demonstrated a degree of unpredictability about what they may try to do next," he says. "It is important for organizations to continually hunt their systems for potential intrusions and swiftly remediate before any damage is done."

Bambenek acknowledges the potential for ICS-based attacks, which he says will be a growing area of focus for threat groups. "Someone will take a utility hostage for ransom," he says. "With Triton getting published to GitHub, we've drastically lowered the bar for ICS attacks."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29623
PUBLISHED: 2021-05-13
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying th...
CVE-2021-32917
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
CVE-2021-32918
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
CVE-2021-32919
PUBLISHED: 2021-05-13
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another serv...
CVE-2021-32920
PUBLISHED: 2021-05-13
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.