How Do Lean Hackers Scale Attacks at Lower Cost?

246 views
•
April 8, 2014
by
RSAC Cybersecurity
YouTube video player
How Do Lean Hackers Scale Attacks at Lower Cost?

TL;DR

Attackers increase profits and reduce effort by compromising popular websites, exploiting social networks, automating fake accounts, and moving infrastructure to hosted cloud services. Effective defense requires watching trusted sites, browser-based infections, social platform features, and realistic duplicate accounts because attackers continually adapt their distribution and monetization tactics when platforms impose restrictions.

Transcript

Thank you. I'm, I'm Paul Judge, and I'm Chief Research Officer at Barracuda Labs. And we spend our, our time, you know, looking what attackers are doing around the world, showing up at the doorsteps of our customers. And what I wanna spend time on today is some of the, the tactics of, of the attackers shifting and doing what I think of as, as lean ... Read More

Key Insights

  • Lean hacking is a business-oriented approach in which attackers seek higher revenue, lower costs, broader reach, and less work by adopting efficiency practices similar to those used by legitimate startups and software organizations.
  • Popular legitimate websites are valuable attack channels because compromising one established site gives attackers access to its existing visitors, reputation, and audience without requiring them to build traffic independently.
  • Drive-by downloads convert website visitors into victims without visible action because malicious redirections and exploit kits can operate in the background while the user simply reads or browses the compromised site.
  • About two of the world’s top twenty thousand websites became compromised and hosted drive-by downloads each day on average, according to the measurements presented by Barracuda Labs.
  • Five to ten million users were exposed to drive-by downloads each month through the top twenty thousand websites alone, demonstrating how trusted, high-traffic properties can provide attackers with substantial reach.
  • Social network features are attack infrastructure because sharing, liking, reposting, following, direct messaging, and list notifications can distribute malicious or spam-related links across large connected audiences.
  • Fake accounts are becoming more convincing because attackers copy legitimate names and biographies, add small username variations, combine pictures with profile details, and repeat ordinary-looking posts to avoid detection.
  • Fake-account networks support multiple revenue models because attackers can use them to distribute spam and malicious URLs, then sell followers and likes to people seeking greater apparent popularity on social platforms.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is lean hacking?

Lean hacking is the application of efficiency-oriented business practices to malicious activity. Attackers aim to increase revenue, decrease costs, reach more potential victims, improve the rate at which visitors become compromised, and reduce their workload. They use popular websites, social networks, hosted services, and cloud platforms in ways comparable to how legitimate organizations use efficient infrastructure to improve operations.

Q: How do attackers use popular websites to reach more victims?

Attackers compromise legitimate, popular websites so they can gain access to audiences that those sites have already built. They then place drive-by downloads or exploit kits on the compromised properties. Visitors may encounter background redirections and receive an executable without seeing an obvious consequence, allowing attackers to turn ordinary browsing activity into a large source of potential infections.

Q: How do drive-by downloads infect website visitors?

Drive-by downloads work by exploiting a visitor while that person browses a compromised website, without requiring a deliberate download or another visible action. The examples presented involved background redirections, exploit kits, Java exploits, and an Internet Explorer vulnerability. A user could remain focused on the expected page content while malicious activity installed an executable on the system.

Q: How common were drive-by downloads on major websites?

Barracuda Labs measured an average of about two of the top twenty thousand websites becoming compromised and hosting drive-by downloads every day. The analysis also found that five to ten million users were exposed each month merely by visiting sites within that group. These figures cover the top twenty thousand websites rather than every site on the internet.

Q: How did attackers exploit Twitter lists?

Attackers used Twitter lists because the feature did not have the same limitations applied to activities such as following large numbers of people or repeatedly posting identical messages. They could add ten thousand or twenty thousand users to a list, trigger notification emails depending on user settings, and place a spam-related or malicious URL where recipients might follow it.

Q: Why do attackers create realistic fake social media accounts?

Attackers create realistic fake accounts because social networks have improved at detecting and disabling obvious fraudulent profiles. By copying a legitimate user’s name and biography, slightly changing the username, mixing pictures and profile information, and publishing repeated ordinary-looking posts, attackers can make fraudulent accounts harder to distinguish, keep them active longer, and reach more potential victims.

Q: How do attackers make money from fake followers?

Attackers first used large collections of fake accounts to distribute spam and malicious URLs. After gaining control of millions of accounts, they recognized another market: people who wanted more followers or likes. They began selling access through websites with credit-card payments, customer support, and guarantees. At the time described, one thousand followers cost about fifteen to sixteen dollars.

Q: What should defenders monitor to counter lean hacking tactics?

Defenders should account for the channels identified in the presentation: compromised legitimate websites, background drive-by downloads, browser and Java exploits, unusual social network list activity, duplicate profiles, coordinated fake accounts, and malicious URLs. The central defensive implication is that trusted sites and ordinary platform features can become attack infrastructure, while attackers adapt when networks impose new restrictions.

Summary & Key Takeaways

  • Attackers apply ideas associated with lean startups and software development to cybercrime. Their objectives are to reach more potential victims, improve conversion into successful compromises, develop additional monetization methods, and lower operating costs. Hosted services, cloud platforms, popular websites, and social networks provide efficient infrastructure for pursuing those objectives.

  • Compromised legitimate websites give attackers immediate access to established audiences. Drive-by downloads can infect visitors without requiring visible interaction, often through background redirections and exploit kits. Barracuda Labs observed about two of the top twenty thousand websites becoming compromised each day, exposing five to ten million users in an average month.

  • Social platforms provide both audiences and mechanisms for rapid distribution. Attackers exploited Twitter lists when other actions had stricter limits, built convincing duplicate profiles, and coordinated fake accounts through shared systems. They then expanded beyond distributing malicious links by selling followers and likes through services designed to resemble legitimate businesses.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚