HomeSecurityRocke Group hackers target cloud security products

Rocke Group hackers target cloud security products

A big topic of discussion in the cybersecurity world is security in the cloud. The Rocke Group has created automated malware to uninstall cloud security products, according to an analysis by Palo Alto Networks researchers. 42 The malware samples are designed to gain admin access to a cloud distribution and then uninstall the cyberdefense software, just as the admin would be able to do.

Rock

 

Rocke Group is believed to be based in China, although this has not yet been proven. The biggest concern is that this sets a new direction for further malware development. Defending the cloud against this type of attack is difficult. It is not reasonable or reliable to expect a cloud incident to “heal” itself if a hacker manages to gain this kind of access. Of course, the incident gives us a bit of déjà vu. About five to ten years ago, there was malware that was able to disable anti-virus software and your desktop security.

The Rocke Group threat to your cloud is a bigger risk on a much larger scale. The cure? A consistent approach to securing all IaaS and SaaS clouds can be provided by cloud access security brokers (CASBs). CASBs can provide end-to-end encryption to secure your data in the cloud during all phases of use. This includes in the database, in transit (APIs, middleware, etc.), and in use. If you secure your cloud this way, Rocke Group will likely walk away from your cloud empty-handed. CipherCloud CASBs can provide the data protection, threat protection, and flexible architecture you need to meet (and defeat) new attack vectors like those employed by Rocke Group.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS