Antivirus

Defending against nation state ransomware

As a professional with over 20 years in the cyber security space, I cringe when a vendor presents and says: “attacks are getting more sophisticated and harder to defend against.”   While some of it rings true, it surely misses a critical point. The cyber security community has also become smarter, more vigilant, more sophisticated and…


As a professional with over 20 years in the cyber security space, I cringe when a vendor presents and says: “attacks are getting more sophisticated and harder to defend against.”   While some of it rings true, it surely misses a critical point. The cyber security community has also become smarter, more vigilant, more sophisticated and capable, and goes beyond just using antivirus software and malware removal tools.  In all of my research this year, in cases where I have seen gaps, we have had the means in our possession to easily fix.

With that said, there are two trends that look likely to rise in 2020 and for which we must be vigilant and prepared.

free anti-ransomware software being available.

About the author

Dave Klein is the senior director of cybersecurity at Guardicore.

Nation state actors have become more brazen

A major concern for 2020 must be the increasing number of capable nation state cyber actors/attackers.  These nation state actors have become extremely skilled at using false flag/obfuscation techniques and proxy actors in their cyber warfare to prevent clear-cut attribution back to their home state.  By making attribution difficult, so bad actors get away with their crimes and continue unhindered.  Furthermore, as per the 2019 Verizon Data Breach study, nation state attacks have increased from 12 per cent of attacks in 2017 to 23 per cent in 2018.  

As the world has become more experienced in uncovering nation state players so they have become more experienced in hiding, avoiding pitfalls and even manipulating data, tool kits and techniques to throw forensic analysts off by mimicking another nation state or criminal actors.   

Go to techniques once used to easily identify attackers no longer work.  Time stamps, which if analysed statistically could give you an attacker’s workday (and thus their global location), are now often manipulated.  Coding and debugging techniques are being manipulated since state actors know malware strings themselves. Debug paths and metadata are often used to zero in on an attacker’s base language, usernames and codin

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

Microsoft Defender briefly decided Google Search was malware

You can pay every month for Office 365’s productivity tools, but you still can’t escape Microsoft Defender’s habit of turning everyday links into fake security alerts. On September 2, Office 365 subscribers ran into an unusual incident: Redmond’s endpoint antivirus engine began flagging Google Search results as potentially malicious URLs.Read Entire Article…

You can pay every month for Office 365’s productivity tools, but you still can’t escape Microsoft Defender’s habit of turning everyday links into fake security alerts. On September 2, Office 365 subscribers ran into an unusual incident: Redmond’s endpoint antivirus engine began flagging Google Search results as potentially malicious URLs.Read Entire Article…
Read More

Continue Reading
Antivirus

5 Windows Security Settings You Should Never Skip Over

Windows has a range of authentication methods for accessing your device, a firewall, an antivirus, a way to encrypt your drives and more…

Windows has a range of authentication methods for accessing your device, a firewall, an antivirus, a way to encrypt your drives and more…
Read More

Continue Reading
Antivirus

Watch out for this fake Face ID Apple Pay pop-up scam

Macworld The security, antivirus, and VPN company Malwarebytes has an interesting post on its Malwarebytes Labs blog detailing a new and sophisticated scam. The web-based trick is meant to make users think that they just made a big payment with Apple Pay, with the goal being to trick them into calling a fake “Apple Support”

Macworld

The security, antivirus, and VPN company Malwarebytes has an interesting post on its Malwarebytes Labs blog detailing a new and sophisticated scam.

The web-based trick is meant to make users think that they just made a big payment with Apple Pay, with the goal being to trick them into calling a fake “Apple Support” number…
Read More

Continue Reading
Antivirus

This simple antivirus tool is the easiest way to scan your Linux PC for threats – for free

Worried about Linux vulnerabilities or sharing files with Windows users? This ClamAV GUI makes it easy to ensure they’re clean…

Worried about Linux vulnerabilities or sharing files with Windows users? This ClamAV GUI makes it easy to ensure they’re clean…
Read More

Continue Reading