North Korean insider threat targets U.S. technology companies

Cloud and cross-domain attacks, credential and RMM tool abuse persists.

  • Wednesday, 21st August 2024 Posted 6 months ago in by Phil Alsop

CrowdStrike has released the 2024 Threat Hunting Report, highlighting the latest adversary trends, campaigns and tactics based on the frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts. The report reveals a rise in nation-state and eCrime adversaries exploiting legitimate credentials and identities to evade detection and bypass legacy security controls, as well as a rise in hands-on-keyboard intrusions, cross-domain attacks, and cloud control plane exploits.

Key findings include:

North Korea-Nexus Adversaries Pose as Legitimate U.S. Employees: FAMOUS CHOLLIMA infiltrated over 100 primarily U.S. technology companies. Leveraging falsified or stolen identity documents, malicious insiders gained employment as remote IT personnel to exfiltrate data and carry out malicious activity.

Hands-on-Keyboard Intrusions Increase by 55%: More threat actors are engaging in hands-on-keyboard activities to blend in as legitimate users and bypass legacy security controls. 86% of all hands-on intrusions are executed by eCrime adversaries seeking financial gains. These attacks increased by 75% in healthcare and 60% in technology, which remains the most targeted sector for seven years in a row.

RMM Tool Abuse Grows by 70%: Adversaries including CHEF SPIDER (eCrime) and STATIC KITTEN (Iran-nexus) are using legitimate Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect for endpoint exploitation. RMM tool exploitation accounted for 27% of all hands-on-keyboard intrusions.

Cross-Domain Attacks Persist: Threat actors are increasingly exploiting valid credentials in order to breach cloud environments and eventually using that access to access endpoints. These attacks leave minimal footprints in each of those domains, like separate puzzle pieces, making them harder to detect.

Cloud Adversaries Target the Control Plane: Cloud-conscious adversaries like SCATTERED SPIDER (eCrime) are leveraging social engineering, policy changes and password manager access to infiltrate cloud environments. They exploit connections between the cloud control plane and endpoints to move laterally, maintain persistence and exfiltrate data.

“For over a decade, we’ve vigilantly tracked the most prolific hacktivist, eCrime, and nation-state adversaries,” said Adam Meyers, Head of Counter Adversary Operations at CrowdStrike. “In tracking nearly 250 adversaries this past year, a central theme emerged—threat actors are increasingly engaging in interactive intrusions and employing cross-domain techniques to evade detection and achieve their objectives. Our comprehensive, human-led threat hunting directly informs the algorithms that power the AI-native Falcon platform, ensuring that we stay ahead of these evolving threats and continue to deliver the industry’s most effective cybersecurity solutions.”

Businesses that create a cycle of savings and investment in innovation are 2x as likely to report improved ROI.

Data modernisation investment crucial for AI success

Posted 20 hours ago by Phil Alsop
Only 19% of communications service providers worldwide have fully implemented an integrated set of processes, platforms and governance policies...
One in two organisations is overspending on cloud storage budget.

Enterprises wasted $104M on underused tech in 2024

Posted 20 hours ago by Phil Alsop
AI investment booms with major gap between AI ambitions and employee readiness.

AI Agents 'essential' to work

Posted 20 hours ago by Phil Alsop
New findings from Freshworks’ AI Workplace report have revealed that over half (52%) of Gen Z workers believe AI agents are essential to their...

UK CTOs share their biggest data challenges

Posted 20 hours ago by Phil Alsop
Out-of-date data an issue for the majority alongside visibility, reporting, and digital bureaucracy.

Cyber attacks on manufacturers up globally

Posted 21 hours ago by Phil Alsop
Estimated downtime cost individual firms up to US$2m.

Global AI adoption to surge 20%

Posted 6 days ago by Phil Alsop
AI adoption has skyrocketed over the past years as businesses and individuals increasingly integrate AI-powered tools into everyday life. In 2020,...