2022 Global Threat Analysis Report – Pascal Geenens, Radware
Pascal Geenens, Radware’s director of threat intelligence, will talk about the threat of Russian hacktivists — are they a real threat or merely a nuisance — and review the findings of the company’s recently released 2022 Global Threat Analysis Report. Radware’s report shows that the number of cyberattacks jumped notably to 150% globally and 212% in the Americas compared to 2021. Other stats include the spike in DDoS attack volumes, most DDoS-attacked industries, and the rise in malicious web application and API attacks.
Transcript
This is texturing TV. Hi everyone. Welcome back to techstrung TV.
I want to introduce you to our next guest. His name is Pascal Geenens pascalo's with radware. We haven't had anyone on from radware in a while.
So Pascal. It's a pleasure to have you on here representing radware and welcome to Tech strong TV. Thank you, Alan and thank you for having me.
It's it's another to be back. I was here think a couple of yeah, maybe two years ago, but that's it's always a good to see you back looking good. Here is a long time and dog years and internet use the lifetime in security years.
I did not teach very well. I'm sorry about that you and me both my friends you and me both it does it does age you hey fiscal, you know, it's been three years. What are you doing radware now?
What's your title? I'm the director of threat intelligence. So I oversee all the tread research and also everything that has to do with the threat intelligence.
which ties into most of the pillars that radware is productizing and We have Security Services on which is details protections. We have bot management and also Cloud protections. So most of our research is based on one of those pillars and details being one of the most prominent and most important areas of research for my team.
Actually, all right. You know what? I I think people understand now, you know radware and you know, obviously what you do is direct or threat intelligence and thread intelligent coming back from RSA last week right thread intelligence is is it's no longer a nice to have or something that only big companies use right threat intelligence now is a must-have for everybody and and the good news is with companies like radware offering threat intelligence as a service if you will right you yeah, every company has you know almost as great insight as the biggest companies do in terms of you know, what the threat intelligence roadmap or what the threat intelligence current state is on any given moment.
So That's been a real development and security from let's say 10 years ago, right where? Unless you were really big company. You really didn't have access to that kind of Intel.
Oh, yeah, for sure. Did the internet changed the whole landscape for for everyone I believe and With respect to to intelligence itself. I think that now we are better equipped and especially for a very specific category of threat actors that we have been monitoring and those are activists and the reason why I say specifically for that category is that a activist is just like an activist.
He wants to be hurt. He wants this message to come out. He wants to come on TV have interviews, maybe even with you Allen.
He would probably activists will be happy to talk to you and to bring your story and to bring their message. So in doing that what they also do is they perform attacks. So typically a activists will do a website defacement of a website in a certain country for religious or for political reason or you are social reasons.
But also what they do is denial of service attacks, denial of service attack is something that is close to our heart because yeah, we have a lot of customers to protect from those attacks and we want to be on the Forefront and know what is happening in that area. So following activists and what they do to boast about their attacks is that they gonna write the message about it. So every time they do an attack and they are successful they will post a message and that used to be on Twitter or in a private group, but now more more than often we see them posting on telegram.
So they post a message on Telegram and they need to prove that they did a successful attack so they will use that monitoring tool like check hosts. Don't man and they will put in a link with a report to that specific Target that they were attacking and demonstrating that they had a successful Beatles attack. How long that attack loss is difficult to say because it's only a snapshot of the website not being available.
However, it does allow us to find out who is targeting who and then most of the time they give some context in the message. So also do why so activist is a very interesting subjects in terms of threat intelligence because they give us all the information that we eat. It's totally different when you look at a nation state or at some private groups that are doing and filtration and try to exfiltrate information for intelligence without being called because those they will not post about that.
They will not brag about it activist. However will always brag about what he did. Um, also when he posts information sometimes difficult to find out what is true and what is not true.
So specifically for details that monitoring tool that they're using to prove that they broke down the website gives us a certain certainty that this event actually happened and might have been successful. So most of the time we will talk about attacking but it's more like targeted so they have an idea. They want to attack a certain website now activists are not Typically going after critical infrastructure or after the harder targets.
They want to optimize their time so they gonna go after public websites public websites that make a lot of noise and you might remember from last year. They have been lots of pressure coverage from killenet. For example, the pro-russian actor who was attacking airports in the US hospitals in the US it all made a lot of noise in the media and that is what those activists want because they are attacking for specific purpose.
They have a message to bring and in the case of progression activist or create neurotic activists as we call them. It's anyone who says something wrong or something that feels wrong for Russian citizens or for the Russian government and you have a whole cluster of those those activists in Russia. So I mentioned kill that but there's a whole cluster around killenet with Anonymous Russia recently changed into a new Anonymous for a show because he was the original one was apprehended, but the new group was created and to show Ruins of a group like kilnut and its leader killmilk who's very media Savvy and who was in several interviews in Russia today and also interviews with journalists in the written press in Russia.
And also in the west he actually appointed the new leader of anonymous Russia and that Anonymous Russia works, very close with kilnite and killenet has has a good amount of groups that run around them and take orders. So to speak from from the same kilnet group whenever they say we gonna attack this country today because of this and this political reason and most of the time it has to do with the invasion of Ukraine a country providing support for Ukraine or helping with weapons delivery or saying something bad about Russia Russian attacks. That would be a motivation that says that kill not might want to attack a certain country and then all that group will go and attack them.
So that was mostly 2022. So those group evolves and and they started out. A low threat actor but after a year or more than a year now doing attacks, they gain some experience now in terms of kill net and that was a surprising part of our report.
So what we did is Because they like to boast about their attacks and because they are on telegram which is a medium that is easily accessible with apis that are well specified and certain place we could cover a certain period and follow all the different attacks that activists were claiming that they did a DDOS attack or that they had a successful deals attack. So we compiled all that information put it in database and try to find out across 80 different telegram channels and a total of 1,800 attacks and a period of only two months that we assembled we try to find out if there's a patterns over there and we can clearly see the pro Russian activists on one side for the political which we know very well from last year and which has been covered in the media. But in other area that came up out of the report is that the religious activists specifically the pro-islamic activists who were involved in Oppo Australia in February and also an OP Israel?
right now and also last month that those actually take almost not almost I would say more than 50% of the attack activity. So religious activism is still very important and came back up in 2023 on the radar. When we looked at 2022 we were expecting this whole hack to this man, especially the Patriotic activism movement to continue and to actually grow but we didn't think it would escalate so fast.
So that is the reason why we started monitoring more closely and try to find what the patterns are. Now one of the interesting patterns is especially among the pro Russian activists is that kilnats in 2023 did not even rank in the top 15 of activist actors in terms of diesel attacks. So kill not in 2023 did not do any details attacks or at least not did not report any original ones.
We saw that kill not posted didost attacks and they posted about the tax on telegram, but those were murdered reports that were originally posted by another group such as no name zero five seven sixteen. So there's other groups who do the attacks and then kill net assembles them and puts them in a summary and post one big message. Hey, we attack 20 different targets today, but actually when you go look into the report links, you see that those attacks are from yesterday and day before and even one day before another day before so and when we track the IDS the unique IDs that are made for those reports.
We saw that the actual attacks that kill nut is boasting about That those were already performed by another group, which is no name. So kilnats had almost had 11 attacks in a period of two months original attacks, which means that and we also knew that because coconut the kill milk the leader of kill nut is busy with other Ventures and has other ideas and other projects. One of the things that he's working on is to make a private military hacking crew.
So it's like a Wagoner but for cyber, so that's his new pet project really now working. Yeah, exactly. And that that also shows the danger of those activists we might say.
Yeah, those details attack some of them only impact for five minutes. So like killing that today, they might typically turn up their servers and then they do an attack for five minutes and then they go away they have enough proof to say. Hey, I impacted this airport over there.
So a lot of people might say, yeah, the the impact stays limited. However, when it's covered in the Press, I mean the media asked him to talk about what he's doing and why he's doing it. We're giving him a place to shine and he's very media savvy.
So he created a lot of influence. He is one of the most influential activists in the pro-russian groups. You can see that from the cluster but also he started Infinity Forum tried to monetizing schemes.
That didn't work. Well, but now he's working at a PMC a private military army that will do cyber. And it looks like it will be for higher.
So the highest bidder will actually have the skills of those those attackers. So he's clearly out for monetizing and the more we put them in the media the more his influence will grow and the bigger that crew will become so those activists are gaining from media attention because that's how they get more members and more influence. Now are they the mostly is killing at the most active and dangerous one in terms of diesels?
Absolutely. Not today. If you look at the one that's most dangerous in our opinion.
That's no name zero five seven sixteen, which is a crew that doesn't want to be associated with killing that it's one of the the exceptions in the pro-russian activist groups because most of the progression active is groups have Affinity with killenet and they want to be associated with them in their cluster. However, no name resolutely says we have no association with kill Network completely independent. Now what they did they started this a project called ditocia and that'll see a project.
They developed a bolt that can be installed by their volunteers by their members on their PC and what they then will do as administrators is create a command and control server and they will feed the targets and the links that will attack victims 24/7. So the Bots are just put on their Forum everybody can download it. Stores it on their PC on or their Linux computers and runs it it Army of Ukraine has the same on the other side.
We also know about Liberator and this from this balancer that has the same idea of a crowdsourced botnet. So to speak so people voluntarily download it and run it but it's the operator the administrator that curates a list of targets to attack now no name in this way has been attacking for 24/7 since the time that we started tracking them and that already goes back to October last year. So every day 24/7 they had you targets and you can and new countries that they were continuously attacked.
Those are not attacks that last five minutes. Those are attacks that run at least for 24 hours until they change the feet and sometimes they stay in defeat for a couple of days. So that's that's why they came out on top us one of the most active activists.
Now. The second active one is anonymous Sudan Anonymous Sudan. We catalog them as a religious activist.
However in the press it has been sometimes said that they are pro Kremlin and the reason behind that is the history when Anonymous Sudan came up beginning of this year that was during attacks on Sweden and Denmark and the reason or the motivation behind the attacks of anonymous Sudan was the burning of the Quran. There was a right-wing politician that burned the Quran in Sweden in front of the Turkish Embassy and that caused a whole Shockwave across the Muslim Community because they are burning around it's discretion. They cannot do that.
So Anonymous Saddam decided to attack Sweden and then Mark because of the burning of the Quran. However, the reason that the politician burned the Quran in the first place was because he didn't want Into join NATO which fits in The Narrative of the pro-russian activists. So killnat is also interested in attacking Sweden and Denmark.
So you have two hacktivists. With the same objective but with different motivations. Yeah, so when we look so that's when killing that said.
Well Anonymous Sudan is attacking Sweden and Denmark. I declare them an official member of the killnat cluster and for anonymous Sudan that was great because they were just coming up and killing it was already a year out there in the media as being one of the most prominent pro-russian activists. So they were happy to use that label in their graphics and then their propaganda to gain more members for for their cause so Anonymous dance started using that girl not label as well.
But after Denmark and Sweden Anonymous sudama to France and that the motivation behind that was Charlie had dolk cartoon that came out about it Mohammed a couple of years ago. And after that he got distracted because some of his friends well friends. I would say colleagues more or less.
I don't think that they're officially friends but you have mysterious team Bangladesh and you also have Team insane and Pakistan and those two activists were attacking Australia at that moment. And the reason that they were attacking Australia is because the week before in the last day of the Melbourne fashion show the fashion label not a man's dream put a model in a transparent clothing transparent rape that says I walk with Allah And of course the Islamic and the Muslim Community did not like our work with Allah on a scarcity plated a scarcely dressed woman. That was no good.
So mysterious team and Demon saying picked up on that information and they started attacking all the mass dreams and after that like up to 70 in one weekend up to 70 different organizations from private businesses small and medium businesses to Ports governments airports were all targeted by both of them Anonymous Sudan picked up on that and he also joined them in their calls and that became that's what we call up Australia. So they put a battle tag up Australia. And then after that there was up Israel.
So we saw Anonymous Sudan move to Israel. And with the infighting in Sudan because now there is more excites Sudan there were some news outlets in Ethiopia or in Egypt that were bragging about that and that we're talking bad about it. Anonymous Sudan also attacked Egypt for that.
So it's like half politics half religion. But Anonymous Sudan is the number two by far and and one of the more dangerous one in terms of volume. We see that they can do volumetric attacks that go above the one terabit per second, which is is significant not in terms of nobody can mitigate that it's easy to mitigate if you have to write infrastructure and the right Services, however, most of the people who run a website on Prem or an API or application on-prem.
They don't have a one terabit per second internet Uplink. So they always need a cloud service to protect against that the No Name goes in a different way. So the progression no name.
They don't use fully metric attack. They are Be Clever because they up the game of the traditional Beatles attacks that we see until now when we saw application Level attacks, they were targeting. Encrypted HTTP so https and they were just using a get request to the website name to the root page of the website.
Typically CDN will cache that information and we'll have no impact on the backend server. So what they start to doing those actors putting some random trash with a question mark after that initial URL so that they can cut through a CDN because the CDN things that there's some arguments for a application of the backend server that needs to be treated. But those attacks are not that effective because they they always look the same and they're repeating very fast.
Now when you look at no name. They do their reconnaissance. So before they stage attack vectors, they will go look at the website and they will identify those pages who are most impacting for the server or for the back end of the web server in terms of resources, like a search query or a forum post.
If a government has an open-form post for the public to put information and to post that form they will Target that for they will use the exact variables. They will copy all the form post variables. I will put in random information in those valuables up to the point that they have different randomized values like for a phone number they will use only digits for an email they will use six to 12 characters all phone number if you need a text they will use a longer text.
So they have special randomized variables which makes it look like a legitimate form pose. But when you look at the actual data, it's garbage, but for systems Protection Systems, it becomes more difficult to find the difference between a legitimate submission. And a real person and even in the back ends after the attack, even if your server can consume the attack because you have enough resources to consume it in the back end the guide that comes in the day after and has to process all the new form posts.
He will get hundreds of thousand maybe millions of new form posts with old trash data and he will have to identify the two legitimate or the two real ones and all those messages. So it creates a details attack on the backend as well. So we saw some customers suffer from from those kinds of attacks.
Prescott I got to stop you here. Sorry. We're already 20 something minutes into this 15 minute interview.
We wound job and off your wet. I guess you have no interest in this activism stuff, huh? Boring.
Yeah. so Prescott, you know what's interesting is a lot of people think of activists as Kitty script so harmless or not as lethal as some of the other things but clearly They're they're not. For people want to get more information.
Where can we go on radware? com and we have reports there and advisories and we will also provide a link in the descriptions so that you can get access to that report in the report. We have all the details of who we have tracked.
We even have per country we can say which actors were attacking which country which type of websites they were targeting. So all that information isn't report. Perfect.
Thank you so much for coming on text on TV and really giving us all a good look into what's happening in hacktivism. At least, you know, these couple three or four different groups. Keep up the great work.
Don't wait three years to come back on and we can talk more about this. Okay? All right.
My pleasure. All right, we're gonna take a break here on Tech strong. We'll be right back.