{"id":35077,"date":"2019-05-07T07:51:28","date_gmt":"2019-05-06T23:51:28","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35077"},"modified":"2019-05-07T07:54:58","modified_gmt":"2019-05-06T23:54:58","slug":"geopolitics-south-east-asian-targets-power-threat-activity-in-q1-as-the-big-players-stay-quiet","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/05\/07\/geopolitics-south-east-asian-targets-power-threat-activity-in-q1-as-the-big-players-stay-quiet\/","title":{"rendered":"Cyber attacks focused on geopolitics, South East Asia in Q1"},"content":{"rendered":"<p>In the first three months of 2019, Kaspersky Lab researchers observed an active landscape of advanced threat operations that was centered mainly on South East Asia, increasingly influenced by geopolitics, and which featured cryptocurrency and commercial spyware attacks as well as a major supply-chain campaign. These and other trends are covered in Kaspersky Lab\u2019s latest quarterly threat intelligence summary.<\/p>\n<p>The quarterly APT trends summary is drawn from Kaspersky Lab\u2019s private threat intelligence research, as well as from other sources, and highlights the main developments that researchers believe everyone should be aware of.<\/p>\n<p>In the first quarter of 2019, Kaspersky Lab researchers observed a number of interesting new developments. The defining APT campaign reported during the quarter was operation ShadowHammer: an advanced, targeted campaign using the supply-chain for distribution on an incredibly wide scale, combined with carefully implemented techniques for the precision targeting of intended victims.<\/p>\n<p>Further APT highlights in Q1, 2019 include:<\/p>\n<p>\u2022\tGeopolitics featured as a key driver of APT activity \u2013 with often a clear correlation between political developments and targeted malicious activity.<\/p>\n<p>\u2022\tSouth East Asia remained the most frenetically active region of the world in terms of APT activity, with more groups, more noise, and more sets of activity targeting the region than elsewhere.<\/p>\n<p>\u2022\tRussian-speaking groups kept a low profile in comparison with recent years. This could be due to an element of internal restructuring, although there remained a steady drumbeat activity and malware distribution by Sofacy and Turla.<\/p>\n<p>\u2022\tChinese-speaking actors continued to maintain a high level of activity, combining both low and high sophistication depending on the campaign. For example, the group known to Kaspersky Lab as CactusPete, active since 2012, was observed in Q1 with new and updated tools, including new variants of downloaders and backdoors and an appropriated and then repackaged VBScript zero-day belonging to the DarkHotel group. &nbsp;<\/p>\n<p>\u2022\tProviders of \u201ccommercial\u201d malware available to governments and other entities seem to be thriving; researchers observed a new variant of FinSpy in the wild, as well as a LuckyMouse operation deploying leaked HackingTeam tools.<\/p>\n<p>\u201cLooking back at what has happened during a quarter is always a surprising experience. Even when we have the feeling that \u201cnothing groundbreaking\u201d has occurred, we uncover a threat landscape that is full of interesting stories and evolution on different fronts \u2013 including, in Q1, sophisticated supply chain attacks, attacks on cryptocurrency and geopolitical drivers. We know that our visibility is not complete, and there will be activity that we do not yet see or understand, so just because a region or sector doesn\u2019t appear on our threat intelligence radar today doesn\u2019t mean it won\u2019t in the future. Protection against both known and unknown threats remains vital for everyone,\u201d said Vicente Diaz, Principal Security Researcher, Global Research and Analysis Team, Kaspersky Lab.<\/p>\n<p>The APT trends report for Q1 summarizes the findings of Kaspersky Lab\u2019s subscriber-only threat intelligence reports, which also include Indicators of Compromise (IOC) data and YARA rules to assist in forensics and malware-hunting.<\/p>\n<p>In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky Lab researchers recommend implementing the following measures:<\/p>\n<p>\u2022\tProvide your SOC team with access to the latest Threat Intelligence, to keep up to date with the new and emerging tools, techniques and tactics used by threat actors and cybercriminals.<\/p>\n<p>\u2022\tFor endpoint level detection, investigation and timely remediation of incidents, implement EDR solutions such as&nbsp;Kaspersky Endpoint Detection and Response.<\/p>\n<p>\u2022\tIn addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as&nbsp;Kaspersky Anti Targeted Attack Platform.<\/p>\n<p>\u2022\tAs many targeted attacks start with phishing or other social engineering technique, introduce security awareness training and teach practical skills, for example through the Kaspersky Automated Security Awareness Platform.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the first three months of 2019, Kaspersky Lab researchers observed an active landscape of advanced threat operations that was centered mainly on South East Asia, increasingly influenced by geopolitics, and which featured cryptocurrency and commercial spyware attacks as well as a major supply-chain campaign. These and other trends are covered in Kaspersky Lab\u2019s latest [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":35076,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,117],"class_list":["post-35077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky-lab"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35077"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35077\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/35076"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35077"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}