AT&T research suggests that the vast majority of large businesses believe widespread remote working because of the COVID-19 pandemic makes their companies less secure and more vulnerable to cyberattacks.
The survey of 800 security professionals across the United Kingdom, France, and Germany found while 88% initially felt well prepared for the mass work-from-home migration, 55% now say remote working makes their companies more or much more vulnerable to attacks. This figure jumps to 70% for large companies with more than 5,000 employees.
And, at least in this case, perception is reality. Remote workers and the systems they access are less secure these days, said AT&T Cybersecurity’s Jaime Blasco.
Blasco, a security researcher at AT&T Cybersecurity, leads the Alien Labs Intelligence and Research team. These are the ethical hackers who research and integrate threat intelligence into detection mechanisms.
“You look at especially Q2 and the beginning of Q3, and the amount of phishing campaigns using COVID-19 was crazy,” Blasco said. In fact, during March, as health officials declared a global pandemic and organizations began implementing telework policies, AT&T Alien Labs Open Threat Exchange platform saw a 2,000% month-over-month increase in COVID-related indicators of compromise.
One new trend that’s especially alarming is the spike in ransomware, Blasco added.
SonicWall’s mid-year threat report found a 20% (121.4 million attacks) jump in ransomware globally in the first half of 2020 compared to mid-year 2019, with a staggering 109% (80 million attacks) spike in the United States during that same period.
“The amount of ransomware campaigns right now is just unbelievable,” Blasco said. “And two trends are enabling this.”
Don’t Pay RansomsFirst: these campaigns work. “More companies are paying the ransom,” he said. This includes Garmin, which reportedly paid upwards of $10 million to cybercriminals after an attack took several of its services and products offline late last month. Sky News reported this week that Garmin obtained the decryption key to recover its files from the WastedLocker virus linked to Evil Corp, a cybercrime group based in Russia.
“And anytime that happens, you have more of these groups saying 'hey, this is actually something that we can keep doing because it’s very lucrative for us,'” Blasco said, noting that WastedLocker in particular is on the rise along with Netwalker, REvil, and Maze ransomware.
Paying these ransoms “is a terrible thing for companies to do, for them but also for the industry because it makes the problem bigger,” Blasco said. “My recommendation is: get on the phone and call your local FBI office. On top of that, if you have a cybersecurity provider or a [managed security services] provider, they can work with you and give you advice in terms of what to do next.”
However, the other piece enabling successful (and lucrative) ransomware attacks comes back to remote workers, Blasco added. “They have been exploiting a lot of the recent vulnerabilities in remote access tools, gateways, VPNs,” he said, noting the high-profile flaws in F5 Networks’, Citrix, and Pulse Secure devices. “The minute that there is a publicly available code that they can use” or buy on the dark web or develop themselves, cybercriminals will exploit the software vulnerability.
How to Secure Remote WorkforcesAT&T’s survey found a large minority of businesses have not taken basic steps to secure a suddenly remote workforce. One quarter have not offered additional cybersecurity training for employees; 24% have not created secure gateways to applications hosted in the cloud or in a data center; 22% have not increased endpoint security to protect laptops and mobile phones; and 17% have not implemented internet browsing protection from web-based threats.
“It is really important that as companies enable remote working, they pay a lot of attention to the cybersecurity side of things before they deploy these remote access tools,” Blasco continued. “Make sure the software is up to date, make sure you do a risk assessment, enable two-factor authentication.”
Attackers aren’t just exploiting security flaws, they are also using stolen credentials to access corporate networks and assets. “So it’s really important that you enable multi-factor authentication,” Blasco said. “Otherwise, it’s very likely you’re gonna get in trouble.”
Comments