Cybersecurity professionals report that 82% of attacks now involve counter incident response (IR) with destructive attacks — often the final stage of counter IR — happening 54% of the time, according to VMware Carbon Black’s latest Global Incident Response Threat Report.

“Counter incident response is increasing as the adversaries become more punitive, and they’re fighting back to maintain persistence,” said Tom Kellermann, head of cybersecurity strategy at VMware Carbon Black.

Kellermann described counter IR as a “knife fight” with the attacker, which is very likely a sophisticated criminal with nation-state backing. “When counter incident response truly escalates to the Nth level, they’ve leveraged ransomware, NotPetya style, in your environment to punish you, just to cripple you, lock you up without placing any demands for ransom.”

New Worst-Case Cybersecurity Scenario

And the worst-case scenario from these attacks isn’t just theft anymore, he added. “Now they want to take over your entire brand, your entire digital presence, and use it to attack your customers,” Kellermann said. In fact, the report found that 55% of cyberattacks target the victim’s digital infrastructure for the purpose of island hopping. This involves attackers exploiting one businesses’ weakness and then moving laterally to target their partners, suppliers, and customers.

“So the game has changed in terms of worst-case scenario, but also in terms of the long-term efforts of the adversary, which are much more focused on home invasion slash colonization of your infrastructure versus just pillaging your secrets or moving your money,” Kellermann said.

Kellermann also serves on the U.S. Secret Service’s inaugural Cyber Investigations Advisory Board. This is a 16-member advisory committee, formed last month, to provide outside guidance to the Secret Service’s cyber investigations. The board calls these hacker groups “cybercrime cartels,” Kellermann said, “because they operate like cartels. Look at the business partnership between Maze and Ragnar Locker. Look at how REvil is offering up a million dollars for people to create the ultimate piece of ransomware. Look at how modern ransomware has 14 evasion modules built into it on average. All these things really highlight the industrialization of eCrimes.”

These are highly sophisticated, well-financed groups with the know-how, time, and resources to colonize victims’ networks. And they are taking advantage of the COVID-19 crisis to infiltrate organizations’ environments.

IR and Election Cybersecurity

For this report, VMware Carbon Black conducted an online survey about trends in incident response and election security in September. Eighty-three incident response and cybersecurity professionals from around the world participated.

Cybercriminals have been taking advantage of global fear and anxiety related to the COVID-19 pandemic plus a newly remote workforce relying on digital technology and online networks. And now the U.S. presidential election presents another business opportunity for attackers.

VMware Cabon Black’s sixth Global Incident Response Threat Report found almost half (49%) of cybersecurity professionals named government as the industry most targeted by attacks, while media and entertainment, which can also be leveraged for election-related hacks, was named by 42% of respondents. VMware Carbon Black says these percentages are roughly double the findings from the August report.

Counter IR can take many forms including deleting logs, manipulating time stamps, and using ransomware for destructive attacks. “It’s a very Russian playbook, and as evidenced by the indictments this morning, it highlights that awe should be concerned with ransomware attacks that are leveraged against state and local electoral systems,” Kellermann said. He’s referring to a federal grand jury that charged six hackers, all military intelligence officers in Russia’s GRU with carrying out several massive attacks. In addition to the NotPetya malware, this includes the Petya ransomware used against Ukraine in 2015 as well as attacks against the French elections in 2017 and the 2018 winter Olympics. This is the same group that hacked the Democratic National Committee and Hillary Clinton’s presidential campaign in 2016.

Election Disinformation, Ransomware Attacks

Cities, towns, and companies that sell voting and election system software have already seen Russian-style ransomware attacks ahead of the 2020 presidential election next month, and security officials warn that these may increase in severity and scope on or around election day. “And more importantly, these ransomware attacks could very well emanate from the technology service providers who are servicing those [voting and election systems], because island hopping has become the vector of choice for most large-scale campaigns,” Kellermann said. “I’m more concerned with disinformation. They’re gonna commandeer media outlets and journalists’ profiles and use them to spread disinformation — if not spread malware as well.”

The survey asked respondents what type of election-related attack they were most concerned about, and misinformation/disinformation (27%) topped the list. Ransomware (20%) came in second, followed by voter manipulation or fraud (20%) and voter disenfranchisement via an integrity attack on rolls (18%).

Of the various ways for attackers to disrupt the election process, Kellermann said disinformation is the most likely to be successful. Last month the FBI and Cybersecurity and Infrastructure Security Agency released a joint warning alerting the public about the potential threat posed by disinformation campaigns designed to cast doubt about the legitimacy of the election.

“But disenfranchisement is the one that is most concerning to me,” Kellermann added. “Which is why I think mail-in voting and early voting is an imperative. Any adversary that’s going to start to manipulate the integrity of voter rolls specific to party affiliation to benefit one candidate or another is going to do so more than likely like the week before the election itself, and hopefully most Americans will have voted by then.”

How to Secure the Vote

However, there are ways to fight back, and the report provides things that defenders can do to help secure the vote as well as best practices for threat hunting in general. Specific to disinformation on social media: the platforms themselves should be developed or co-developed by the social media companies themselves. To protect the voting infrastructure against ransomware and other malware attacks, security teams should implement next-generation antivirus software and email security tools should include attachment detonation, secure access server edge (SASE), web application firewall, and network detection and response (NDR) to reduce the likelihood of the attack being delivered and internally spread.

Hardening legacy election systems requires “vulnerability management, coupled with microsegmentation, coupled with regular cyber threat hunting to ensure that there isn’t some sort of [attacker] point of presence that already exists,” Kellermann said. “And then pursuing a strategy of robust application control for the applications that govern the interface with those systems is going to be fundamental to that your success in securing those systems.”

Threat-Hunting Best Practices

For IR professionals, the report recommends five threat-hunting best practices. This includes assuming the attacker already has multiple avenues into the organization and waiting to strike only after determining the scope and breadth of the intrusion.

“I’m really focused on the telemetry associated with evasion techniques and persistence techniques. How would you actually detect and respond to an adversary unbeknownst to an adversary,” Kellermann said. “As you can see from this report, the adversaries are becoming more punitive. The second they feel like you are on to them, they’re going to react viscerally. And your worst-case scenario again, would be for your infrastructure to be used to launch destructive attacks against your customers.”

Additionally network segmentation is vital — especially as people work from home because of COVID-19 — and so is the capacity to detect and respond to attacks across workloads running in clouds, containers, and microservices.

XDR is a real thing,” Kellermann said. “And it’s really about connecting security controls and building that in.”