27
PROTECTING YOUR NETWORK Industry-leading threat intelligence. The largest threat detection network in the world. Martin Lee – Manager Talos Outreach EMEA

Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

P R O T E C T I N G Y O U R N E T W O R K

Industry-leading threat intelligence. The largest threat detection network in the world.

Martin Lee – Manager Talos Outreach EMEA

Page 2: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

250+Full Time Threat Intel Researchers

MILLIONSOf Telemetry Agents

4Global Data Centers

1100+Threat Traps

100+Threat Intelligence Partners

THREAT INTEL

1.5 MILLIONDaily Malware Samples

600 BILLIONDaily Email Messages

16 BILLIONDaily Web Requests

Honeypots

Open Source Communities

Vulnerability Discovery (Internal)

Product Telemetry

Internet-Wide Scanning

20 BILLION

Threats Blocked

INTEL SHARING

Talos Intel Background

Customer Data Sharing Programs

Provider Coordination Program

Open Source Intel Sharing

3rd Party Programs (MAPP)

Industry Sharing Partnerships (ISACs)

500+Participants

Page 3: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Olympic Destroyerand the Rise of Wiper Malware

Page 4: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

The Guardian Publication

Page 5: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Reported Effects

§ Official Pyeongchang 2018 website off line

• visitors unable to access information

• unable to print tickets for events

§ Wifi in Olympic stadium unavailable

§ Internet access in press centre unavailable

§ Television screens in press centre not working

Page 6: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Olympic Destroyer

Page 7: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Actions

• Overwrite files with 1Mb of ‘0’s.

• Delete shadow copies.

• Delete backups.

• Wipe files on mapped shared folders.

• Disable boot recovery.

• Destroy event logs.

• Disable all Windows services.

• Reboot.

Page 8: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Antecedents

Page 9: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Rogues Gallery

Page 10: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

The Delivery Problem

Page 11: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Solved

Page 12: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Nyetya Spread

ETERNALBLUE

Scans IP subnet139 TCP

Perfc.dat PSEXEC

WMI

ETERNALROMANCE

Page 13: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Nyetya Effects

Page 14: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Olympic Destroyer Spread

Scans IP subnet viaARP table & WMI (WQL)

Winlogon.exe PSEXEC

WMI

Page 15: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

System Stealer

• Mimikatz (communication to the main module via named pipe)

Page 16: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Password Stealer

• Browsers: Internet Explorer, Firefox, Chrome (communication to the main module via named pipe)

Page 17: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

System Stealer

• The stolen credentials are used to patch the main binary• The patched binary will be used for the propagation

Page 18: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Whodunnit?

Page 19: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Who Was That?

Page 20: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Olympic Destroyer Similarities

Lazarus Group

APT3 APT10 Nyetya

Filename similarities +

Wiper function logic +

Credential stealer + +

AES key generation function +

WMI propagation & named pipe comms +

EternalBlue POC stub +

Page 21: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Is Anything New?

Page 22: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Ancient History

1974 Wabbit (1969?)

1985 CyberAIDS

1987 Jerusalem Virus

mainframe – used up resources until unable to access system

DOS – deletes executable files on Friday 13th

Apple – overwrites file system

Page 23: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Really Ancient History

Lumine supero privitis.Devotas consecratasque.Sunt maxime…Devoti.

Publius Cornelius Scipio Africanus

Page 24: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Areas for Research

Page 25: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Areas for Research

Traditional• Worm Spread

• Malware Execution

• Minimising Harm

Page 26: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

Areas for Research

Traditional Organisational• Worm Spread

• Malware Execution

• Minimising Harm

• Network architecture choices

• End point protection prevalence

• Backups anyone?

What decisions were made and why?

Page 27: Martin Lee –Manager TalosOutreach EMEA · Threat Intelligence Partners THREAT INTEL 1.5 MILLION Daily Malware Samples 600 BILLION Daily Email Messages 16 BILLION Daily Web Requests

talosintel.comblogs.cisco.com/talos

@talossecurity

[email protected]