sophos introduces the threat landscape

40
Threat Landscape John Shier Sr. Security Advisor @john_shier March 2017, Infosec BE

Upload: sophos-benelux

Post on 15-Apr-2017

30 views

Category:

Education


0 download

TRANSCRIPT

Page 1: Sophos introduces the Threat Landscape

Threat Landscape

John ShierSr. Security Advisor@john_shierMarch 2017, Infosec BE

Page 2: Sophos introduces the Threat Landscape

The Problem

Page 3: Sophos introduces the Threat Landscape
Page 4: Sophos introduces the Threat Landscape

Symptoms and Causes

ANNUAL NEW MALWARE

SAMPLES100,000,000’s

ANNUAL KNOWN EXPLOITS (CVE’S) 1,000’s

CUMULATIVE KNOWN EXPLOIT TECHNIQUES 10’s

Page 5: Sophos introduces the Threat Landscape

5

Top 10 detections: BelgiumMalformed doc

Infected archive

Conficker

Browser hijacker

Jenxcus botnet

Shortcut trojan

IRC bot

Bundpil worm

Dropper

Phishing

Page 6: Sophos introduces the Threat Landscape

6

What are we facing?

Page 7: Sophos introduces the Threat Landscape

The Tools

7

Page 8: Sophos introduces the Threat Landscape

Phishing

Page 9: Sophos introduces the Threat Landscape

9

How not to phish

Page 10: Sophos introduces the Threat Landscape

10

Modern phishing

Page 11: Sophos introduces the Threat Landscape

11

Modern phishing

http://www.kbc.be.vvsmbk.info/bestellen

Page 12: Sophos introduces the Threat Landscape

12

HD phishing

Page 13: Sophos introduces the Threat Landscape

13

Paypal

Page 14: Sophos introduces the Threat Landscape

14

Amazon

Page 15: Sophos introduces the Threat Landscape

15

Apple

Page 16: Sophos introduces the Threat Landscape

Document malware

16

Page 17: Sophos introduces the Threat Landscape

17

Curiosity infected the cat

Page 18: Sophos introduces the Threat Landscape

18

Curiosity infected the cat

Page 19: Sophos introduces the Threat Landscape

19

Curiosity infected the cat

Page 20: Sophos introduces the Threat Landscape

20

It’s guaranteed!

Page 21: Sophos introduces the Threat Landscape

21

Build Your Own 2.0

Page 22: Sophos introduces the Threat Landscape

The Infrastructure

Page 23: Sophos introduces the Threat Landscape

Malvertising

Page 24: Sophos introduces the Threat Landscape
Page 25: Sophos introduces the Threat Landscape

Exploit kits

25

Page 26: Sophos introduces the Threat Landscape

26

A decade of misery

2006 2013 2016

Page 27: Sophos introduces the Threat Landscape

27

Angler EK

Page 28: Sophos introduces the Threat Landscape

28

Lurk banking trojan

Page 29: Sophos introduces the Threat Landscape

Exploit Kits (2016)1H2016

Angler Nuclear NeutrinoMagnitude RIG Other

2H2016

RIG Neutrino Other

Page 30: Sophos introduces the Threat Landscape

Exploits (January 2017)• Magnitude• Neutrino-v

• RIG, RIG-E

• Sundown

• Bizarro Sundown

CVE-2016-0189

CVE-2014-6332

CVE-2016-4117

CVE-2016-1019

CVE-2015-8651

CVE-2016-4117

CVE-2016-0189

CVE-2016-7200

CVE-2016-7201

CVE-2016-0189

CVE-2015-8651

CVE-2015-5122

CVE-2013-2551

CVE-2014-6332

CVE-2015-2419

CVE-2016-4117

CVE-2015-5119

CVE-2016-0034

CVE-2016-7200

CVE-2016-7201

CVE-2016-0189 CVE-2016-4117

CVE-2015-5119

Flash Edge Silverlight IE Windows LPE

Page 31: Sophos introduces the Threat Landscape

The Payloads

31

Page 32: Sophos introduces the Threat Landscape

32

Remote access trojans

Page 33: Sophos introduces the Threat Landscape

33

Honour amongst thieves

Page 34: Sophos introduces the Threat Landscape

34

Dridex

Page 35: Sophos introduces the Threat Landscape

BetaBot

Page 36: Sophos introduces the Threat Landscape

Ransomware

36

Page 37: Sophos introduces the Threat Landscape

37

Ransomware

</>

Command andControl Server

Malware Distribution

Server

Page 38: Sophos introduces the Threat Landscape

38

Ransomware

abc exe abc

abc abc dll

Private Key Public Key

RAM

Malware Distribution

Server

Command andControl Server

0100101011010110101010

Page 39: Sophos introduces the Threat Landscape

39

Ransomware

abc exe abc

abc abc dll

Private Key Public Key

Malware Distribution

ServerRAM

#$! exe #$!

#$! #$! dllCommand andControl Server

Page 40: Sophos introduces the Threat Landscape