February 19, 2014 By John D. Johnson 2 min read

All Hands to Battle Stations! The Enterprise is Under Attack!

No, this is not the start of a sci-fi story, it is the reality that enterprise IT security defenders face in 2014. Attackers are waging an asymmetric battle for our networks, assets and data. Their attacks are increasing in sophistication, velocity and volume. Meanwhile, IT systems are becoming more complex and enterprise resources extend beyond the traditional perimeter boundaries, and enterprise data is used in social media, cloud services and stored in the cloud and on mobile devices. Suppliers and contractors remotely access enterprise networks and resources by VPN and virtual desktops. We truly have our work cut out for us.

Advanced threats have been shown to pose a significant threat, if they can gain a foothold in the enterprise. Recent attacks against retail giants like Target and Neiman Marcus demonstrate that even companies with leading security controls, which are certified as PCI compliant are at risk. Remote access, credentials abuse and malware are on the increase, and it motivates improved diligence by security defenders. The traditional approach has been to look for signatures of malware or an attack, so it can be blocked. Anti-malware, intrusion detection and vulnerability management focus on ‘known malicious behavior’. The bulk of attacks, today, are based on 0-day exploits and undiscovered vulnerabilities. In many cases, the attack vector leverages software that is not quickly patched, or that cannot be patched for fear of breaking enterprise applications. Examples are PDF files, Java and Office file formats.

Like a game of chess, there are many moves possible, but there are certain stages in the threat lifecycle where the attacker has fewer options. These are strategic chokepoints, where malicious code seeks to exploit a system and where it attempts to establish a connection to a command and control channel. Trusteer Apex applies this knowledge to break the exploit chain and prevent compromise on endpoints.

Defending like an attacker

In the recent Target breach and in other high-profile attacks, both remote access connections and privileged credentials have been leveraged and abused. Trusteer Apex provides protection of corporate credentials, against reuse on other websites and from keystroke logging by malware. When suppliers and contractors connect to the enterprise remotely, their computers are in an unknown state. They may not be patched and secure, and there is a good likelihood that some of these systems are already compromised. The application of Trusteer Apex for remote access by non-corporate assets adds an important layer of security to address this gap. A key additional factor in the selection of Trusteer Apex was the ease of deployment and management, especially when dealing with non-corporate assets. Because of the adoption of Trusteer Apex by large financial institutions with up to millions of customers, we recognized that this solution would require a low level of support.

Defenders need to think like attackers. As corporate strategy moves to adopt consumer technologies to grow and compete globally, and as the threat landscape becomes more aggressive, it is more important than ever to develop a risk-based, layered security strategy to defend against sophisticated adversaries. Trusteer Apex addresses some key gaps that are missing in traditional endpoint and network security controls. It is a key piece to an enterprise IT security strategy for advanced threat protection.

More from Malware

Hive0051’s large scale malicious operations enabled by synchronized multi-channel DNS fluxing

12 min read - For the last year and a half, IBM X-Force has actively monitored the evolution of Hive0051’s malware capabilities. This Russian threat actor has accelerated its development efforts to support expanding operations since the onset of the Ukraine conflict. Recent analysis identified three key changes to capabilities: an improved multi-channel approach to DNS fluxing, obfuscated multi-stage scripts, and the use of fileless PowerShell variants of the Gamma malware. As of October 2023, IBM X-Force has also observed a significant increase in…

New Hive0117 phishing campaign imitates conscription summons to deliver DarkWatchman malware

8 min read - IBM X-Force uncovered a new phishing campaign likely conducted by Hive0117 delivering the fileless malware DarkWatchman, directed at individuals associated with major energy, finance, transport, and software security industries based in Russia, Kazakhstan, Latvia, and Estonia. DarkWatchman malware is capable of keylogging, collecting system information, and deploying secondary payloads. Imitating official correspondence from the Russian government in phishing emails aligns with previous Hive0117 campaigns delivering DarkWatchman malware, and shows a possible significant effort to induce a sense of urgency as…

ITG10 likely targeting South Korean entities of interest to the Democratic People’s Republic of Korea (DPRK)

7 min read - In late April 2023, IBM Security X-Force uncovered documents that are most likely part of a phishing campaign mimicking credible senders, orchestrated by a group X-Force refers to as ITG10, and aimed at delivering RokRAT malware, similar to what has been observed by others. ITG10's tactics, techniques and procedures (TTPs) overlap with APT37 and ScarCruft. The initial delivery method is conducted via a LNK file, which drops two Windows shortcut files containing obfuscated PowerShell scripts in charge of downloading a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today