The Russian state-sponsored hacking group that attacked the Democratic National Committee and Hillary Clinton’s campaign in 2016 is back — not that it ever really left. And this year, according to Microsoft’s cyberthreat hunters, it’s joined by similar groups in China and Iran.
Microsoft last month warned that nation-state attackers have attacked hundreds of organizations and individuals associated with U.S. President Donald Trump's and Democratic challenger Joe Biden’s respective presidential campaigns.
Campaigns face particularly tough cybersecurity challenges because they essentially operate as large, distributed enterprises with thousands of full-time employees and volunteers, said ExtraHop CTO Jesse Rothstein.
“Right now, in 2020, they have the added difficulty that most of these people are working remotely,” Rothstein added. “The coronavirus has, in many ways, made the problem more difficult and expanded the threat landscape due to the added component of working from home. So these campaigns face an unprecedented challenge from a cybersecurity perspective.”
However, campaigns can — and should — take a page from enterprise security best practices to harden their defenses and hunt for threats in their environments. This includes taking the following actions, and, as Dmitriy Ayrapetov, VP of platform architecture at SonicWall said, ensuring that “everybody involved takes cybersecurity very seriously.”
Hire a CISOHiring a chief information security officer (CISO) is common sense for enterprise security, and it should be for campaign security, too.
Over the summer the Biden campaign hired Michigan Chief Security Officer Chris DeRusha as its CISO and also hired Jacky Chang, a former senior engineer from Hillary Clinton’s 2016 presidential campaign, as its CTO. “Biden for president takes cybersecurity seriously and is proud to have hired high-quality personnel with a diverse breadth of experience, knowledge, and expertise to ensure our campaign remains secure,” the campaign told Federal Computer Week. “Jacky and Chris will be central to strengthening the infrastructure we've built to mitigate cyber threats, bolster our voter protection efforts, and enhance the overall efficiency and security of the entire campaign.”
While it’s unclear if the Trump campaign hired a CISO, Rothstein applauded the Biden campaign’s hires. “A shout out to the Biden campaign,” he said. “It’s very clear that they made big investments in cybersecurity back in July when they hired very qualified individuals to both the CISO and CTO roles.”
Protect Campaign EmailSecurity best practices also include not using personal email for campaign business, which John Podesta — and hopefully every other large national campaign — learned the hard way back in 2016. “Email is the primary way for attackers to get in,” Ayrapetov said. “Campaigns have to get very sophisticated mail protection and that means being able to look for very evasive, very sophisticated malware.”
He noted a dire warning last week from the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) about the resurgence of the sophisticated Emotet malware. It’s an advanced Trojan primarily spread via phishing email attachments.
Earlier this month hundreds of organizations across the U.S. received emails purporting to be from the Democratic National Committee recruiting volunteers that was, in fact, an Emotet spear phishing campaign.
“There is a lot of phishing, which is exactly what happened in 2016,” Rothstein added. “And the attackers are using these sorts of email phishing attacks because they are very effective.”
Secure Remote AccessCampaign staffers and volunteers, just like the rest of us, are working from home these days. And that means secure remote access, whether via virtual private networks (VPNs) or zero-trust network access, is essential.
Rothstein pointed to a different CISA alert about a cyberthreat on a federal agency’s network in September. “It’s believed that the agency was compromised through a vulnerability in the VPN provider for remote access,” he said. “Everybody working remote increases the attack surface, and it introduces some additional threats.”
Another important piece of securing a remote, distributed campaign involves endpoint detection and response. “Assume that people are working in a distributed manner, they’re working from home, their machines have to be protected with advanced protection against these types of attacks,” Ayrapetov said. “And then after that, you get into segmenting the network.” Segmentation ensures that if a device is compromised, the malware or the attacker can’t spread to other devices and access additional data on the campaign’s network.
“We know that nation-states do target elections, and so if somebody does get compromised, make sure that there is isolation, segmentation, so a wildfire doesn’t burn to the entire organization but it is contained to a segment of the organization,” he explained.
Deploy Multi-Factor AuthenticationThe newly remote workforce needs to access cloud-based applications and services. Because of this, multi-factor authentication topped the list of security investments made during the pandemic, according to a recent Microsoft survey.
Campaigns should follow suit. “On every webinar, every call I advocate for multi-factor authentication — and we’re a vendor that doesn’t sell multi-factor authentication,” Ayrapetov said. “It is the biggest bang for the buck that can be turned on across all modern cloud services. Not turning it on is extremely negligent from a cybersecurity perspective at this point.”
Invest in Threat Detection and ResponseIf there’s one lesson that campaigns should learn from enterprise security, it’s that even a layered defense strategy alone isn’t sufficient, Rothstein said. “Sooner or later attackers do find a way in,” he said. “And this is why most organizations have recognized that when they think about compromises, it’s really a matter of when, not if.”
While campaigns should invest in a layered, in-depth security strategy, they should also invest in threat detection and response, Rothstein added. “If an attacker does find their way into your environment, you need to very quickly detect this to limit the dwell time — that’s how long they spend in your environment undetected — and then limit the blast radius.”
Comments