Antivirus

Defending against nation state ransomware

As a professional with over 20 years in the cyber security space, I cringe when a vendor presents and says: “attacks are getting more sophisticated and harder to defend against.”   While some of it rings true, it surely misses a critical point. The cyber security community has also become smarter, more vigilant, more sophisticated and…


As a professional with over 20 years in the cyber security space, I cringe when a vendor presents and says: “attacks are getting more sophisticated and harder to defend against.”   While some of it rings true, it surely misses a critical point. The cyber security community has also become smarter, more vigilant, more sophisticated and capable, and goes beyond just using antivirus software and malware removal tools.  In all of my research this year, in cases where I have seen gaps, we have had the means in our possession to easily fix.

With that said, there are two trends that look likely to rise in 2020 and for which we must be vigilant and prepared.

free anti-ransomware software being available.

About the author

Dave Klein is the senior director of cybersecurity at Guardicore.

Nation state actors have become more brazen

A major concern for 2020 must be the increasing number of capable nation state cyber actors/attackers.  These nation state actors have become extremely skilled at using false flag/obfuscation techniques and proxy actors in their cyber warfare to prevent clear-cut attribution back to their home state.  By making attribution difficult, so bad actors get away with their crimes and continue unhindered.  Furthermore, as per the 2019 Verizon Data Breach study, nation state attacks have increased from 12 per cent of attacks in 2017 to 23 per cent in 2018.  

As the world has become more experienced in uncovering nation state players so they have become more experienced in hiding, avoiding pitfalls and even manipulating data, tool kits and techniques to throw forensic analysts off by mimicking another nation state or criminal actors.   

Go to techniques once used to easily identify attackers no longer work.  Time stamps, which if analysed statistically could give you an attacker’s workday (and thus their global location), are now often manipulated.  Coding and debugging techniques are being manipulated since state actors know malware strings themselves. Debug paths and metadata are often used to zero in on an attacker’s base language, usernames and codin

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

This hacker conference installed a literal antivirus monitoring system

Organizers had a way for attendees to track CO2 levels throughout the venue—even before they arrived…

Organizers had a way for attendees to track CO2 levels throughout the venue—even before they arrived…
Read More

Continue Reading
Antivirus

Hackers abuse Triofox antivirus feature to deploy remote access tools

Hackers exploited a critical vulnerability and the built-in antivirus feature in Gladinet’s Triofox file-sharing and remote-access platform to achieve remote code execution with SYSTEM privileges. …

Hackers exploited a critical vulnerability and the built-in antivirus feature in Gladinet’s Triofox file-sharing and remote-access platform to achieve remote code execution with SYSTEM privileges. …
Read More

Continue Reading
Antivirus

Moonlock review: We put MacPaw’s new antivirus suite to work

Macworld At a glanceExpert’s Rating Pros Excellent viral and malware protection and detection Good purchase options Access to learning tools and YouTube links Cons Security Advisor module lacks functionality Menus don’t offer enough clarity sScan scheduler only allowing for 15-minute increments VPN auto-connects to the closest server Our Verdict Moonlock isn’t perfect…

Macworld

At a glanceExpert’s Rating

Pros

Excellent viral and malware protection and detection

Good purchase options

Access to learning tools and YouTube links

Cons

Security Advisor module lacks functionality

Menus don’t offer enough clarity

sScan scheduler only allowing for 15-minute increments

VPN auto-connects to the closest server

Our Verdict
Moonlock isn’t perfect…
Read More

Continue Reading
Antivirus

Avast Free Antivirus for Mac review: Basic protection, for free

Macworld At a glanceExpert’s Rating Pros Easy installation and setup Solid customization options such as whitelists, exceptions, and scheduled scans Handy network tools like Traffic Monitor and Network Inspector Cons Steady stream of ads, upgrade prompts, and assorted locked features The Web Guard module failed to catch obvious scam links The Scam Guard failed to

Macworld

At a glanceExpert’s Rating

Pros

Easy installation and setup

Solid customization options such as whitelists, exceptions, and scheduled scans

Handy network tools like Traffic Monitor and Network Inspector

Cons

Steady stream of ads, upgrade prompts, and assorted locked features

The Web Guard module failed to catch obvious scam links

The Scam Guard failed to detect scam…
Read More

Continue Reading