* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, October 1, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Penn State-Themed Restaurant and Entertainment Spot Happy Valley Live Set to Open in State College – StateCollege.com

    Penn State-Themed Restaurant and Entertainment Spot Happy Valley Live Set to Open in State College – StateCollege.com

    The Police Made Chart History With This 1979 Hit Nearly 50 Years Ago – Yahoo

    How The Police Changed Music Forever with Their Iconic 1979 Hit Nearly 50 Years Ago

    Good Deed Entertainment Acquires Worldwide Rights To Liza Mandelup’s Documentary ‘Caterpillar’ – Deadline

    Good Deed Entertainment Lands Global Rights to Liza Mandelup’s Captivating Documentary ‘Caterpillar

    Danielle Fishel Explains Why Being on “DWTS” Makes Her Feel ‘Like It’s 1994 Again’ Filming “Boy Meets World” (Exclusive) – Yahoo

    Danielle Fishel Explains Why Being on “DWTS” Makes Her Feel ‘Like It’s 1994 Again’ Filming “Boy Meets World” (Exclusive) – Yahoo

    Jussie Smollett Claims He Was ‘Disrespected’ on the ‘Special Forces’ Season Premiere – Yahoo

    Jussie Smollett Opens Up About Feeling ‘Disrespected’ During the ‘Special Forces’ Season Premiere

    TicketSmarter Fall Entertainment Guide – Eastern Illinois University Athletics

    TicketSmarter Fall Entertainment Guide – Eastern Illinois University Athletics

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    STELLA Automotive AI Appoints Fred Seidelman as Chief Technology Officer – Yahoo Finance

    STELLA Automotive AI Appoints Fred Seidelman as New Chief Technology Officer

    Saving Energy and Money with Smart Technology – Terms of Service with Clare Duffy – Podcast on CNN Podcasts – CNN

    Saving Energy and Money with Smart Technology – Terms of Service with Clare Duffy – Podcast on CNN Podcasts – CNN

    Four Strategic Signals Technology Leaders Are Tuning In To – SPONSOR CONTENT FROM ARM – Harvard Business Review

    Four Essential Strategic Signals Every Technology Leader Should Watch

    Virginia Tech hosts annual New Music + Technology Festival this week – Cardinal News

    Virginia Tech Kicks Off Exciting Annual New Music and Technology Festival This Week

    Why I gave the world wide web away for free | Tim Berners-Lee – The Guardian

    Why I Decided to Make the World Wide Web Free for Everyone | Tim Berners-Lee

    From shale to steam: Fossil fuel technology boosts clean geothermal energy – Washington Examiner

    From Shale to Steam: How Fossil Fuel Technology is Powering a Clean Geothermal Energy Revolution

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Penn State-Themed Restaurant and Entertainment Spot Happy Valley Live Set to Open in State College – StateCollege.com

    Penn State-Themed Restaurant and Entertainment Spot Happy Valley Live Set to Open in State College – StateCollege.com

    The Police Made Chart History With This 1979 Hit Nearly 50 Years Ago – Yahoo

    How The Police Changed Music Forever with Their Iconic 1979 Hit Nearly 50 Years Ago

    Good Deed Entertainment Acquires Worldwide Rights To Liza Mandelup’s Documentary ‘Caterpillar’ – Deadline

    Good Deed Entertainment Lands Global Rights to Liza Mandelup’s Captivating Documentary ‘Caterpillar

    Danielle Fishel Explains Why Being on “DWTS” Makes Her Feel ‘Like It’s 1994 Again’ Filming “Boy Meets World” (Exclusive) – Yahoo

    Danielle Fishel Explains Why Being on “DWTS” Makes Her Feel ‘Like It’s 1994 Again’ Filming “Boy Meets World” (Exclusive) – Yahoo

    Jussie Smollett Claims He Was ‘Disrespected’ on the ‘Special Forces’ Season Premiere – Yahoo

    Jussie Smollett Opens Up About Feeling ‘Disrespected’ During the ‘Special Forces’ Season Premiere

    TicketSmarter Fall Entertainment Guide – Eastern Illinois University Athletics

    TicketSmarter Fall Entertainment Guide – Eastern Illinois University Athletics

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    STELLA Automotive AI Appoints Fred Seidelman as Chief Technology Officer – Yahoo Finance

    STELLA Automotive AI Appoints Fred Seidelman as New Chief Technology Officer

    Saving Energy and Money with Smart Technology – Terms of Service with Clare Duffy – Podcast on CNN Podcasts – CNN

    Saving Energy and Money with Smart Technology – Terms of Service with Clare Duffy – Podcast on CNN Podcasts – CNN

    Four Strategic Signals Technology Leaders Are Tuning In To – SPONSOR CONTENT FROM ARM – Harvard Business Review

    Four Essential Strategic Signals Every Technology Leader Should Watch

    Virginia Tech hosts annual New Music + Technology Festival this week – Cardinal News

    Virginia Tech Kicks Off Exciting Annual New Music and Technology Festival This Week

    Why I gave the world wide web away for free | Tim Berners-Lee – The Guardian

    Why I Decided to Make the World Wide Web Free for Everyone | Tim Berners-Lee

    From shale to steam: Fossil fuel technology boosts clean geothermal energy – Washington Examiner

    From Shale to Steam: How Fossil Fuel Technology is Powering a Clean Geothermal Energy Revolution

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Business

A Disturbing Trend in Ransomware Attacks: Legitimate Software Abuse

July 21, 2023
in Business
A Disturbing Trend in Ransomware Attacks: Legitimate Software Abuse
Share on FacebookShare on Twitter

When discussing ransomware groups, too often the focus is on their names, such as Noberus, Royal or AvosLocker, rather than the tactics, techniques, and procedures (TTPs) used in an attack before ransomware is deployed. For example, the particularly heavy use of legitimate software tools in ransomware attack chains has been notable in recent times. In fact, we rarely see a ransomware attack that doesn’t use legitimate software.

Staying Under the Radar: Why Abuse Is Rampant

Ransomware attacks remain a major cybersecurity problem. Ransomware actors, like threat actors in general, are abusing legitimate software for a number of reasons. First is a desire for stealthiness — they’re trying to get into and out of networks as quickly as possible without being discovered. Leveraging legitimate software can allow attackers’ activity to remain hidden, which may allow them to achieve their goals on a victim network without being discovered. Legitimate software misuse also can make attribution of an attack more difficult, and these tools can also lower barriers to entry. This means less-skilled hackers may still be able to conduct quite wide-ranging and disruptive attacks.

The legitimate tools we most commonly see being used by malicious actors are remote monitoring and management (RMM) tools, such as AnyDesk, Atera, TeamViewer, ConnectWise, and more. In fact, the use of RMM software by malicious actors was considered serious enough for the Cybersecurity and Infrastructure Security Agency (CISA) to issue an alert about this kind of. As recently as February this year, the Symantec Threat Hunter team saw ConnectWise used in both Noberus and Royal ransomware attacks. These tools are commonly used legitimately by IT departments in small, midsize, and large organizations.

Rclone, a legitimate tool for managing content in the cloud, was also used in a Noberus attack recently. In this particular case, attackers used Rclone to exfiltrate files because their earlier attempt to exfiltrate data, using their own custom ExMatter tool, had failed because it was blocked by security software.

AdFind, a legitimate free command-line query tool that can be used for gathering information from Active Directory, is also frequently used by ransomware attackers, who use it to map a network. PDQ Deploy, a tool that sysadmins use to apply patches, is also often abused by attackers, who use it to drop scripts onto victim networks quite efficiently. It’s not just legitimate tools that are used for malicious purposes by ransomware actors. For example, multiple state-sponsored groups have used legitimate cloud infrastructure such as Google Drive, Dropbox, OneDrive, and others for command-and-control (C&C) infrastructure and to exfiltrate and store stolen data.

Stay Vigilant

Attacks that leverage legitimate software and infrastructure present a particular challenge for both defenders and organizations. A blunt-instrument approach such as blocking the service or tool doesn’t work in these kinds of cases.

And this problem isn’t going away. With every new technology, bad actors will find a way to use it for their own nefarious purposes. For example, a few years ago the cloud wasn’t necessarily a big feature in many organizations. Now, obviously, as more data is moving to the cloud, the infrastructure itself is being used for malicious means, and legitimate tools for use in the cloud, such as Rclone, are being misused by attackers.

To reduce the risk of misuse of legitimate software, organizations should take the following steps:

Improve visibility: The old approach of simply detecting, blocking, and deleting malicious files is no longer sufficient to protect your organization in a cyber-threat landscape where legitimate tools, dual-use tools, and legitimate infrastructure are increasingly being used by malicious actors. Organizations need to have a comprehensive view of their network — they need to know what software is installed on their networks. If unauthorized legitimate tools are found, treat that discovery with the highest priority.

Implement least privilege: User permissions should be kept to a minimal level, without impacting user experience, so that if an attacker gains access to a machine or account, it doesn’t mean they can necessarily spread widely across the network, or that they can access everything that’s on the computer, or the network.

Go beyond malware detection: Since bad actors are often leveraging legitimate software, it’s important that organizations use a security solution that can detect and analyze suspicious behavior — and stop it. Vigilance within an organization is also key. You need to build a culture of security at your organization so that everyone is on the lookout for any kind of suspect behavior that might occur.

To read more from the Threat Hunter team at Broadcom go here: https://symantec-enterprise-blogs.security.com/blogs/

About Brigid O’Gorman:

O’Gorman

Brigid O’Gorman is a Senior Intelligence Analyst on the Symantec Enterprise Threat Hunter Team, part of Broadcom. She works with other security experts within Symantec to investigate targeted attacks, ransomware and other cybercrime. The team drives enhanced protection in Symantec products, and offers analysis and insights to help customers and more respond to malicious attacks.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : CIO – https://www.cio.com/article/645393/a-disturbing-trend-in-ransomware-attacks-legitimate-software-abuse.html

Tags: businessDisturbingTrend
Previous Post

How SAP changed Carl Zeiss AG’s view of optical product manufacturing

Next Post

Banking on customer experience and security via technology-based innovation

Atlanta Braves Manager Brian Snitker Moving to ‘Advisory Role’ – FOX Sports

Atlanta Braves Manager Brian Snitker Moving to ‘Advisory Role’ – FOX Sports

October 1, 2025
The sleepy SF neighborhood that just became one of the world’s coolest – SFGATE

The sleepy SF neighborhood that just became one of the world’s coolest – SFGATE

October 1, 2025
The “stuck economy,” tariffs and Wall Street – marketplace.org

How Tariffs and Wall Street Are Strangling the Economy’s Growth

October 1, 2025
LSU Theatre’s season opener: A handkerchief discovered by a lovesick suitor adds up to hilarity – The Advocate

Love, Laughter, and a Lost Handkerchief: LSU Theatre’s Season Opener Promises Hilarious Fun

October 1, 2025
Rural Health Transformation (RHT) Program – Centers for Medicare & Medicaid Services | CMS (.gov)

Rural Health Transformation (RHT) Program – Centers for Medicare & Medicaid Services | CMS (.gov)

October 1, 2025
Ex-NATO head on Russia: ‘We cannot change Putin’s mind’ – DW

Ex-NATO head on Russia: ‘We cannot change Putin’s mind’ – DW

October 1, 2025
PFAS in East Selah drinking water – Washington State Department of Ecology (.gov)

Alarming PFAS Contamination Discovered in East Selah Drinking Water

October 1, 2025
Science Expo – Northern Public Radio

Discover the Wonders of Science at the Exciting Expo!

October 1, 2025
Science and artificial intelligence could help personalize brain stimulation for smokers – News-Medical

How Science and AI Are Transforming Personalized Brain Stimulation to Help Smokers Quit

October 1, 2025
Review: What’s good at new prime-cuts steakhouse in Virginia Beach – Yahoo

Review: What’s good at new prime-cuts steakhouse in Virginia Beach – Yahoo

October 1, 2025

Categories

Archives

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (845)
  • Economy (866)
  • Entertainment (21,740)
  • General (17,348)
  • Health (9,910)
  • Lifestyle (879)
  • News (22,149)
  • People (868)
  • Politics (877)
  • Science (16,076)
  • Sports (21,367)
  • Technology (15,849)
  • World (849)

Recent News

Atlanta Braves Manager Brian Snitker Moving to ‘Advisory Role’ – FOX Sports

Atlanta Braves Manager Brian Snitker Moving to ‘Advisory Role’ – FOX Sports

October 1, 2025
The sleepy SF neighborhood that just became one of the world’s coolest – SFGATE

The sleepy SF neighborhood that just became one of the world’s coolest – SFGATE

October 1, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version