Deepen Desai, Zscaler | Black Hat USA 2023
Annual ThreatLabz Ransomware report tracks trends and impacts of ransomware. Learn more from Deepen Desai, global CISO and head of security research at Zscaler.
Transcript
This is Techron tv. Hey everybody. Mitch Ashley.
I am at the Mendel Bay Suite, the studios for Techron here at, uh, black Hat in 2023 Las Vegas. We're talking a lot of great folks, and I have a great privilege of being joined by Deep DeepEnd Desai, who's with, uh, Zscaler. He is the global ciso, head of the security research team.
Wow. Fun job. This is a perfect place.
You know, this is sort of home country for you. Perfect place. Yeah.
Excellent. Well, you know, I'd love, I'd love to, to dive in and talk a lot about Zscaler and all the great things you're doing. You've got recognized on the Service Edge, secure Service Edge recently, which is great for you all.
Um, but I know you're here talking about your threat research report right? From the threat labs. So I think you're talking tomorrow, right?
I Have a presentation. You're welcome to, you know, get any scoops in here that you want, but you may give a little preview of to folks about, uh, what you're doing. Absolutely.
So I can start with the report that we published, uh, on, that's our annual ransomware report. Um, so my team Threat Labs, it basically looks at data from, uh, Zscaler Cloud platform. Uh, on any given day.
We are securing 300 billion transactions. We're seeing more than half a million new unique payloads at our sandbox. Mm-hmm.
So there's a lot of, uh, unique intelligence that the team leverages to track threat actor activity campaigns, targeted attacks, so signals derived from there. And then the team is also tracking threat landscape where we're tracking the threat actors infrastructure. Uh, and in this case, the annual ransomware report is focused on what the ransomware gangs are after.
So combining both of these intel, what we do on an annual basis is draw comparison between what are some of the newer trends that we're seeing? How are we seeing increase in the attacks? Are they leveraging one tactic over the other?
How are they able to evade some of the security controls as well? And are they going after specific industries? So all of those are, uh, basically part of the report that got published.
And, and are we happy to share some of those insights? Excellent. Excellent.
Well, you're in a great position with that vast amount of data. Um, and, and of course you have to treat it very sensitively and anonymize and do things like that. Of course.
I, I'm curious, um, have you seen any changes in just the amount of data, the kind of data that you've collected, that you've done the threat report around ransomware for multiple years? Yeah, so ransomware attacks continue to rise. Uh, I know there's conflicting reports out there like, Hey, it's plateauing.
It's going down and, and based on the research data, and, and we, we, we do see some high quality data, 38% increase in successful ransomware attacks year over year. And I'm talking about timeframe from August, 2022 to, uh, April, 2022 to April, 2023. So it does cover Q one of this year as well.
Um, United States is one of the most targeted, uh, country. If I were to look at the overall geo, um, a lot of organizations in US were successfully targeted by ransomware attacks. The other piece we looked at was, which industries are they going after and manufacturing stays at the top year over year.
There was no change over there. And then the, there's a long tail after that. But manufacturing is the number one, uh, industry that was being hit even in the timeframe we looked at.
Um, the other key trends, and these are more, um, more along the lines of how they're evolving. What are we seeing on the horizon as well? So there are three key trends that we highlight, and this is gonna be part of my talk track tomorrow as well.
Uh, number one is, uh, brand seminar as a service, uh, continues to grow in adoption. In fact, eight out of 11 top ransomware families. And these are prevalent in terms of successful attacks that they've launched.
They're all leveraging vast models. So it, it's basically making it very easy for even a average skilled, uh, threat actor to kind of pick up the service and launch fairly sophisticated ransomware attacks. The second piece that we saw was, uh, uh, weaponization of vulnerability exploits.
Uh, and this is where vulnerability exploits in combination with supply chain attack vector is being leveraged to go after organizations that are behind on their patching schedule. Or they have like overly flat network where once you're in the network, everything is trusted. And that's, that's what they target.
And then they, uh, they reach the crown jewel and steel data. And then the last trend, which is one of the most, uh, unique one and important one to keep an eye out for is encryption less attacks. So this is where, um, if you look at the history, it started, I mean, ransomware ha has been around for a while, but 2017 when WannaCry Bad Rabbit, not Petya happened, that's where everyone started paying attention to it.
'cause now people realize that they can really bring down cripple your business operation. So all organizations had a program to get to a good state in terms of data backup, backup hygiene, even doing exercises to restore their data. If there was a catastrophic event, a few years later, obviously Ransomware gang saw that everyone's able to recover from encrypted attacks.
So they started stealing data, right? So now, now we are in the era of double extortion attack where they're encrypting data and they're also stealing data from last 12 months. What we're noticing is many of these gangs, they're not encrypting data.
They're just stealing data. And I'm talking about large volume, terabytes and terabytes of data being stolen. Uh, in one of the case that we were just investigating, it's 24 terabytes of data stolen.
So the attack cycle looks identical to when they would encrypt the data, except the last stage of the attack where they would push ransomware payload in a coordinated fashion. That will not happen. But they have access to your data, they have access to your environment, which means they know what kind of ransom demands can they make.
Mm-hmm. Because they know what's your financial status, what's your cyber insurance coverage Like your customers are. Exactly.
So that's a, So it is a threat then that they would use the data, sell the data, we've got it, you know, we don't don't need it encrypted to sell it. Right. They will threaten you if you don't pay ransom, your data will be leaked out and that will attract a lot more threat actors to go after you.
That will also cause significant brand reputation, harm, Loss of customers, loss of business. Exactly. So that's a new trend that we're starting to see where, where they're not encrypting data and um, it's, it's still very, very opportunistic.
It's not like, Hey, I'm gonna do this for every target. They will see, in certain cases, they will still go ahead and encrypt the data if they feel like the organization wouldn't care if you leak the data. Mm-hmm.
Mm-hmm. Go, go to the traditional, if we could call it that. Right.
Ransomware, I'm, I'm curious, um, you mentioned manufacturing still number one. How about healthcare? You see a lot more of that in the, in the news cycle anyway.
I have more and more there. So year over year it did, uh, go down. It, it, it didn't actually go up.
Uh, so, um, I guess they realized that bringing down a healthcare institution will definitely draw a lot of attention. 'cause it does cripple their ability to provide service, which is mm-hmm. Which can result into life and death situations.
Oh, hospital systems. Exactly. Doctors And, Exactly.
So, so based on our tracking, we saw that go down, uh, manufacturing actually went up a few other industries as well where, um, you know, it technology services where there is large downstream organizations that could get impacted. Like, uh, think of Kaseya for example. Ca targeting a vendor that has thousands of downstream vendors relying on the software that they provide and then going after them.
I think that can result in a lot of, uh, success for them. So, um, they will continue going after such industries. And another point I'll mention about the encryption less attack is they're, they're literally trying to stay under the radar.
And, and they're doing this not just for themself, but also for the victim. So they're not causing business disruption 'cause your data is not encrypted. So it's businesses up, uh, usual for the victim.
Victim will get a notification that you, you are, you were hit, we have your data, here is the proof. You can log in and check, but the victim doesn't get into media or unwanted attention. They're not in getting any kind of unwanted attention from law enforcement agencies.
And, and, and in some of the cases we're observing ransom being paid out. And it's, it's all hosh flash. Nobody Knows the radar for everybody.
Yeah. Interesting. Yeah.
What, what are your thoughts about the s e c kind of pending rule of four day disclosure? And that kind of puts a kibosh on that, if that ends up happening For all public companies. Absolutely, yes, it is.
Uh, but private companies still up there. Mm-hmm. Um, right.
So I, I think it's a good move. Um, it will definitely prevent, uh, what we're seeing right now. I mean, there's still, as a public company, you are obligated to report these type of incidents even without that ruling, uh, in place.
But it will definitely mandate that, Yeah. Bush's puts a timeframe on it, which, And a timeframe on it, and Maybe some accountability of what's, um, uh, what's, I forget the term that they use. It's not, you know, valuable kind of attack or of sub sub substance, you know, versus like, yeah, it happened, but not much came of it.
Correct. Correct. Exactly.
So ransomware does fall into that category for sure. Mm-hmm. Very, you're losing our data.
Yes. Interesting. Um, so I mean, there's a black market for this data, just like there's a kind of productized black market for ransomware toolkits and things like that.
Uh, are, are there easier paths to selling data? Um, yeah. So in, in many of the cases, they're just outright leaking the data.
So data is available to everyone, so Just use it as a threat. Still Selling data is not a way for monetizing, uh, for these ransomware. Okay.
They're, they're, they're like, they're after very specific amount of ransom. Like, uh, we, we monitor a lot of these ransom negotiation as well between victim companies and the operators. They got stuck at say, I'll, I'll bring a number 4 million, that's the lowest I'll go.
They start at seven. Victim organization is ready to pay 2 million and they will turn it down and leak the data. So they're, they're after very specific, uh, you know, amount of money and Treating like a business.
I mean business treating, we do deals of this size and up don't bring deals, smaller deals 'cause they'll get turned down. It's kind of the same idea. Exactly.
It is a business. I mean, we don't, people outside the security industry don't realize how much of a business, how much of an industry in and of itself that it is. Yeah.
It's funny you make that point. 'cause there, the, what I was talking earlier today with a colleague was I'm seeing more and more of, uh, customer service, uh, angle in these attacks that are happening. 'cause they're, they're literally trying to cater to the victim.
Obviously they, they breach their environment, which is not a good thing. But after that, they're trying to assist the victim. Um, if the victim pays ransom, they will also generate a report, which we call pen test report.
They're, they're literally call out how they got in, how they moved around, how they stole data, and provide detailed recommendations on what the victims should be doing in order to prevent these type of attacks from happening. So, so you not only get your data back, but you know, we did a pen test, so here you go. Exactly.
There's lot to do to prevent it. Wow. Okay.
Does is that commonplace or is that, So some gangs are doing it more, uh, comprehensive than the others? Uh, there are, there are a few of them that, that will just give you like a five bullet point, Hey, do this, this, this. Which is pretty generic, but there are certain gangs which are actually calling out.
Here is what we did. Here is how we got in. And, and, and that, that's actually very fascinating.
That Is interesting. I'm not quite sure the motivation for that, but Like I said, customer service. Well, and there is customer services for all these, you know, productized.
Yeah. Uh, security. Um, so I have to bring up ai.
Are you seeing anything in terms of AI being injected into the way people are doing ransomware attacks? Yeah. So if you think of, uh, ransomware attack, these are multi-stage attacks.
It's not like, uh, you will receive an email with a ransomware payload and you get hit. It's, it's starts with phishing. There're multiple stages involved.
They may even go after the vulnerability, like the MoveIt vulnerability, which was recently in the news where, where claw ransomware gang was quick to capitalize. So, um, when it comes to generative AI or AI in general, um, I would say phishing is where we have started seeing some, um, evidence, um, malware. There are a few cases, but, but it's, it's not, uh, like we're seeing large volumes of attacks starting to leverage it.
But it's a direction we are heading in. I mean, there are malicious versions of chat, G P D for instance, uh, out there, um, Dark G P T and Yeah, fraud. G P D, warm, G p D.
Um, and, uh, good guys are also leveraging it right? To, to train their models and make sure they're, they're, they're ahead of it. It, it, uh, it may be already happening, but seemed to me one of the low hanging fruit might be using agenda of AI to, if I've got access to your email, I would import a bunch of it.
Now I ask G P T or whatever lm, L l m you're using to write a phishing email in the voice of someone who works at the company or the c e o if you have their account or whoever's it is and makes it even harder to see, you know, now you get a text to say, go to, uh, best Buy and buy these cards for me. But, which, you know, bosses don't generally do, but We actually observed an attack, and we call this business email a compromise where our CEO's voice was actually used to generate a quick voice snippet and, and using AI or ml, um, the, the, the attack starts with an employee receiving a call, which just plays out this audio that say, Hey, this is Jay. I'm, I'm in a location where the coverage is really bad, but I need you to, and then it cuts off and then it follows up with the same number with Jay's picture and everything, the WhatsApp message that, that is like, Hey, call dropped off.
Can you do take care of this wire this much amount to this bank account? So, so that, that's already happening where we're seeing that. Yeah.
And not surprised at all. And a video video to follow Right. Video To follow.
Yes. Some point Avatars that look like us, maybe we already do and don't know it. Uh, I'm curious as a presenter at Black Hat, you know, I haven't done presentations myself to an R S A and other things.
Um, you're always thinking about your audience and the kind of people that're gonna be coming to your talk. Obviously researchers, people that are doing pen testing, people that are securing their own networks. Um, what are the things you're really, really important to you about how you deliver your talk tomorrow?
Yeah, no, so I, I definitely feel at home. Uh, my, my career started as a researcher and I grew into the current role as well. Uh, the audience is pretty mixed, but definitely a lot of, uh, practitioners over here, right.
And, uh, um, there are CISOs, there are senior directors and directors as well, attending a lot of these talks. So my goal when I'm presenting any of these topics is always to make sure they, they get some key takeaways. So in, in, in, in, in ransomware case, and we can walk through them right now as well, but in this talk, the number one thing that we wanna make sure everyone gets is what are some of the new things we are observing?
And, and there are a few more that, uh, we'll go through tomorrow. Um, down until the programming languages, uh, that these guys are using like rust mm-hmm. Golang, um, uh, why are they doing that?
How, how are they evolving? Um, you know, the data exfiltration aspect of it as well. So one is educating everyone on the evolving ransomware threat landscape.
And the second biggest aspect is how, what do you do about it? We all know the problem. How do we defend against it?
What can I do, uh, in near term long term to get to a place where we're in, uh, in a better shape in terms of, uh, network defense? I'm curious your thoughts on, you know, supply chain. We've been talking about that a lot for the last couple of years, but that, that's such a wide and deep talk topic.
'cause you'd be talking about sort of the, uh, the, the approach of my, my tool chain and my development environment talking about the, the people that I'm using, you know, my SaaS or my cloud service providers or just suppliers to my applications that are part of operating my business. Is there, you mentioned earlier about kind of suppliers to your business. Is that a fast growing or one of the fastest growing areas of supply chain?
So, So that's a good point. Supply chain attacks can happen in both direction. I I like to call it downstream as well as upstream.
So downstream is where your leveraging a software, right? A software that is very popular, leveraged by thousands of organization, and they target the vendor who's the owner of the software, SolarWinds Kase, right? And then they're able to, to do downstream attacks on all the organization that have that software running.
Mm-hmm. Uh, the other, uh, the vector is, say you are a large company of very strong security defenses. They're not able to get to you, but you rely on a third party vendor that has really sensitive data that you do care about.
Mm-hmm. Their security defenses are not as strong as yours. They will go after that.
Right. And then that's an upstream attack. 'cause they're, they're stealing all your data that's, that's available to that supplier or that that third party vendor that's providing you a service and then they come and demand ransom from you.
Mm-hmm. So we've seen instances of that happen over the last two to three years as well. But, so you might use an analytics tool, service SaaS kind of application or maybe an AI or something like that where you need that data there for them to do whatever exactly that they do with the data.
And so why not get it, you know, that's the easier path to go getting it. And, but it's still your data, so we'd like some money to give it back to you. Exactly.
Yeah. Good. Well, I wish you the best of luck.
Um, anything new happening at Zscaler that, uh, you wanna mention? You all have a lot of, a lot of great products in C SS B, we talked about secure service Edge and Right. Yeah, I, I'll mention a couple things.
So number one is, um, when you're planning your defense against ransomware, right? Think about having a platform approach. You need to have a platform that's able to send signals, uh, within the module that are part of the platform.
The four stages that I mentioned. They find you, they compromise you, they move laterally and then they steal data. How can you have a platform that will allow you to basically reduce your external attack surface, enforce consistent security policy to all your users and devices no matter whether they are, whether they're at blackhead, whether they're traveling, whether they're home, prevent that lateral propagation phase, which is reducing that blast radius from a user that makes mistake, or a machine that gets hit by the bad guys.
And then finally inline inspection of all data that's egressing your, your devices. Mm-hmm. So that's, that's how it would look at and that's, that's what Zscaler helps thousands of organizations with in order to safeguard against these type of attacks.
Uh, a new thing that we actually announced, uh, a month, uh, a couple months back at our user conference is, uh, cyber risk quantification tool. It's called Risk 360. Um, that actually came from my group where, you know, we go through the pain of quantifying risk.
What is real risk to the organization? How do I communicate that, uh, even to my board? And so that's where we, we, we saw what was being done, uh, outside in the industry, how cyber insurance folks were also using these 800 questions that needs to be answered.
There was a lot of subjectivity complexity in that. Mm-hmm. So with those problem statements in mind, we, we went towards creating a a a a A tool that's able to use data that's data-driven, completely data-driven, no subjectivity.
It looks at how you're configured, what are some of the behavior we're seeing in your environment, maturity of your controls. It's not a binary response. You will say, yes, I'm doing M F A or you may be doing m f A for one application, but you may have a thousand applications in your environment and everything else.
You're not doing m F a. Right? Not at your SaaS vendor, but your apps or whatever.
Exactly. So observing the data and configuration and combination coming up with, hey, yes, you're doing M F A, but your maturity level on on that control is 40% 'cause you're only doing it for certain apps and here are all the apps where you're not doing it. Same thing with t l s inspection, same thing with sandboxing.
So all the controls that we provide, and there's a lot of third party integrations as well where we'll basically derive insights from wall management tools and other tooling that most organizations will have. We all know security researchers and practitioners love to fill those reports out. So we think that makes it easier, right?
Yes. No, we don't like to do that, but we know we have to. Well, it depends.
It's been fascinating to talk to you. I wish you the best, break a leg tomorrow and, uh, have a fantastic talk. Uh, looking forward to that.
I hope you'll come back again. Thank you. Thank you for having me.
You Bet. DeepEnd Desai, who is a global CISO and head of, uh, uh, security research at Zscaler. So talking here at Black Hat.





