{"id":2439,"date":"2020-04-16T15:53:07","date_gmt":"2020-04-16T11:53:07","guid":{"rendered":"https:\/\/techxmedia.com\/?p=2439"},"modified":"2025-04-18T00:01:33","modified_gmt":"2025-04-17T20:01:33","slug":"cyber-adversaries-adapting-exploit-global-pandemic","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/cyber-adversaries-adapting-exploit-global-pandemic\/","title":{"rendered":"Cyber adversaries adapting to exploit the global pandemic"},"content":{"rendered":"\n<p><a href=\"http:\/\/tracking.epressrelease.me\/tracking\/click?d=lzuWHnCace3bcbisA7lXPeMCW3YSYth1v9RRkcaMg8XnB7nB_CrFAdGdg4hy2eXWOjvaB8ojRcSmqI71PEVdhRpuxU1ppj3k4tr77gI6c26t8-ZG0c0giUsd2rKN9ob0SJBwIabO4WtFXw3KyISSOUjeutG1tVt8qTU6K8X5a9ITrnQy1zavSS2G8qt20miMM_BqgUWO5ZT42Cc4plDrVHdPh_BROwlrmNhGULGAmICE0\">Secureworks\u00ae Counter Threat Unit\u2122<\/a> (CTU)\nresearchers are tracking multiple coronavirus-themed campaigns across customer\ntelemetry and third-party reporting.<\/p>\n\n\n\n<p>There is clear evidence of well-established cybercriminal and government-sponsored threat actors leveraging general interest in <a href=\"https:\/\/techxmedia.com\/tag\/covid_19\/\">COVID-19 <\/a>to entice victims to open malicious links and attachments. CTU\u2122 researchers have observed government-sponsored hackers weaponizing coronavirus-themed Office documents and sophisticated criminal operators targeting critical infrastructure and organizations in areas hit hard by the pandemic.<\/p>\n\n\n\n<p>The fundamental\nbusiness model and revenue generation of these sophisticated criminal groups\ndoes not really change as a result of the global pandemic. But fear,\nuncertainty, and a thirst for information about the current situation increases\nthe number of potential victims and the likelihood of successful attacks.<\/p>\n\n\n\n<p>In a nutshell, contrary to what more sensationalistic voices may be saying, Secureworks has not seen an overall increase in cybercriminal activity as of April 8<sup>th<\/sup>, but it has seen evidence of threat actors using the <a href=\"https:\/\/techxmedia.com\/tag\/covid_19\/\">COVID-19<\/a> pandemic to lure people into clicking links, opening files and exposing themselves to dangerous ransomware.\u00a0<\/p>\n\n\n\n<p>Don Smith,\nSenior Director Cyber Intelligence, Secureworks, says: \u201cAt this time of panic\nand anxiety in many areas of everyday life, it\u2019s important for us to be a\nsensible, honest voice that is sharing what is actually happening, based on\ntelemetry and third-party reporting, rather than sensationalistic conjecture\nand hypothetical worst-case scenario situations. The world is vastly different\nthan a couple of months ago and that has put people on edge.<\/p>\n\n\n\n<p>\u201cNow is not the\ntime for industry experts to add fuel to the fire by sharing information and\nopinion that is not only incorrect but adds to the anxiety many are facing.\nYes, businesses and consumers need to be aware that cyber criminals are now\nposing as local governments, charities and trusted organisations, but that is\never present in today\u2019s society. Getting security basics right is just as\nimportant now as it has been for the past decade, we should focus energies on\nensuring those basics are in place,\u201d he added.<\/p>\n\n\n\n<p>CTU researchers\nrecommend that organizations apply the following mitigations for\ncoronavirus-themed threats. Many of these security practices protect\norganizations against other threats as well.<\/p>\n\n\n\n<p>\u2022 Train employees to recognize and report phishing and other scams. These attempts could leverage via email, phone, social media, SMS (text), or other messaging applications.<\/p>\n\n\n\n<p>\u2022 Conduct regular vulnerability scans, particularly of Internet-facing infrastructure. Ensure that devices and applications are centrally managed, are installed from known-good media, and are regularly patched.<\/p>\n\n\n\n<p>\u2022 Use multi-factor authentication where possible. Requiring additional authentication elements makes it difficult for threat actors to gain access using stolen user credentials.<\/p>\n\n\n\n<p>\u2022 Implement endpoint and network monitoring controls to detect malicious activity. Focus on detecting and investigating unusual activity from weaponized files, such as launching PowerShell, WMI, WScript, or unusual network communications.<\/p>\n\n\n\n<p>\u2022 Where possible, require users to connect through corporate resources such as virtual private networks (VPNs) and DNS servers to access the Internet. This approach provides additional monitoring opportunities if user endpoints are compromised.<\/p>\n\n\n\n<p>\u2022 Consider the organization\u2019s security requirements when selecting a remote conferencing tool and vendor to ensure that the tool allows for an appropriate level of protection for conversations and data.<\/p>\n\n\n\n<p>\u2022 Issue guidance to employees regarding proper use of remote conferencing services. Use passcodes or other authentication features, and do not publicly disclose meeting IDs where possible.<\/p>\n\n\n\n<p>\u2022 Review incident response plans to ensure that remain appropriate for the modified work environment. Consider how to test those plans without adding unnecessary stress to the organization.<\/p>\n\n\n\n<p>\u2022 Select a full-service threat intelligence provider, or several complementary ones, that offers coverage to support the organization\u2019s threat model and that reduces the potential of internal security teams spending their time chasing false leads.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Secureworks\u00ae Counter Threat Unit\u2122 (CTU) researchers are tracking multiple coronavirus-themed [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":8816,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621],"tags":[724,1189,518,894,949,1036,1188],"contributor":[],"class_list":["post-2439","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","tag-covid_19","tag-ctu","tag-cyber_security","tag-pandemic","tag-research","tag-secureworks","tag-threat_unit"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/04\/Cyber-Security-Cyber-adversaries-techxmedia.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=2439"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2439\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/8816"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=2439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=2439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=2439"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=2439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}