Kaspersky: From investigating a billion-dollar digital heist and analyzing a cyber espionage group that exploited satellites to hide its tracks, to investigating sophisticated malware that was capable of disrupting a region's oil industry and much more – this is the daily routine for over 40 experts who make up Kaspersky Lab's Global Research and Analysts Team (GReAT).
To highlight the background and diversity of these modern-day “Sherlock Holmeses,” to demonstrate how the brightest minds solve the most difficult digital puzzles, and to encourage others to become fellow travelers on their journeys, Kaspersky Lab launched the Great in Person.
The demand for cybersecurity professionals is growing at a faster rate than the number of people with the right skills, experience and passion. Five years from now, a shortage of 1.8 million cybersecurity professionals is expected, partly driven by a failure to recruit millennials into the IT sector. Kaspersky Lab’s new project aims to help address this obstacle: by spotlighting the people who make up the GReaT team and some of their greatest revelations, it hopes to challenge outdated perceptions of the careers and lives of people working in IT security.
The Global Research and Analysis Team is one of the company’s most important assets, comprising leading security researchers who constantly analyze new and advanced digital threats and develop protection solutions for all Kaspersky Lab customers and partners. Founded in 2008, the team now consists of 42 experts working worldwide – Europe, Russia, America, Asia, the Middle East.
In recent years, the GReAT team’s combination of expertise and passion has led to the discovery of some of the most significant targeted attacks, including: Miniduke, Flame, Equation, Red October, Duqu 2.0, CozyDuke, ProjectSauron and Regin. Implementing these types of attacks costs millions of dollars and requires months of development. Governments, the military, scientific, commercial and industrial organizations are all at risk. They are targeted because of who they are, where they are, what they do or who they do it with.
“The global cyber threat landscape is complex and includes not only cybercriminals seeking financial gain, but also nation-states and hactivists. At first, campaigns that seemed to be isolated incidents – for example the bank robbery in Bangladesh – were just the icing on the cake. At any given moment, hundreds, if not thousands, of unknown attacks are taking place. Predators never sleep – and neither do threat hunters,” explains Costin Raiu, Director of GReAT, explaining his team’s “hunger” for new discoveries.
GReAT experts are currently monitoring over a hundred threat actors, as well as sophisticated malicious actions targeting commercial and government organizations in more than 80 countries. After conducting the research, the company's experts created reports that help organizations hunt for malware by providing them with forensic evidence.
Several of the investigations undertaken by Kaspersky Lab turned into joint operations between GReAT and global organizations such as INTERPOL and Europol, national and regional police forces such as the City of London Police and the National High Tech Crime Unit (NHTCU) of the Dutch National Police Service, and several global teams such as Computer Emergency Response Teams (CERTs). During the investigations, the company’s researchers provided their technical expertise in issues related to malware analysis, support in managing and auditing infrastructure and exploitation methods.
"I may be a CEO, but I'm still a security researcher at heart. I'm still driven by the need to get there first, before anyone else. My personal area of interest includes APT attacks, exploits, sophisticated threats, and pretty much anything that's popular at any given time," added Costin Raiu.
The GReAT in Person website is an introduction to, and a gateway to, the company's Threat Intelligence services, designed to meet the most frequent requirements of large enterprises, government organizations, and law enforcement agencies dealing with digital crime.
It’s now clear that organizations need much more than just endpoint protection to stay safe in the increasingly complex and ever-evolving digital threat landscape. That’s why Kaspersky Lab has introduced an APT Intelligence Reporting (PDF), which offers tailored reports on specific aspects of the threat landscape, as well as immediate, actionable reports on the latest and most advanced threats. These arm organizations with an understanding of the threat landscape and reveal the actions they need to take.
GReAT also supports a Digital Security Training (PDF) which includes a workforce awareness program, as well as training in Digital Security Fundamentals, Digital Forensics, and Malware Analysis/Reverse Engineering.
