2022 Sysdig Cloud-Native Threat Report – Anna Belak & Michael Clark, Sysdig
Sysdig just released the 2022 Sysdig Cloud-Native Threat Report, in which they claim it costs $430,000 in cloud bills for an attacker to generate $8,100 in cryptocurrency revenue. The report confirms that cryptojacking remains the primary motivation for opportunistic attackers, exploiting vulnerabilities and weak system configurations.
Transcript
This is texturing TV. Hey everyone, welcome to another tech strong TV segment. I'm really happy to be joined by our friends assistant's always.
In the news and helping sponsoring giving helping us with speakers and information and content and there they're much anticipated report is is out and we're gonna talk about it. Let me introduce you first though to Michael Clarke and annabelic and it's a regular on our show. If you've watched extract TV, you've probably seen her three four six times.
Michael is the first timer. So we're gonna we promise to go easy on him, but Anna and Michael welcome to techstrong TV. Thank you.
Pleasure to be here as always to have you on Anna and Michael before we jump into the report though, you know, what in spite of cystings presence on our Tech strong Network? There might be people out here who are not familiar with with this thing and what you guys do and what it's about Michael since you're the new guy we're gonna make you Tell our audience kind of a little bit of the cystic background. All right, I'll do my best.
But okay is a cloud security company. We specialize in vulnerability management Cloud detection and response caspm, you know all the normal goodies, but mostly around runtime track detection. Excellent and your role at this thing and the director of threat research.
So we handle all of our detection rules and go hunting for new threats and making fun content to read and things like that. All right, and we haste him enough. Oh, why don't we why don't we tell them a little bit about you?
I am the director of thought leadership accessing so my role revolves mostly around content and specifically content that is about the industry not so much about since itself. and that Is a great segue into why we're here today, and why don't you introduce the report if you don't mind. Sure, it will be my pleasure.
This is the first threat report that we have shipped. It is pretty cool. Actually, we do intent to ship one every year from now on and the focus of the third report specifically is on something that we've been kind of we as an industry.
I've been talking about for a while, but there hasn't been too much concrete to publish on it of like what are these Cloud threats are they different from on-premes are things that people need to change the way they do in order to protect themselves and really what what's going on anyway with the bad guys in the cloud. So that's what we've done. There are three parts to it.
I guess I'll say what they are. So one is about crypto jacking which is the top threat that we see right now. And actually I think most folks probably agree with that assessment.
So we talk about a specific adversary that it focuses on this. We also talk about supply chain attacks is that are now being initiated through Docker containers, which is pretty novel and kind of cool if you're a cynic and then we talk about how do political and Global events can affect how attackers behave at this point. They can pivot their activities very rapidly using some of the benefits of cloud and automation to move from one type of Attraction another in response to something like the conflict in Ukraine.
And this is also true Michael. So your director of threat research is a threat report. I'm going to assume you had a outsides you and your team played an outside outside stroll here in this report.
Why don't you talk to us a little bit about that and and maybe a little bit about what were some of the findings in the report that you think are you know, and it's giving us three areas that I think are important, but why don't we you know jump into specific findings as well if it's okay. Sure. So if our team did a lot of it mostly my team, I only did a small part of it.
So most of the credit goes to to them. I think the most interesting thing we found that was around cryptojacking and we were able to kind of put a price on How much it costs a victim to let crypto jacking run in their environment it's often considered like a nuisance malware threat where they may just kill it and start something new and go on with their lives, but we found that you know for every dollar the attacker makes it can cost victim 53 dollars and that can scale up extremely quickly. Especially if a nature of the cloud and if they're able to spawn new instances of compute, and that way you can get six figures very quickly in a matter of days and Beyond so I thought that was really interesting.
I mean think about that for every dollar the attacker makes it costs the victim of would you say 53? Yeah. It's very inefficient for the attacker that's all free money to them.
So, you know, the attacker doesn't care about efficiency, right? He just wants to get what she's can and and you know, so it works for him, but my goodness. you know, it gives you an idea of just how how inefficient crypto mining is to begin with right and or how expensive and resource-intensive it is.
But you know when it's someone else's dollars, you don't you tend not to care but how expensive it can get for those victims of crypto jacking right? And and what happens there. It's it's Start right, I mean it's crazy the dollars go really quickly.
I wonder if the recent downturn in cryptocurrency has has this made? for more crypto jacking or people saying it's not worth it. I think it just makes for more like double try to earn it by more quantity because they're still very little risk compared to other types of unless activity.
Like I don't seem new stories all people going to jail for crypto jacking and things like that. Yeah. so it's a matter of the scale up to to make up the shortfall, but at some point it'll become not worth it depending on regulations and the price of things, but for now, I just need to see it increasing.
Got it. Was there any particular I mean you gave the $1 to the fifty three dollar cost any other specific metrics in the report around crypto jacking that you want to call out. I think we so we scaled it up based on one of the adversaries that we are tracking.
We found a large amount of their wallets and you're able to see how much they actually made and if you apply the formula to it, it came out to a relatively small amount on a limited amount of wallets we had which is like eight thousand dollars, but that equals about 430,000 victim. So it just kind of how it scales up and these are numbers that Actors are seeing out there. You know this I'm sorry.
Good Anna. I said the other comment we can make is to the point about crypto jockeying being so prevalent. There's a fear data points out there from cloud providers about it being the most common attack when we looked at the docker Hub analysis of what appears in malicious images crypto miners were the number one multicious thing if you will that we found in dunker images.
So that's also an indicator that this is just another way that they're being propagated. Yeah, I know we've seen that in other reports right Docker images and Docker repos. you know, they'll have like a very similar sounding name to a legitimate Docker container and people download that by mistake and voila but you're right in terms of how the public perceives it.
You know. yeah, it's not kiddie scripting but it's it doesn't rise to the level of you know geopolitical kind of advanced persistent threats either Yeah, at least in the public perception. Right, it's fair.
I mean, I think we have to be a little careful about how we think about it going forward. All right, because this 430,000 impact number. For example, the club provider does incur that cost right?
Like it might not seem like much to up provider. But if it happens often enough that's their infrastructure that's being wasted basically. So at some point they're going to stop for giving those amounts and then you have to ask yourself.
The question of like is your cyber Insurance gonna pay out or you're gonna pay out of pocket like what what's gonna happen when they come asking for that money and they're not willing to forgive it anymore. I agree. I agree.
I mean someone's got to pay. for his you know, this is a problem that needs to be taken. Seriously.
We saw wasn't about two weeks ago the ethereum folks. Did you know made an announcement change the way they're doing things that makes a little bit more eco-friendly? Do you think this would have any effect on the crypto jacking?
Now because most of the it's right actors, we see don't use a theorem or ethereum base coins these Manero and other privacy coins and make it difficult to track so they still use computational. Mining versus to put the state that appearing changed it. Got it.
Thanks. political geopolitical kind of stuff is is interesting what and you mentioned specifically the Ukrainian crisis War whatever you want to call it. What are you seeing there?
So the most interesting thing there is just the speed with which these people are able to Pivot into doing something else. Right? So Mike and his team watch essentially the threat landscape if you want to call it that all the time so they have this Honey Nut and they have all this technology that basically tries to figure out what the attackers are doing and most of the time they're mostly crypto jacketing or at least they're doing things that are financially valuable for them because they're financially motivated and they want to make money the APT threats tend to be a little more nuanced.
And so most attackers you're gonna find are not going to be apt right. However, what you see with Ukraine is Essentially a right around the date of this conflict which I believe it's very 24th, right? There's this huge shift from cryptojacking to DDOS and DDOS for any what does nose denial of service or distribution of service.
And so the intent of DDOS is to disrupt usually infrastructure like to break down it infrastructure to break down, maybe utilities and other things like that. So this is a destructive rather than financial motive and although you can make money off of DDOS. It's it's much less lucrative than crypto jacking which is like Direct Cash essentially so clearly at this moment a bunch of attackers decided to take size and participate in this conflict through their, you know, cyber criminal activities, which is really interesting and the fact that they were able to do it so quickly is really interesting the other piece that we found that's interesting is that this joining this DDOS network was also actually through containers in many cases.
So you could go to like a telegram Channel as I know for updates and they would tell you whom to attack and they you like a container like a detox in a box container that you could just Deploy on your infrastructure. So you can volunteer to participate and we saw over 150,000 people actually willingly join this effort. You could also of course be hijacked unwillingly to become part of the DDOS.
So it's hard to tell how many of those there are. But yeah, just like the Automation and the speed of the whole thing is pretty impressive. It is it is.
well It was interesting. Look I I so what's going on in the Ukrainian Wars certainly? Having folks on both sides probably, you know getting involved there.
But I I don't want to give a false sense. Look what goes on in Iran right now. For instance.
I'm sure it's spawning a lot of You know kind of geopolitical type of threat stuff. Aimed all over the place. There's always something going on in China or from China.
This is it, you know, it's this probably a constant state of chaos going on and then spikes. When when world events kind of you know demanded if you will. I mean the overall theme is that cyber warfare is just part of warfare now, right?
It's no longer this novel futuristic thing. It's pretty much par for the course. So every government or you know, any entity out there that has a stake in political game is gonna have a cyber component almost necessarily as part of their effort.
So Michael rubber meets the road, right? You get all these things that we were talking about in in the report. How does this translate into what you do with your team?
So we make a lot. So we improve our detection Technologies, but we also publish a lot of ways to do it without using our particular tools. So with kubernetes, there's all sorts of open policies that you can use to do things.
So we we try to give advice there and you know provide that feedback into our product as well. So our customers can get the latest defenses and indicators and things like that. Absolutely all good stuff.
guys for people who want to get this report Who had who has the where can they go? I think if Okay. com Slash threat report.
com, it should be friends Center, but also front page there as well. It was a rhetorical question. com threat report.
Hey, Michael, and I want to thank you for for coming on Michael you got through your first one now now we're gonna have to have you back. No, definitely. Thank you.
All right. I know it's always a pleasure to see you. even right Go check it out sistig slash threat report interesting information, especially about the crypto jacking stuff guys.
Take that. Seriously. It's a crazy number there a dollar for course fifty three dollars to a dollar a terrible business model.
Anyway, we're going to take a break here on Tech strung. We'll be back in a moment and stay tuned.