Kaspersky Lab 's Global Research and Analysis Team has uncovered some of/and the largest APT (Advanced Persistent Threat) campaigns , including RedOctober , Flame , NetTraveler , Miniduke , EpicTurla , Careto Mask others.
By closely monitoring over 60 threat actors responsible for cyberattacks globally, the company’s team of experts has compiled a list of the top emerging trends in the APT attack landscape. These include:
Fragmentation of larger APT groups: An increasing number of smaller threat actors is likely to lead to more attacks targeting businesses. In addition, larger organizations are expected to face more attacks from a wider range of sources.
The spread of APT attacks in the cybercriminal world: The days when cybercriminal gangs focused solely on stealing money from end users are over. Criminals are now directly targeting banks, because that is where the money is coming from. For this reason, they are using APT techniques to carry out sophisticated attacks.
Targeting executives through hotel networks: Hotels are the ideal place to target high-ranking executives. The group behind Darkhotel is one of the actors behind APT attacks that has been known to target specific guests during their stay in hotels.
Enhanced evasion techniques: More and more APT groups will be concerned about their identities being exposed, which is why they will take more advanced measures to protect their identities.
New data exfiltration methods: In 2015, more groups are expected to use cloud services, making data exfiltration (unauthorized transfer of data from a computer) more stealthy and harder to detect.
The use of “false flag”: APT groups are expected to exploit the authorities' intention to “reveal the identities and expose” those suspected of attacks, using “false flag” methods, through which it will appear that the attack was carried out by another person or entity.
“If in 2014 we can say that the attacks were ‘advanced’, then the evolution in 2015 can be said to be ‘unimaginable’. We believe that APT groups will evolve and become more ‘silent’ and insidious, in order to avoid potential exposure. This year, we have already discovered APT actors using various zero-day software. We have also observed new persistent and ‘silent’ techniques. We have used these findings to develop and implement several new defense mechanisms for users of our products,” commented Costin Raiu, Director of the Global Research and Development Team at Kaspersky Lab.
More information about new trends in APT threats is available on the Securelist blog.
Also, on YouTube you can watch a video by Kaspesky Lab regarding the above issues.
For more information on key events that shaped the threat landscape in 2014, please visit Securelist.com.
Additionally, Kaspersky Lab is today launching the interactive “Targeted Cyber attack Logbook”, an online chronicle of all complex digital campaigns or APT threats that have been investigated by the company’s Global Research and Analysis Team. More details are available at apt.securelist.com.
