Can “Regular” Threat Actors Become Quasi-APTs?

The proliferation of cyber-offensive capabilities has been thoroughly discussed in recent years by academics and think tankers alike. Parallels between this modern cyber arms race and the race to nuclear capabilities that plagued the previous century have been exhausted, in an attempt to encapsulate the rapid expansion and increasing volatility of the cyber threat landscape in recent years. In the past year alone, this escalation has been made blatantly manifest through the spike in ransomware attacks, the deployment of pernicious new malware and the unprecedented surge in cybercrime, cybercriminals and cyber incidents - coordinated and conducted within the illicit underground communities of deep and dark web. Check out our “State of the Underground in 2021” report for more context.

If there was any need to further crystallize this idea of cyber proliferation and its consequences, the latest conflict in Ukraine made the final argument. To understand why the conflict in Ukraine is so significant to our discussion, we need to look back fourteen years, when Russia attacked Georgia during the summer of 2008. Before and after Russia’s invasion, international media outlets reported that Moscow had deviated from the standard norms of conventional warfare, and had been deploying major cyberattacks against Georgian websites and internet infrastructure. This was reported to be a Kremlin-backed, nation-state campaign, one that was considered by many as the “first case in history of a coordinated cyberspace domain attack synchronized with major combat actions in the other warfighting domains”.

Fast-forward to 2022. The first shots fired in the current conflict between Russia and Ukraine were not by firearms, but keystrokes. In this new-age war, the cybersphere is a primary battleground, and advanced threat actor groups are the foot soldiers. This Russian-Ukrainian cyber-battlefield is complex and multipolar, populated by many disparate threat groups, each determined to do their part - and take their share of the winnings. Hence, it is not uncommon to see threat actor groups declaring their latest victories in the ongoing digital battle, be it pro-Ukranian threat actor groups announcing their successful breach of Russian federal organizations or pro-Russian threat actors targeting Western infrastructures. A brief scroll through these groups' twitter profiles and telegram channels is suffice to see how structured and organized they behave.  

What has changed between 2008 and 2022? How can we explain the mass mobilization of threat actors of all levels of sophistication, taking to the cyber-battlefield to play their part in a conventional war between nation-states? It would be simplistic, in my humble opinion, to attribute this massive paradigm shift only to advancements in technology. Instead, I find this external, global change to be deeply connected to the changing internal dynamics of the cybercriminal underground itself. The proliferation of cyber offensive capabilities on the global scale has unfolded in tandem with the proliferation of knowledge  within the cybercriminal underground, allowing threat actor groups to build off one another and ‘leapfrog’ their way forward at a dizzying pace.

‘Leapfrogging’ refers to the process of bypassing the standard, step-by-step path of development, whereby a nation, an enterprise or a person takes advantage of existing opportunities and innovations to skip ahead, accelerating development to jump straight to a leading position of advancement. In the cybercriminal underground, threat actors have access to a multitude of ‘leapfrog’ enablers, able to employ the tools and services developed by their more experienced counterparts to deploy complex attacks that had previously only been possible for those who had followed the step-by-step evolutionary practice of building cyber expertise. Now, there is a clear opportunity for cybercriminals of every level of sophistication to “buy” instead of “make” their arsenal for attack.

This leapfrog phenomenon has advanced rapidly in the cybercriminal underground over the past decade, starting with the introduction of “kits” and “as-a-service” offerings within the illicit underground economy of the dark and deep web. These new offerings allowed threat actors to wholly outsource their tools for attack, with pre-built packages of scripts and tools facilitating anything from DDoS attacks to common vulnerability exploitation. To capitalize on this booming new underground industry, many malware authors have moved to profit on their expertise, providing their skills   “as-a-service” - allowing their customers to cherry-pick their targets while bypassing the tiresome and complicated process of developing sophisticated malware or deploying and maintaining C&C servers to control the malware’s operations during the attack. 

“It’s the economy, stupid”, said the chief strategist of Bill Clinton’s 1992 election campaign. The dark and deep web -- the world’s third largest economy – appears to be in vehement agreement. The demand for quick wins and easy profits has spurred more and more actors to offer new kinds of services in various pricing strategies. One of the more popular services today in the underground market is that offered by Initial Access Brokers, or as we like to call them, IABs. These IABs sell access to thousands of compromised endpoints on a daily basis, allowing cybercriminals to buy their first way into the networks of almost every enterprise and vendor out there. For as little as $10 apiece, threat actors can purchase access and gain a steady foothold in their targets’ systems, attaining a beachhead into highly secured organizations without having to bother with the complex and boresome process of gaining initial access on their own. By outsourcing access, attackers of all levels of sophistication can leapfrog several steps, jumping yet another step closer to the level of Advanced Persistent Threat Groups (APTs).

Why is this leapfrog strategy important? Well, if you were a CISO working in a big corporation 5 or 10 years ago, you could have directed your threat intelligence team to focus on a dozen nation-state linked groups, and rest assured that your team has got you covered. Today, this is no longer the case. As cyber capabilities proliferate, trickling from APTs to less advanced threat groups, there are tens of thousands of actors who may be simply one click away from purchasing the advanced capabilities that would allow them to leapfrog into quasi-APT status. 

This means that the CISO of 2022 must maintain constant vigilance, ensuring that their organization has the capacity to track, monitor and remediate threats coming in from multiple focal points. It’s not only the well-known SPIDERs, BEARs and PANDAs anymore, but your average-joe dark web actor or the local anonymous chapter. The question is no longer how relevant and actionable your threat intelligence is, but it’s also how comprehensive and scalable it can be. Simply put: can your cyber threat intelligence continuously track millions of cybercriminal actors every day, and deliver the critical insights you need to block threats in real-time?

Featured

  • Survey: 48 Percent of Worshippers Feel Less Safe Attending In-Person Services

    Almost half (48%) of those who attend religious services say they feel less safe attending in-person due to rising acts of violence at places of worship. In fact, 39% report these safety concerns have led them to change how often they attend in-person services, according to new research from Verkada conducted online by The Harris Poll among 1,123 U.S. adults who attend a religious service or event at least once a month. Read Now

  • AI Used as Part of Sophisticated Espionage Campaign

    A cybersecurity inflection point has been reached in which AI models has become genuinely useful in cybersecurity operation. But to no surprise, they can used for both good works and ill will. Systemic evaluations show cyber capabilities double in six months, and they have been tracking real-world cyberattacks showing how malicious actors were using AI capabilities. These capabilities were predicted and are expected to evolve, but what stood out for researchers was how quickly they have done so, at scale. Read Now

  • Why the Future of Video Security Is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reasons. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. Read Now

  • UL Solutions Launches Artificial Intelligence Safety Certification Services

    UL Solutions Inc., a global leader in safety science, today announced the launch of artificial intelligence (AI) safety certification services, enabling comprehensive assessments for evaluating the safety of AI-powered products. Read Now

  • ESA Announces Initiative to Introduce the SECURE Act in State Legislatures

    The Electronic Security Association (ESA), the national voice for the electronic security and life safety industry, has announced plans to introduce the SECURE Act in state legislatures across the country beginning in 2025. The proposal, known as Safeguarding Election Candidates Using Reasonable Expenditures, provides a clear framework that allows candidates and elected officials to use campaign funds for professional security services. Read Now

    • Guard Services

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.