Cybercriminals, both organized criminal groups and Nation State Advanced Persistent Threat actor groups have been raising the stakeswithbanking Trojans. This malware primarily aims to steal the banking credentials of an organization or individual, usually moving silently in the background, waiting until victims go to access their personal or corporate financial accounts. At that point, credentials are captured through a variety of means and ultimately funds are drained, paychecks are diverted, fraudulent transactions occur, etc.
In recent months, however, banking Trojan variants such as emotet, Trickbot, ICE-ID, Qakbot, and others have been crippling companies, schools and government networks around the world. The newest strains don’t stop at bank-related fraud; somejoin with other malware as secondary and tertiary payload drops into infected networks to saturate victims with unauthorized remote access looking for additional information to steal and can severely disrupt business. Some infected victims become part of a larger botnet and in recent months, Kroll has observed actor groups maturing their tactics and moving to deploy ransomware post network saturation as both a means to cover their tracks and to further monetize their intrusion through ransomware payments.
Organizations should be prepared with a diversified defense that blends “back to the basics” security with advanced threat monitoring and response capabilities.
Employee education and awareness still key for defense
For the most part, banking Trojans are unwittingly and unknowingly welcomed into networks by users at all levels of the organization. Many of the strategies used by fraudsters are not new and include:
• Social engineering attacks, including phishing (email), vishing (voicemail) and smishing (mobile messaging), where victims most often click on infected links
• Email attachments that contain macro viruses (i.e., maldocs)
• Compromised Internet ad campaigns
• “Drive-by” attacks: users visit a website infected by malware that in turn infects users’ computers
While many organizations are getting better at educating employees about social engineering attacks, other enterprise priorities – such as delivering responsive client service – can work against caution. For example, Kroll recently worked an investigation where a supervisor at a financial services company received an email request from a business associate at another financial institution. Despite recognizing the request was somewhat out of character, the supervisor—who routinely works with financial information—opened the attachment expecting an invoice. The document was in fact a maliciously crafted document which triggered a chain of events on the endpoint that were invisible to the user.
As fraudsters become more sophisticated in crafting decoy messages, we recommend that organizations conduct more frequent training with staff at all levels, including executive leadership and boards of directors. Issuing regular bulletins that share examples of deceptive emails can also prove enlightening to employees. To gauge the effectiveness of their training programs, many enterprises are proactively making social engineering exercises part oftheir technical penetration testing programs. Annual training should be in addition table top exercises that involve the IT Security teams, the corporate staff, internal and external legal counsel and a third party incident response firm like Kroll Cyber Risk.
Be prepared with threat intelligence, endpoint monitoring and expert response
For many organizations, endpoint threat monitoring is part of their network protection arsenal, but next generation end point solutions are still evolving. Kroll regularly works with clients who have traditional AV solutions that have historically proved ineffective against polymorphic, bit-shifting, and process hollowing techniques.
While each banking Trojan is unique in the mechanisms it employs to inflict harm and further spread malware, the following simplified overview of the way we typically handle common banking trojans such as Emotet or Trickbotprovides a glimpse into the steps of an effective response:
• Kroll leverages our Endpoint Detection and Response (“EDR”) solution to combine forensic and incident response tools, threat intelligence feeds, human analysts, and client feedback about their own networks to identify and ban identified malware hashes (i.e., unique fingerprints of malicious processes or binaries) which terminates running processes and prevents subsequent execution. When deployed at an enterprise level, this gives us the ability to block the execution of malware network wide
• When necessary, Kroll can isolate infected systems to prevent data acquisition or exfiltration from client networks due to unauthorized access and network intrusions.
• Work with the client to identify and blockactor command and control (“C2”) IPs at the network perimeter
• Pull selected events to generate a timeline of infections and determine user accounts being utilized by malware for installation and/or spreading.
• Work with Client to reset domain and local user account credentials for all accounts known to have been used by the malware to spread (or at the appropriate time, performs an enterprise-wide password reset); also ensures all local administratoruser account passwords are unique.
• Ultimately, we create and deploy a custom remediation script to purge remaining malware artifacts.
Ubiquitous and persistent threat
The evolving nature of banking Trojans—and frankly, all types of malware—means that enterprises of all sizes can never let down their guard. In fact, there is no better time than now to ask yourself three questions:
1. Are we continually educating employees and leaders on realistic threat scenarios?
2. How are we testing our defenses and how regularly are we testing?
3. Do we have advanced resources to detect and eradicate threats?
With every day that goes by, cybercriminals are counting on you not to know. Get answers and take action today.