Archive for June 22, 2023

Year-Long Cyber Attack on IT Firm Used A Bespoke Malware Called RDStealer

Posted in Commentary with tags on June 22, 2023 by itnerd

A targeted cyber-attack against an East Asian IT company utilized a custom malware called RDStealer, written in Golang. Known as RedClouds, the campaign began in early 2022 and specifically targeted the interests of China-based threat actors. “The operation was active for more than a year with the end goal of compromising credentials and data exfiltration,” Bitdefender security researcher Victor Vrabie said in a technical report.

In the initial stages, the attackers relied on readily available remote access and post-exploitation tools like AsyncRAT and Cobalt Strike. However, they later shifted to bespoke malware to evade detection.

To avoid being detected by security software, the attackers employed several anti-detection methods. One tactic involved utilizing Microsoft Windows folders that are typically excluded from scanning, such as “C:\Program Files\Dell\CommandUpdate.” This folder is associated with a legitimate Dell application further camouflaging the malicious activity, as all the infected machines were manufactured by Dell.

The threat actors further attempted to blend in with the target environment by registering command-and-control (C2) domains like “dell-a[.]ntp-update[.]com.” By doing so, they aimed to appear as legitimate entities within the network.

Dave Ratner, CEO, HYAS had this to say:

   “Malicious actors continue to find new mechanisms to cover their tracks, evade detection, and even masquerade their command-and-control communication. It’s further proof that advanced Protective DNS with unique knowledge of what is, and isn’t, adversarial infrastructure is a critical layer in a modern security stack. as recommended by CISA and others. Increasingly, it’s clear that detection of the beaconing behavior is the best way to drive the time required from infection to detection and remediation as close to zero as possible.”

The best way to stop attacks is to detect them before the threat actors have a chance to set up shop within your environment. Thus any steps that you can take to do that will only help you in the long run.

Digital Transformation Critical to Overcoming Roadblocks: Procore

Posted in Commentary with tags on June 22, 2023 by itnerd

Today Procore Technologies released its construction industry benchmark report, How We Build Now: Technology and industry trends shaping Canadian construction in 2023

The survey was conducted by independent research company Censuswide. A total of 502 construction decision-makers and influencers across Canada participated in the report. 

How We Build Now examines the general sentiment of the industry on issues including the labour shortage, the supply chain, digital transformation, sustainability in construction, and diversity and inclusion in the workplace. 
Construction firms in Canada understand that digital transformation is required to overcome the labour shortage: 22 per cent of construction businesses consider themselves a digital-first business and 51 per cent are ‘well on the way’ to adopting digital formats and workflows. Construction decision makers recognize that technology provides benefits, particularly around resource efficiency through less rework, an enemy of sustainability. The survey shows 27 per cent of the total time spent on a project is spent on rework or rectifying issues. Other findings: 

  • Almost half of all projects go over budget (50%) and over schedule (49%) according to respondents
  • Over 30 per cent of respondents identify needing new technology to improve operational efficiency and cost controls amid economic volatility
  • Paper remains a common medium for Canadian construction decision makers. About a quarter of respondents (23-28%, depending on the workflow) still use paper-based records or non-digital processes as part of their workflows 

According to the report, the industry realizes the value of data yet they are not able to leverage it to the fullest. 

  • 41 per cent of respondents feel that they would be able to make better decisions if they had better access to real-time and historic information on project performance. 
  • Respondents believe they could save up to 12 per cent of their total spending on projects if they captured, integrated and standardized data more efficiently

The full report can be found here: http://www.procore.com/en-ca/ebooks/how-we-build-now-report-can

Are Training and Certificates Improving Security?

Posted in Commentary with tags on June 22, 2023 by itnerd

Speaking at Infosecurity Europe, Munawar Valji, CISO of Trainline, Dr Emma Philpott, CEO at the IASME Consortium and Helen Rabe, CISO at the BBC were asked if there is an over reliance on security certifications. The panel agreed there are benefits but the processes designed to satisfy auditors or insurers potentially results in a less innovative and diverse workforce and can lead to organizations doing the bare minimum required to achieve certifications rather than improve security. 

“It can be time consuming and cumbersome to maintain,” says Rabe. “You have to figure out if controls are no longer relevant. It is not necessarily about certificates but obtaining the right outcomes,” Valji explained. 

In a separate panel, Charlie Sinclair, cyber security senior awareness and engagement manager at Unilever, and Tim Ward, CEO and co-founder at ThinkCyber explained the Nudge Theory, which uses easy, attractive, social and timely techniques to incentivize employees instead of punishing them for mistakes avoiding risky behavior and improving overall security. 

According to Ward, as many as 80% of security issues can come from just 10% of users. Sinclair pointed out that those users are usually “disconnected” from security issues, and they make mistakes and don’t tell anyone. “You need to focus on the psychology and how it works. You have to accept that humans bring risk and understand how to tackle that risk,” he said.

Willy Leichter, PV of Marketing, Cyware had this to say: 

   “Compliance requirements have been a major factor in making many organizations take security more seriously, but the typical check-box training program is out of date and inadequate. Rather than relying on online courses, real-world tests like mock phishing emails are more effective and impactful for users. But security teams can’t rely on training to keep them out of trouble – we have to assume there will always be susceptible users and design security that is resilient to insider mistakes.”

This kind of reminds me of the early 2000’s where everyone had a MCSE, but few people actually knew anything related to said MCSE. But employers would hire them anyway simply because of the fact that they had this certification. Given how high the stakes are when it comes to cybersecurity, we can’t afford to go back to those days because too much is on the line.