{"id":27170,"date":"2016-12-02T13:15:41","date_gmt":"2016-12-02T05:15:41","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=27170"},"modified":"2016-12-02T13:15:41","modified_gmt":"2016-12-02T05:15:41","slug":"kaspersky-labs-top-threat-predictions-2017","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2016\/12\/02\/kaspersky-labs-top-threat-predictions-2017\/","title":{"rendered":"Kaspersky Lab&#8217;s top threat predictions for 2017"},"content":{"rendered":"<p id=\"yui_3_16_0_1_1480080349391_167150\" dir=\"ltr\"><strong><span id=\"yui_3_16_0_1_1480080349391_167149\">Kaspersky Lab\u2019s discovery in 2016 of an APT able to create new tools for each victim has effectively killed off \u2018Indicators of Compromise\u2019 as a reliable means of detecting infection, according to the company\u2019s Threat Predictions for 2017. \u00a0<\/span><\/strong><\/p>\n<p id=\"yui_3_16_0_1_1480080349391_167154\" dir=\"ltr\"><span id=\"yui_3_16_0_1_1480080349391_167153\"><img loading=\"lazy\" decoding=\"async\" id=\"yui_3_16_0_1_1480080349391_167152\" class=\"aligncenter\" src=\"https:\/\/lh6.googleusercontent.com\/JpgYsNELbmrkhibmhrUZm0Z_BdUcItuiq1aW6h2n9DhhSSsb9iyn0oIbPv0LCv1GT3PerPFxThyleqISGBuXz4nSTnkc_LClBNT7SJ5A5mnPovPpUz9akXX-tKp8Q_s0K4xq8GM3\" alt=\"Kaspersky Lab_KSB Predictions 2017_1.jpg\" width=\"605\" height=\"437\" \/><\/span><\/p>\n<p id=\"yui_3_16_0_1_1480080349391_167211\" dir=\"ltr\"><span id=\"yui_3_16_0_1_1480080349391_167210\">The predictions are prepared annually by the company\u2019s expert Global Research and Analysis Team (GReAT) and are based on its wide-ranging insight and expertise.\u00a0 The list for 2017 includes the impact of bespoke and disposable tools, the growing use of misdirection in terms of attacker identity, the fragility of an indiscriminately Internet-connected world, and the use of cyberattacks as a weapon of information warfare.<\/span><\/p>\n<p dir=\"ltr\"><strong>The decline of IoCs<\/strong><\/p>\n<p dir=\"ltr\">Indicators of Compromise (IoCs) have long been an excellent way of sharing traits of known malware, allowing defenders to recognize an active infection. The discovery by GReAT of the <a href=\"https:\/\/securelist.com\/analysis\/publications\/75533\/faq-the-projectsauron-apt\/\" target=\"_blank\" rel=\"nofollow\">ProjectSauron APT<\/a> changed this. Analysis of the group revealed a bespoke malware platform where every feature was altered for each victim, rendering IoCs unreliable for detecting any other victim, unless accompanied by another measure, such as strong Yara rules.<\/p>\n<p dir=\"ltr\"><strong>The rise of ephemeral infections<\/strong><\/p>\n<p dir=\"ltr\">In 2017, Kaspersky Lab also expects to see the appearance of memory-resident malware that has no interest in surviving beyond the first reboot that will wipe the infection from the machine memory. Such malware, intended for general reconnaissance and the collection of credentials, is likely to be deployed in highly sensitive environments by stealthy attackers keen to avoid arousing suspicion or discovery.<\/p>\n<p id=\"yui_3_16_0_1_1480080349391_167203\" dir=\"ltr\"><span id=\"yui_3_16_0_1_1480080349391_167202\"><img loading=\"lazy\" decoding=\"async\" id=\"yui_3_16_0_1_1480080349391_167201\" class=\"aligncenter\" src=\"https:\/\/lh5.googleusercontent.com\/dyEP4FTB-0rEMhwzp56SucSWjK68N05OUNJOYEqSncZDifsoMvec9f1PhRSBPG68g6o_w-PHBrJSk6xtO8zE3hPKBPgZ_7kJcsLJBsCjQKGitj88bgaC1YGWwfOeU3S2shfuWz_B\" alt=\"Kaspersky Lab_KSB Predictions 2017_2.jpg\" width=\"605\" height=\"437\" \/><\/span><\/p>\n<p id=\"yui_3_16_0_1_1480080349391_167408\" dir=\"ltr\">\u201cThese are dramatic developments, but defenders will not be left helpless. We believe that it is time to push for the wider adoption of good Yara rules.\u00a0 These will allow researchers to scan far-and-wide across an enterprise, inspect and identify traits in binaries at rest, and scan memory for fragments of known attacks. Ephemeral infections highlight the need for proactive and sophisticated heuristics in advanced anti-malware solutions,\u201d <span id=\"yui_3_16_0_1_1480080349391_167407\">said Juan Andr\u00e9s Guerrero-Saade, Senior Security Expert, Global Research and Analysis Team.<\/span><\/p>\n<h2 id=\"yui_3_16_0_1_1480080349391_167405\" dir=\"ltr\"><span id=\"yui_3_16_0_1_1480080349391_167410\">Other Top Threat Predictions for 2017<\/span><\/h2>\n<ul id=\"yui_3_16_0_1_1480080349391_167401\">\n<li id=\"yui_3_16_0_1_1480080349391_167400\" dir=\"ltr\">\n<p id=\"yui_3_16_0_1_1480080349391_167399\" dir=\"ltr\"><span id=\"yui_3_16_0_1_1480080349391_167403\">Attribution will flounder among false flags: <\/span><span id=\"yui_3_16_0_1_1480080349391_167398\">As cyberattacks come to play a greater role in international relations, attribution will become a central issue in determining a political course of action \u2013 such as retaliation.\u00a0 The pursuit of attribution could result in the risk of more criminals dumping infrastructure or proprietary tools on the open market, or opting for open-source and commercial malware, not to mention the widespread use of misdirection (generally known as false flags) to muddy the waters of attribution. <\/span><\/p>\n<\/li>\n<li id=\"yui_3_16_0_1_1480080349391_167437\" dir=\"ltr\">\n<p id=\"yui_3_16_0_1_1480080349391_167436\" dir=\"ltr\">The Rise of Information Warfare<span id=\"yui_3_16_0_1_1480080349391_167435\">: In 2016, the world started to take seriously the dumping of hacked information for aggressive purposes.\u00a0 Such attacks are likely to increase in 2017, and there is a risk that attackers will try to exploit people\u2019s willingness to accept such data as fact by manipulating or selectively disclosing information.<\/span><\/p>\n<\/li>\n<li id=\"yui_3_16_0_1_1480080349391_167440\" dir=\"ltr\">\n<p id=\"yui_3_16_0_1_1480080349391_167439\" dir=\"ltr\">Alongside this, Kaspersky Lab expects to see a rise in Vigilante Hackers \u2013 hacking and dumping data, allegedly for the greater good.<\/p>\n<\/li>\n<li id=\"yui_3_16_0_1_1480080349391_167444\" dir=\"ltr\">\n<p id=\"yui_3_16_0_1_1480080349391_167443\" dir=\"ltr\">Growing Vulnerability to Cyber-sabotage: <span id=\"yui_3_16_0_1_1480080349391_167442\">As critical infrastructure and manufacturing systems remain connected to the Internet, often with little or no protection \u2013 the temptation to damage or disrupt them could prove overwhelming for cyberattackers, particularly those with advanced skills, and during times of rising geopolitical tension. <\/span><\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">Espionage Goes Mobile: Kaspersky Lab expects to see more espionage campaigns targeted primarily at mobile, benefiting from the fact that the security industry can struggle to gain full access to mobile operating systems for forensic analysis.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">The Commoditization of Financial Attacks: Kaspersky Lab expects to see the \u2018commodification\u2019 of attacks along the lines of the 2016 SWIFT heists in 2016 \u2013 with specialized resources being offered for sale in underground forums or through as-a-service schemes.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">The Compromise of Payment Systems: As payment systems become increasingly popular and common, Kaspersky Lab expected to see this matched by a greater criminal interest.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">The Breakdown of \u2018Trust\u2019 in Ransomware: Kaspersky Lab also anticipates the continuing rise of ransomware, but with the unlikely trust relationship between the victim and their attacker \u2013 based on the assumption that payment will result in the return of data &#8211; damaged as a lesser grade of criminal decides to enter the space. This could be the turning point in people being prepared to pay up.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">Device Integrity in an Over-crowded Internet: As IoT-device manufacturers continue to pump out unsecured devices that cause wide-scale problems, there is a risk that vigilante hackers could take matters into their own hands and disable as many devices as possible.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\">The Criminal Appeal of Digital Advertising: Over the next year, we will see the kind of tracking and targeting tools increasingly used in advertising being used to monitor alleged activists and dissidents. Similarly, ad networks &#8211; which provide excellent target profiling through a combination of IPs, browser fingerprinting, browsing interest and login selectivity \u2013 will be used by advanced cyberespionage actors keen to precisely hit targets while protecting their latest toolkits.<\/p>\n<\/li>\n<\/ul>\n<p dir=\"ltr\" style=\"text-align: center;\"><em>The full text of the report \u201cKaspersky Lab Threat Predictions for 2017\u201d is available <a href=\"https:\/\/securelist.com\/analysis\/kaspersky-security-bulletin\/76660\/kaspersky-security-bulletin-predictions-for-2017\" target=\"_blank\" rel=\"nofollow\">on Securelist<\/a>.<\/em><\/p>\n<p id=\"yui_3_16_0_1_1480080349391_167495\" dir=\"ltr\" style=\"text-align: center;\"><em><span id=\"yui_3_16_0_1_1480080349391_167494\">To look back at what the Kaspersky Lab experts expected to see in 2016, please <\/span><a id=\"yui_3_16_0_1_1480080349391_167502\" href=\"https:\/\/securelist.com\/analysis\/kaspersky-security-bulletin\/72771\/kaspersky-security-bulletin-2016-predictions\/\" target=\"_blank\" rel=\"nofollow\"><span id=\"yui_3_16_0_1_1480080349391_167501\">read<\/span><\/a><span id=\"yui_3_16_0_1_1480080349391_167504\">. <\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab\u2019s discovery in 2016 of an APT able to create new tools for each victim has effectively killed off \u2018Indicators of Compromise\u2019 as a reliable means of detecting infection, according to the company\u2019s Threat Predictions for 2017.  <\/p>\n","protected":false},"author":6,"featured_media":27171,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[107,117,54,96],"class_list":["post-27170","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cloud","tag-kaspersky-lab","tag-security","tag-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=27170"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27170\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/27171"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=27170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=27170"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=27170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}