Most Cyberattacks in 2019 Were Waged Without Malware

  /     /     /  
Publicated : 23/11/2024   Category : security


Most Cyberattacks in 2019 Were Waged Without Malware


If the malware-free attack trajectory continues, it could mean major trouble for defenders, according to experts from CrowdStrike and other security companies.



A modern spin on the old-school hacker-behind-the-keyboard attack exceeded malware-borne ones worldwide last year, new incident report data from CrowdStrike shows.
Seasoned cybercriminals and nation-state attackers for some time now have been upping their game with new methods to mask their activities from security tools by blending in and posing as real users in the targeted organizations network - using stolen credentials and running legitimate tools to dig through victim systems and data, for instance. And for the first time in CrowdStrikes research and incident response engagement reporting, so-called malware-free attacks edged ahead of malware-based ones, at 51% to 49% in 2019. In 2018 and 2017, malware accounted for around 60% of all attacks globally, and malware-free attacks around 40%, according to CrowdStrikes data.
A malware-free attack in CrowdStrikes parlance is one where the method to gain entry into a victim organization doesnt employ a malicious file or file fragment to a computer disk. In addition to stolen credentials or legitimate tools, this type of attack also can execute code from memory and can only be detected with higher-level tools and techniques that spot unusual behavior, or via threat hunting.
Like the bad old days of hacking, much of the attack is driven by hands-on keyboard methods like command line interface, PowerShell, and hiding files and directories, according to CrowdStrike. These techniques feature prominently in many sophisticated attacks, where a human adversary is engaged in the intrusion and is actively working toward an objective, according to
the report

Security experts worry that if attackers double down on malware-free attacks, security tools - and ultimately, targeted organizations - will be overwhelmed and unable to thwart them.
Michael Sentonas, CTO of CrowdStrike, says these malware-free attacks have gradually increased as attackers have found ways to bypass traditional security tools. But the attackers arent stopping at commodity antivirus software. Now theyre starting to bypass next-generation AV products as well. Thats driving a big escalation in malware-free attacks, he says. If that hits 60% and above, its going to be a big problem.
The problem is that most organizations dont have the technology to discern between a legitimate user or an attacker who has stolen his or her credentials, Sentonas notes. I want to track over the next 12 months the malware-free piece to see if thats a real interesting [longer term] trend there, he says.
Rapid7 also has seen attackers forgo malware when infiltrating their targets. They are using valid credentials or reusing credentials from other breaches. Thats hard [to defend against], says Tod Beardsley, director of research at Rapid7. Its not something you can easily automate defense on.
To help combat these threats, he says, organization needs to empower end users to be part of a security culture. You have to build trust between IT security and the user base. In that vein you are building a culture of vigilance, he says, where if you see something that looks suspicious, theres a clear step on what to do about it, whether confirming it out-of-band or reporting it to the right people.
Most malware-free attacks last year occurred in North America, where three-fourths of attacks didnt deploy malware to get inside the victim organization, according to CrowdStrike. It will be interesting as we go through this year: Will malware-free attacks continue to rise, and will that correlate in dwell time [of attackers]? says Sentonas. If we see that as a two- to four-year trend, we have a problem. There are more and more ways to evade security controls.
That requires a defense that accounts for the human element. Now more attackers are human, says Chester Wisniewski, a principal research scientist with security vendor Sophos. Thats why setting tripwires to detect legitimate tools being used for nefarious purposes is key, he says. For example, if the Nmap network monitoring tool is spotted running on a Web server in the DMZ, that should be a red flag, he says. No one should be running it ... in the server in the DMZ, he says.
If a legitimate security tool is running at a time other than when it should be used, that constitutes an incident, he says. Youre not the only one using these tools, he says, noting that the bad guys are as well.
Related Content:
Latest Security News from RSAC 2020
Malware-based Attacks Dropped 20% Worldwide
Assessing Cybersecurity Risk in Todays Enterprise
How Data Breaches Affect the Enterprise

2019 Online Malware and Threats: A Profile of Todays Security Posture
Check out The Edge, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
With New SOL4Ce Lab, Purdue U. and DoE Set Sights on National Security
.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Most Cyberattacks in 2019 Were Waged Without Malware