In this latest Lightboard session, Kate Taylor takes us through the three steps of the Palo Alto Networks multi-layered advanced threat detection approach: reduce the attack surface, leverage the sandbox and advanced malware detection techniques, and perform static and dynamic analysis of a file. Watch below:
Regular readers of this blog have heard all about the infamous Kuluoz malware. This family was the latest evolution of the Asprox malware and at its peak in 2014 it accounted for 80% of all malware sessions we observed in WildFire. When the team published our Threat Landscape Review in December of last year, we highlighted this family as a scourge that impacted nearly every company Palo Alto Networks protected in 2014. Kuluoz was primarily distributed through e-mail, which means we saw large numbers of SMTP sessions, but also downloads over a variety of webmail clients.
Even if you didn’t read our blogs, you probably dealt with Kuluoz. Throughout 2014, most of the waves of spam e-mails carrying fake court notices, voicemail messages and package delivery alerts carried a Kuluoz attachment. If you opened these attachments you quickly became part of the botnet, sending copies of the malware to other victims while the botmaster silently installed additional malicious software on your system.
Given all of this activity, we were quite surprised when the malware all but disappeared at the end of December 2014.
The screenshot above shows the number of malware sessions per week that we tagged as “Kuluoz” in the AutoFocus service. When we first noticed the drop-off, our suspicion was that we were “missing” the new Kuluoz samples. Just weeks earlier we published a report that highlighted their tactics — a tactical shift in response would not have been unprecedented.
As weeks turned into months, we found that Kuluoz didn’t return. We weren’t the only ones who noticed; Brad Duncan wrote a blog for the SANS indicating that the e-mails which had previously carried Kuluoz were now just…spam.
Based on the data we’ve collected, the Kuluoz command and control infrastructure largely shut down in January and the botnet is no more. We continue to capture new samples of Kuluoz in WildFire as orphaned infections continue sending out newly-crypted variants of the malware, but the numbers are a tiny fraction of Kuluoz at its peak.
The original Asprox botnet has gone through multiple incarnations since it came online in 2007. We’ve not yet seen any indication that the individuals behind these attacks have been arrested or forced to stop operating, so it’s likely that they’ve shut down this botnet to regroup and redeploy after they’ve found ways to evade the detections deployed by the security industry. After all, sending 80% of all malware puts you pretty high on everyone’s list of priorities.
If you are wondering what malware has replaced Kuluoz as our top family, the reigning champion is Upatre, which is a downloader that typically installs the Dyre banking Trojan or the CryptoWall Ransomware. It’s not nearly as prevalent as Kuluoz, but it’s certainly making an impression:
“As a security professional, what keeps you up at night?
I get this question all the time when speaking at various security events. There are a myriad of security-related problems that keep me up at night, but the one that weighs on my mind most is the sheer number of old vulnerabilities — we’re talking vulnerabilities at least a year old or more — that are still being successfully exploited.
According to Secunia, more than 15,000 vulnerabilities were discovered across nearly 4,000 products in 2014 alone.
So, why does this bother me so much? Because exposing yourself to risk through old vulnerabilities is unnecessary.
Vendors typically release patches for the most severe CVEs very quickly after they’re discovered, with 83 percent releasing them on the same day as disclosure. I’d like to say that, in light of this information, there’s no reason for organizations to be susceptible to old vulnerabilities, but that’s not entirely true.
Problems arise when there are so many patches per month or year that IT simply cannot keep up, as well as when vulnerable software runs on systems so critical that any downtime would endanger employee safety or cost the company millions of dollars in lost productivity. The vulnerability problem becomes an insurmountable obstacle that gets perpetually more difficult to tackle with each passing day. However, there are processes and technologies available to help solve these problems.
In a previous post, I explained how to go about making applications more secure. At the risk of being repetitive, I’m going to harp on the same points I made in that post, but only because software vulnerabilities are a serious problem that affect everyone, from your CEO to your mom.
Vendors can certainly do more to make sure fewer vulnerabilities reach production, by practicing secure coding and software development life cycles, and using web application firewalls. However, software vulnerabilities are a fact of life, and we’re not going to eradicate them anytime soon. Knowing this, enterprise software customers can do some things to protect themselves:
Segment your network. Architect it using the Zero Trust methodology, and make sure you know exactly which applications, users, data, and devices are traversing which segments.
Secure each segment with technologies that target multiple stages in the attack lifecycle, so that attackers are forced to spend the time and resources to craft completely new zero-day exploits and malware, and brand new command and control domains. Cyber criminals won’t be so set on attacking you if it’s cost-prohibitive or requires too much time and attention.
Use an intrusion prevention system whose signatures can stop more than a single exploit. Just like skinning a cat, there are many ways to exploit a vulnerability, so your protection must protect the vulnerability itself, regardless of which exploit is used.
Let’s stop attackers in their tracks — or at least make it difficult to poke holes in the software we use.
Find out more about Palo Alto Networks Intrusion Prevention System here.
Having recently moved to the San Francisco Bay Area, the reality that there is literally an app for everything is just now beginning to sink in. From my phone, office, and (the passenger seat of my) car, I’m able to have the week’s groceries delivered, a prescription refilled, and book a table at our favorite neighborhood brewpub. The customer-facing experience in the retail sector has been revolutionized in the past several years to make the checkout line more mobile and streamlined, but what about more secure?
Traditional thinking in security focuses on limiting attackers’ access to your data, by constricting user freedom. This is why, rather than an “Easy Button,” IT departments are more associated with a stern “NO” memo. But with evolving consumer tastes and the desire to streamline our lives, security must evolve or die if it is to have a place in this fast-evolving sector.
However, without strong, seamless security, we begin to lose trust in these digital systems that are making our life easier day to day. Recent breaches of personal information across stores, health providers, and governments show us how fragile this trust can be. And without it, we risk serious damage to the brands and innovation that drive our economy.
This was a core motivation behind President Obama’s decision to work with the retail and banking sectors at developing new ways to make us all more secure at the checkout. One group answering this call is the recently developed Retail Cyber Intelligence Sharing Center (R-CISC). Palo Alto Networks is proud to be the first associate partner for this new effort to share cyberthreat intelligence and help drive new security research as this sector works to adopt new technologies to make our lives both more accessible and secure.
The R-CISC includes top brands and will set up channels for sharing automated cyber intelligence on new and evolving threats targeting their customers. Palo Alto Networks hopes to provide this community with valuable cyberthreat intelligence and access into the broader security community as they stand up and grow in membership.
Palo Alto Networks will also be participating in the U.S. Department of Homeland Security’s efforts to establish guidelines for Information Sharing and Analysis Organizations (ISAOs), by sharing their experience working with the Cyber Threat Alliance. The ISAO model serves to provide an alternative to organizations that don’t fit into the traditional, critical infrastructure sector-based model of sharing information or who want to start a trusted sharing group based on common interest.
These efforts are a helpful start, but in order for trusted communities to grow, those of us who are already on this journey will have to help those taking the first steps. We’re excited to be a part of this conversation and will continue to press to make our community more effective and secure.
We’re pleased to announce that Mark McLaughlin and Ron Myers have been named to this year’s CRN’s Annual Top 100 Executives list. This list includes the fastest-moving executives in a market moving at warp speed.
“Most Influential” Category
The Top 25 Most Influential executives thrive in an era of speed-of-light disruptive technology changes, rising security threats, and activist investors.
The Top 25 Sales Leaders list is dominated by cloud sales leaders, hyper-converged and security sales superstars, and seasoned telecom channel executives bringing rich new cloud opportunities to partners.