What We Do
How we do it
Resources
SECURITY ADVISORIES
Jul 29, 2021
UPDATE: PetitPotam NTLM Relay Attack
THE THREAT PetitPotam is a variant of the NTLM Relay attack discovered by security researcher Gilles Lionel. It is tracked as an authentication bypass vulnerability in Active Directory (Certificate Services); currently no CVE identifier has been assigned to this vulnerability. Proof of Concept (PoC) code released last week [1] relies on the Encrypting File System Remote (EFSRPC) protocol to…
Read More
View all Advisories →
Company
ABOUT eSENTIRE
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1000+ organizations in 70+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
LATEST PRESS RELEASE
Jul 12, 2021
Tecala and eSentire Partner to Protect Enterprises across APAC from Business-Disrupting Cyber Attacks
Sydney, 12 July, 2021 - Tecala, Australia’s award-winning technology services and IT consulting provider, today announced it has chosen eSentire, the global Authority in Managed Detection and Response (MDR) cybersecurity services, as their exclusive MDR solution provider in Australia and New Zealand. This partnership will enable Tecala to augment its cybersecurity practice and offer enterprises…
Read More
Partners
PARTNER PROGRAM
Partners
Our award-winning partner program offers financial rewards, sales and marketing tools and personalized training. Accelerate your business and grow your revenue by offering our world-class Managed Detection and Response (MDR) services.
Learn about our Partner Program
Resources
Blog — Jan 09, 2019

Revisiting the 2018 threat forecast

4 min read

In the 2017 Annual Threat Report, the eSentire Threat Intelligence team documented a series of scenarios that could potentially occur though 2018. The likelihood of each forecast scenario increased or decreased according specific indicator events occurring. The 2017 report also contained a trend analysis section with five trends from 2017 that accurately carried through 2018. With 2018 now complete, this blog post reviews the list of scenarios and indicators to assess the 2018 forecast accuracy.

2018 Scenarios List

For a full explanation of each scenario and the correlating indicators, please see the 2017 Annual Threat Report [1].

Verified Forecasts

From this list, there were three scenarios that were positively confirmed through 2018.

2018 saw major increases in threat actor activity targeting cryptocurrencies; both through illicit mining [2] and targeted attacks on cryptocurrency wallets [3]. In late January 2018, eSentire detected a supply chain attack exploiting Kasaya’s Virtual System Administrator (VSA) to deliver cryptocurrency miners; this major event set a trend for 2018 [4]. One of the interesting aspects surrounding this rise is that the targeting of cryptocurrencies did not decrease as cryptocurrency values declined. This is likely due to a variety of contributing reasons, including the comparable simplicity of monetizing illicitly gained cryptocurrencies and the perceived anonymity of cryptocurrencies.

Throughout 2018, eSentire detected a high amount of IoT exploitation attempts, in line with an increase of cyber criminal attention on IoT devices. The largest spikes specifically targeted cameras, door controllers, surveillance equipment and media devices. Events that indicated attackers increased focus on IoT devices include the continuing low awareness of individuals relating to IoT devices, the ever increasing number of deployed devices and wormable IoT malware [5]. IoT device compromise is generally designed for indirect financial gain; compromising devices that can then be used in later attacks to generate illicit revenue.

Out of the seven scenarios from the 2017 annual report, Cyber criminals adopt swarm methods for command and control execution to harden blocking effort, is the only scenario to fall in between the generic did or did not categories. Peer to peer botnets have been used by threat actors for some time now; these botnets are structured in a decentralized way and do not require a standard command and control infrastructure. This botnet structure helps criminals to avoid a full takedown of services by law enforcement. Through 2018 we have not seen the advanced aspect of a swarm botnet, where each bot acts as an individual intelligent piece of a larger cluster, capable of discovering vulnerable systems and targets without specific instruction being passed down. Botnets continue to evolve and pose a threat, but true swarm technology botnets have not yet been identified in the wild.

Forecasts that did not Occur

The following three scenarios were not confirmed through 2018:

The indicators tracked for the above three scenarios were rarely seen or were negative events. Machine learning continues to be improved and applied in a real world context, but attacks in the wild employing machine learning have yet to be seen. Cyberwarfare is a vague term and open to some interpretation, but the known cyber operations used by radical groups has remained limited. Attacks by radical groups in 2018 have been primarily defacement and recruitment. Lastly, the potential that cyber-attacks cause physical infrastructure damage or loss of life remains real; in early 2018 the Triton ICS malware was publicly identified in a real world attack and had the potential to cause major damage and loss of life but this outcome was luckily avoided [6]. Although each scenario remains plausible, the likelihood of occurrence in the near future is limited.

A Final Word

By their nature, security predictions are unstable; any number of events can dramatically change the threat landscape and threat actor tactics. By identifying and tracking indicators that raise or lower the likelihood of a potential scenario it becomes possible to better know what to expect. For a complete security focused over-view of 2018, including industry trends and threat data, see the eSentire 2018 Annual Threat Report.

eSentire Threat Intel
eSentire Threat Intel Threat Intelligence Research Group