Menu
Many attackers lurk undetected for months, then pounce, study finds

Many attackers lurk undetected for months, then pounce, study finds

Gaining access credentials is a way to keep access without installing malware, Mandiant said

Attackers who penetrate company networks often pose as legitimate users for long periods of time, causing lengthy delays before victims figure out they've been hacked.

FireEye's Mandiant forensics service found that it took a median of 205 days for an organization to detect a compromise, down slightly from 229 days in 2013, according to its 2015 Threat Report.

The drop is nearly insignificant. "I don't think it's enough to make a claim that people are getting better at this," said Matt Hastings, a senior consultant with Mandiant who works on incident response.

One of the main problems is that attackers are moving away from using malware that can be quickly detected. Instead, they're stealing authentication credentials and using them to log into systems remotely. In that way, they look like legitimate users logging into systems, which becomes difficult to detect.

In two of the largest payment card data breaches, affecting Target and Home Depot, attackers obtained credentials used by third-parties to access those retailers' networks, allowing them to gain a foothold that eventually enabled attacks on their point-of-sale systems.

To be sure, attackers still use malware and backdoors, but more judiciously. In fact, victims will often find components and tools used for an attack and remove them, Hastings said, but still fail to understand fully what is going on.

As a result, the hackers -- seeing that some of their intrusions have been detected -- can change tactics to maintain their presence in a network.

Mandiant's report said in 69 percent of breaches, an organization found out about an attack from another group, such as law enforcement. That's up from 67 percent in 2013 and 63 percent in 2012.

One of the ways an attacker can appear to be an authorized user is by gaining VPN access. Mandiant saw attackers obtain login credentials for those systems more in 2014 than ever before.

Once they enter through a VPN, an attacker can often get access to other systems, Hastings said. That opens the possibility of using a tool such as Mimikatz, which can collect clear-text passwords of users currently logged in.

Windows will keep credentials in memory so they can be reused for single-sign on, and that can allow Mimikatz to grab them.

Windows Server 2012 R2 and Windows 8.1 have a defensive mechanism called "protected processes" to defend against this kind of attack, Hastings said. But most organizations use Windows Server 2008 functional domains and Windows 7 endpoints.

"Unfortunately, at this point, it's very hard to mitigate this type of risk," Hastings said.

To further blur their activity, attackers modify and recompile Mimikatz's source code. Mandiant said it did not find a single instance in which an organization's antivirus software detected or prevented Mimikatz from running, despite its reputation.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags intrusionsecurityFireEyemalware

Featured

Slideshows

Reseller News launches inaugural Hall of Fame lunch

Reseller News launches inaugural Hall of Fame lunch

Reseller News welcomed 2015 and 2016 inductees - Darryl Swann, Dave Rosenberg, Gary Bigwood, Keith Watson, Mike Hill and Scott Green - to the inaugural Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed how the channel can collectively work together to benefit New Zealand, the Kiwi skills shortage and the future of the industry. Photos by Maria Stefina.

Reseller News launches inaugural Hall of Fame lunch
Educating from the epicentre - Why distributors are the pulse checkers of the channel

Educating from the epicentre - Why distributors are the pulse checkers of the channel

​As the channel changes and industry voices deepen, the need for clarity and insight heightens. Market misconceptions talk of an “under pressure” distribution space, with competitors in that fateful “race for relevance” across New Zealand. Amidst the cliched assumptions however, distribution is once again showing its strength, as a force to be listened to, rather than questioned. Traditionally, the role was born out of a need for vendors and resellers to find one another, acting as a bridge between the testing lab and the marketplace. Yet despite new technologies and business approaches shaking the channel to its very core, distributors remain tied to the epicentre - providing the voice of reason amidst a seismic industry shift. In looking across both sides of the vendor and partner fences, the middle concept of the three-tier chain remains centrally placed to understand the metrics of two differing worlds, as the continual pulse checkers of the local channel. This exclusive Reseller News Roundtable, in association with Dicker Data and rhipe, examined the pivotal role of distribution in understanding the health of the channel, educating from the epicentre as the market transforms at a rapid rate.

Educating from the epicentre - Why distributors are the pulse checkers of the channel
Kiwi channel reunites as After Hours kicks off 2017

Kiwi channel reunites as After Hours kicks off 2017

After Hours made a welcome return to the channel social calendar last night, with a bumper crowd of distributors, vendors and resellers descending on The Jefferson in Auckland to kickstart 2017. Photos by Maria Stefina.

Kiwi channel reunites as After Hours kicks off 2017
Show Comments