Preparing for 2018: Enterprise Ransomware, Software Supply Chain Attacks and Nation-State Threats

Preparing for 2018: Enterprise Ransomware, Software Supply Chain Attacks and Nation-State Threats

As we look back at 2017, one thing is certain – the hacks, breaches and exploited vulnerabilities that halted hundreds to thousands of businesses this year show that threat actors are growing more skilled, moving faster than legacy technology and finding clever ways to infiltrate organizations. With the new year approaching, we’ll see some major trends in attack types continue to grow and geopolitical motivations will strongly influence nation-state cyber activity.

Looking at the major attack types that will be prevalent in 2018, enterprise ransomware will continue to be a major trend for adversaries. In 2017, we saw these disruptive and destructive attacks come to the forefront with the WannaCry, NotPetya and BadRabbit malware outbreaks that successfully took companies offline for days and, in some cases, even weeks. While mostly destructive and not truly ransomware in nature, these attacks highlighted the potential for criminal groups to hold entire networks hostage while demanding millions of dollars in ransom from businesses who need to get their operations back up and running. These viral enterprise ransomware attacks will likely become a major trend amongst e-crime actors in 2018.

In addition to enterprise ransomware, software supply chain attacks will be the new vector for many adversaries. Recent events have demonstrated that the software supply chain is becoming an attractive way for nation-state threat actors to target organizations en-masse – take for example the CCleaner attack in September. Compromising the update channel of a popular software package can immediately give access to thousands of victims in one fell swoop. While these software supply chain attacks are not new, the frequency with which they have been taking place are a cause for concern. As evidenced by this momentum, the software supply chain will likely become a favorite threat distribution vector for criminal groups as well in 2018. In order to stay protected against these attacks, organizations must leverage anomaly-based detection and ensure comprehensive visibility to detect and stop these incidents.

Geopolitical motivations across the globe in 2018 will also continue to influence nation-state cyber activity. The potential for attacks from North Korea will continue to be a primary concern. In fact, we’ve been worrid for some time that one of the ways North Korea may try to deter a possible military attack against their nuclear or ballistic missile facilities is through asymmetric operations, which these days also include significant cyber attack capabilities. In particular, due to North Korea’s lack of dependence on global financial systems and the importance of it to U.S. and Western economies, as well as past history of intrusions into major banking institutions by DPRK, the financial sector is one that will likely suffer the brunt of these attacks.

Additionally, ongoing attacks from Iran against Saudi Arabia, and even potentially the United States, will come to the forefront in 2018. We have observed Iran invest significant resources in advancing its cyber capabilities over the last seven years. Continued tensions and proxy wars with Saudi Arabia over the conflicts in Syria, Yemen and the blockade of Qatar, have resulted in waves of cyber attacks from Iran against Saudi Arabia. These attacks are likely to continue and potentially escalate into 2018, with possible impact on Western companies working in Saudi Arabia. Additionally, if the U.S. pulls out of the JCPOA nuclear agreement and attempts to reinstate financial sanctions against Iran, they may expand those attacks to include the U.S. financial and energy sectors.

This past year was marked by adversaries finding more interesting and effective ways to cause harms to organizations – whether by halting operations or by exposing used data. And, with 2018 quickly approaching, it will be critical for organizations to focus on the growing threat vectors and nation-state developments affecting their industries.

About the Author

Dmitri Alperovitch is the co-founder and CTO of Crowdstrike.

Featured

  • Video Surveillance Trends to Watch

    With more organizations adding newer capabilities to their surveillance systems, it’s always important to remember the “basics” of system configuration and deployment, as well as the topline benefits of continually emerging technologies like AI and the cloud. Read Now

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.