Kaspersky Lab 's discovery in 2016 of an APT ( Advanced Persistent Threat) threat with the ability to create new tools for each victim has essentially "killed" "Breach Indicators" as a reliable way to detect "infection", according to the company's Threat Forecasts for 2017.
The Predictions are prepared annually by the company’s dedicated Global Research and Analysis Team (GReAT) and draw on its extensive experience and expertise. The 2017 list includes the impact of consumable and on-demand tools, the increasing use of attacker identity misdirection, the fragile nature of a world connected to the Internet without restrictions, and the use of digital attacks as a weapon in information warfare.
The fall of IoCs
Indicators of Compromise (IoCs) have long been a great way to share characteristics of known malware, allowing defenders to identify an active infection. The discovery of the ProjectSauron APT by the GReAT team brought about change. The team’s analysis revealed a custom malware platform where each characteristic changed for each victim, rendering IoCs unreliable for detecting any other victim unless accompanied by some other means, such as strong Yara rules.
The increase in ephemeral "infections"
In 2017, Kaspersky Lab expects the emergence of memory-resident malware that has no interest in surviving beyond the first reboot that will clear the “infection” from the machine’s memory. Such malware, intended for general surveillance and data collection, is likely to be deployed in highly sensitive environments by silent actors trying to avoid attracting attention or detection.
“These are dramatic developments, but defenders will not be left helpless. We believe the time has come to push for broader adoption of Yara’s good practices. These will allow researchers to search across all aspects of an enterprise, inspect and identify elements in unused binaries, and scan memory for fragments of known attacks. Ephemeral infections highlight the need for preparation and advanced heuristics in advanced anti-malware solutions,” said Andrés Guerrero-Saade, Senior Security Expert, Global Research and Analysis Group.
Other important threat predictions for 2017
- Reporting will address issues with false flags: As cyberattacks play a more prominent role in international relations, reporting will become a central issue in determining policy direction and action – for example, retaliation. The pursuit of reporting may result in the risk of more criminals releasing proprietary or infrastructure tools into the open market, or opting for commercial or open-source malware, not to mention the widespread use of misdirection (commonly known as false flags) to muddy the waters of reporting.
- The Rise of Information Warfare: In 2016, the world began to take the release of hacked information for offensive purposes seriously. Such attacks are likely to increase in 2017, and there is a risk that attackers will try to exploit people’s willingness to accept such data as fact, through manipulation or selective disclosure of information.
- In conjunction with this, Kaspersky Lab expects an increase in Vigilante Hackers – hacking and releasing data, claiming to be for the greater good.
- Growing risk of digital sabotage: As critical infrastructure and production systems remain connected to the Internet, often with little or no protection – the temptation to damage or disrupt them can seem great to digital attackers, especially those with advanced skills, and especially in times of heightened geopolitical tension.
- Mobile Spying: Kaspersky Lab expects more spying efforts to target mobile devices, taking advantage of the fact that the security industry may have difficulty gaining full access to mobile operating systems for forensic analysis.
- The commercialization of financial attacks: Kaspersky Lab anticipates the “commercialization” of attacks along similar lines to the SWIFT heists in 2016 – with specialized resources being offered for sale on underground forums or through service-providing schemes.
- The risk facing payment systems: As payment systems become more widespread and popular, Kaspersky Lab expects a corresponding increase in interest from criminals.
- The Collapse of “Trust” in Ransomware: Kaspersky Lab also expects the continued rise of ransomware, but with the unexpected relationship of trust between victim and perpetrator – based on the assumption that payment will result in the return of data – collapsing as lower-level criminals decide to enter the space. This could be the tipping point in the number of people willing to pay.
- Device integrity in a crowded Internet: as IoT device manufacturers continue to produce insecure devices that create widespread problems, there is a risk that vigilante hackers may take matters into their own hands and disable as many devices as possible.
- The Attractive Side of Digital Advertising for Criminals: Over the next year, we will see the kind of tracking and targeting tools increasingly used in advertising being used to track so-called activists and dissidents. At the same time, ad networks – which provide excellent profile targeting through a combination of IPs, browser fingerprinting, browsing interest, and login selectivity – will be used by advanced digital espionage agents who want to hit targets while protecting their latest tools.
The full text of theKaspersky Lab Threat Predictions 2017is available on the dedicated website Securelist.com.
To see what Kaspersky Lab experts predicted for 2016, you can read here.
More information: YARA is a tool for identifying malicious files and suspicious activity patterns on systems or networks that have similarities. YARA – essentially search – help analysts find, group, and categorize related malware samples and make connections between them to build malware families and identify attack groups that might otherwise go undetected.
Download PDF version
Download EPUB
Download Full Report PDF
Download Full Report EPUB
