| 3 minute read

Russian Cyberthreats: Steps to Take to Protect Your Business

russia on globe

In early 2022, the US Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to all businesses and government entities on the risk of Russian cyberattacks affecting US systems and networks. Rob Lee, CEO of Dragos, indicates that his team has “observed threat groups that have been attributed to the Russian government by US government agencies performing reconnaissance against US industrial infrastructure, including key electric and natural gas sites in recent months.”

This week we’ve seen distributed denial-of-service (DDoS) attacks affecting government and financial institutions throughout Ukraine. Then, a second wave of attacks, including a sophisticated piece of malware referred to as “Wiper” was identified. Security experts at Symantec and ESET identified a timestamp of December 28, 2021, implying the stage for these attacks were set months in advance. And yesterday, February 24, 2022, when Russian president, Vladimir Putin, launched a large scale attack on Ukraine, the US government declared that it is on “high alert for the possibility of the conflict spilling over into cyberspace, where Russia has shown an ability to cause significant disruption and damage in the past.”

Some of Avalon’s clients have reached out to us asking what’s going on with the Russian cyberthreat landscape and what things they should be on the lookout for. I thought it would be important to curate a list of recommendations/suggestions you may want to consider as you continue to monitor your systems and networks for indicators of badness.

  1. Let’s start with the basics. When was the last time you performed a vulnerability assessment of your systems and networks? Poor patch and configuration management processes are low hanging fruit for adversaries. If you haven’t had one recently, it’s absolutely worth your time to do it again. Focus on remediating the critical and high vulnerabilities with known exploits first and then work your way down from there.

  2. Are you using multifactor authentication (MFA) on every authentication portal within your enterprise? If not, why not?! This is a fundamental security control that needs to be mandatory and implemented yesterday. Tools like Duo, Microsoft Authenticator, Authy, and Google Authenticator are all great products that are easy to implement. SMS for MFA is not a reliable method for validating authentication attempts.

  3. These days, having a security awareness program is critical. Make sure your users have been trained in identifying social engineering attacks, such as phishing, spear phishing, etc. Attackers generally target users to gain a foothold into internal domains. Teach users to identify malicious links by hovering over the link in a suspicious email to verify that the site is legitimate.

  4. Endpoint protection is a must-have, of course. However, the introduction of tools like endpoint detection and response (EDR) will give you enhanced visibility into what’s happening on your endpoints.

  5. Monitor egress on your firewalls. Looking for outbound established connections over protocols like http(s) and DNS is a great place to start. These protocols are typically used to communicate with command and control (C2) servers. Execution instructions and data exfiltration are commonly used here. Specifically, be on the lookout for anomalous DNS requests that have pseudo-random hexadecimal, binary, or Base64 characters.

  6. Yes, you will have legitimate business services and applications with established outbound connections. This includes file transfer systems, mail servers, and some web applications. However, the exception to this rule should be a small sample set. If you don’t know what those are today, a network discovery process could be in order.

  7. Geographical IP blocking is not always the way to go. Nation-states are certainly capable of spoofing your IP address. However, simply putting a block on one country won’t stop the bad guys from infiltrating your networks. Start implementing basic firewall hygiene and treat everything on the internet as hostile and trust what you know.  

  8. Know what normal executables are on your systems. Running applications within your enterprise is an important element to understanding your vulnerability landscape. This can be accomplished through numerous applications and technology processes. Using asset inventory tools, EDR technologies, and vulnerability scanners are great tools to help you determine what is on your systems. If none of these options are available to you, there are open-source tools that should be considered. Valuable details can be obtained from Windows System Resource Utilization Monitor (SRUM) as well. Here are two tools that may be helpful when interacting with Windows SRUM:
  9. Use AuditD or Sysmon for Linux if you don’t have EDR on your Linux systems. Here is a resource that will help you use Sysmon on Linux systems: https://t.co/wYoxNukrrd

  10. Dust off that incident response (IR) plan. Do a refresh and make sure your team is prepared to respond quickly. Also, is your insurance company prepared to assist in the event you need support ASAP? What about your digital forensics and incident response (DFIR) vendor or breach coach (outside counsel)? Make sure you have all these folks on speed dial!

  11. Improve the verbosity of your logs. For instance, by default, certain meaningful events are not tracked through logging. Evaluating best practices to ensure those events are being generated would be a helpful exercise.

  12. Perform threat hunting using whatever tools you have. Keep a close eye on threat intelligence through open-source forums. Look for behaviors, IPs, hashes, and applications consistent with behaviors identified by other security experts, known as indicators of compromise (IoC).

  13. If there are budget concerns, the Cybersecurity & Infrastructure Security Agency (CISA) has released a list of free services and tools to help bolster your defense-in-depth posture: https://www.cisa.gov/free-cybersecurity-services-and-tools

If you have any questions, contact the experts at Avalon. If you need immediate assistance, call our Incident Response line at 1.877.216.2511.

Blog Articles

The CDK Incident and Recommended Actions from Avalon Cyber

Thousands of car dealerships’ operations slowed to a halt last Wednesday as their core dealer management system, CDK, shut down. CDK Global announced that they were investigating a cyber incident and “Out of an abundance of caution and concern for our customers, we have shut down most of our systems and are working diligently to get everything up and running as quickly as possible” according to spokesperson, Lisa Finney. The company said later that day that most of their critical systems were back online, but the next day they announced that another incident had happened.

Get Ready for the New 36-Hour Cyber Breach Notification Rule for Financial Institutions

If you’re in the financial sector, no doubt you’ve already heard, and hopefully, are prepared or preparing for, the new federal banking rule regarding cyber breach notifications. This new rule, which took effect April 1, 2022, with full compliance required by May 1, 2022, requires banking organizations and bank service providers to notify banking regulators within 36 hours after a notification event, which is the tightest timeframe in U.S. history.

Cybercriminals Never Sleep (And Neither Do We)

According to the latest cybersecurity industry research, market demand for Managed Detection and Response (MDR) services continues to climb. In fact, experts forecast that by 2024, 40% of midsize enterprises will use MDR as their only managed security service. That might sound like a large percentage, but because of the continued escalation of cyberattacks, more and more companies are realizing the importance of hiring experts to boost their cybersecurity posture.