Linchakin

CYBERWARCON – Foreign influence operations grow up

 November 19, 2021     No comments   

Not long ago, disinformation campaigns were rather unsophisticated. These days, however, threat actors put serious time and effort into crafting their attacks.

From the Chris Krebs keynote to highlighting third-string, nation-state entrants into the cyber-arms race, the art of targeted disinformation is heating up here at CYBERWARCON. Two years ago (the last time the conference happened), the disinformation efforts were relatively unsophisticated, but now threat actors are spending serious time and effort crafting all the steps of the attack, and finding out what works.

More sophisticated actors are spending a lot more time infiltrating corporate email undetected. In this way, if they can quietly control email, in an email-in-the-middle attack, they can silently referee and exert selective information on very specific parts of the organization.

The phishing is getting better too, with more targeted efforts surrounding would-be conference speakers and news reporters. The ruse for speaker hopefuls it to pretend to be a conference organizer and explain they have been accepted as a speaker at a prominent event, but they have to register by clicking the link, which harvests information on a fake, usually cloned, website.

Attackers are doing a lot more research on their targets too. They now know a lot more about the target’s hopes and aspirations and play into them with very specific details harvested from their research efforts. The attacker’s language is getting better too, making it harder to spot fakes.

When attackers aren’t phishing, they’re usually deploying targeted ransomware. It’s anonymous and the proceeds, passed through cryptocurrency, pay for their continued operation. While the less sophisticated ransomware operators are increasingly getting busted, nation-state ransomware operators have more time and can support a more sustained effort to get what they want.

If neither phishing nor ransomware are doing the trick, bad actors try to influence news directly. By hacking legitimate news websites and pushing out fake stories with a special emphasis on certain aspects that highlight your country’s initiatives, it’s easy to believe it’s real.

To back it up, it’s important to create a number of fake personas that tweet about the story and push it throughout social media to help amplify the fake messaging.

And to sustain this kind of effort to make an issue appear real, organizations have to continue to apply pressure by pushing bogus news without getting caught, which requires some sophistication, budget and long-term focus on key issues. These factors point squarely toward nation-state activity, or at least support.

How can we fix this? According to Chris Krebs: impose steeper costs to attack. In Washington DC, there were rooms full of legislators trying to find ways to go after ransomware operators more deliberately and with the blessing of their constituents, victims, and fellow lawmakers, so imposing costs to attackers will continue to be a popular message. Also, don’t click on links in email – the perpetual public service announcement that just has to be repeated.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Large Phishing Campaign Abuses Open RedirectsResearchers at Microsoft have observed a widespread phishing campaign that’s abusing open redirectors to fool users into visiting credential-harvestin… Read More
  • [Live Demo] Ridiculously Easy Security Awareness Training and PhishingOld-school awareness training does not hack it anymore. Your email filters have an average 7-10% failure rate; you need a strong human firewall as you… Read More
  • When the URL Domain Is Not Enough To Avoid a PhishOne of the most common mantras in security awareness training is “Examine the URL to determine if it points to the legitimate vendor or not!” It is gr… Read More
  • WFHGoogle delays mandatory return to office until January 2022Google will let its employees work from home for a little while longer. In a message to employees published publicly on Tuesday, Google and Alphabet C… Read More
  • LUCRATIVE SEAShopee boss becomes Singapore's richest man with USD20.2 billion fortuneThe most recent update to the Bloomberg Billionaires Index (a daily ranking of the world's richest people) has seen Singaporean tech magnate Forrest L… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates