Malvertising Ad Campaigns – Ricardo Villadiego, Lumu
Lumu CEO Ricardo Villadiego explains why cybercriminals are now creating their own ad networks to drive malvertising campaigns that trick unsuspecting end users into giving up credentials and downloading malicious software.
Transcript
This is Textron TV. Hey guys. Thanks the throw.
We're here with Ricardo Villa Diego also known as RV. He's the CEO for lumo and we're gonna be talking about malvertising and what's going on in this space and it seems to be a Scourge. That won't go away RV welcome to the show.
Thank you, Mike. I suppressor being here. You guys just found yet another one of these campaigns that are out there.
So maybe you might want to dive into what made this one a little more trickier to discover. But I'd love to get your input also on why does this stuff just never seem to go away? Well, it's because he pays off for the criminals Michael.
I think the malvertising is not something new right something that being for the last two day cats probably affecting the end users and you probably remember those ads of stop your computer have been infected when you click there you go truly infected Those ads were spread through their online advertising Network, right Google ads Google display Yahoo, and so on and so forth, but we found is that the bad guys are building the world like abilities the health center spread malware at their own wheel without depending necessarily on on the third party online advertising Network and they do that because it pays off and users continue to click on those fake Arts. Spread malware at an increasingly alarming rate. That's the reason why they build it.
So now what identify the bad guys building this capabilities. There are essentially creating their own online advertising Network so that they can use it at will and and what we identify is that they are using this new technique in connection with ransomware. So the primary matter if you analyze the last A hundred rounds more attacks.
The victim was infected primarily using advertising in which cardboard was deployed. They used Cat book as the entry point to the networks, then they move laterally within the network and they vaccine and with a ransomware Incident That's essentially the the net that of the research. And use the scene at least that the ad Network people were complicit in some of this and that they weren't aggressively policing it, but now it sounds like maybe they got better at it and the bad guys just decided to go build their own head Network.
That's exactly what what's happening in cybersecurity Michael. I what I you know, what I tell the industry analyst and my customers every action creates an adversary of reaction right that the online advertising Network became better of fighting back fake Arts. Now the solution for the bad guys was building our own and you know, the warlike capabilities will win Define I would say there are early stages.
There are affecting primarily websites. They have WordPress in June law and PHP technology, which is which you know, the millions of website have been built using Boston College, they inject into those websites, which is a baling website they in yet. JavaScript like capabilities to ensure that they can display their ads at their will and they ask that they're using are truly clever right when when you go into a website and that website tells you you're using an old browser.
You need to update your browser now because it's vulnerable. Well the human Typically clicks to download the new version of the browser. Theorically that new version of the browser is is a piece of malware is cardboard.
This gives us the new version of the browser and then resolve is the catastrophic effect that comes after that. So, how are we supposed the thought these types of attacks? Because there's something that the end user it organization should be doing to kind of prevent these ads from surfacing or is that something that an ISP is supposed to be doing?
I think you know ideally the ISP will done that for us. But ideally this feature of being doing that the past 25 years. So the truth is they aren't doing that.
So we have to take security in our hands and ensure that we put the controls in place that help us to identify this Behavior the two main things that I recommend for companies when the one attack on this problem the first one it's you need to make sure that the end users are trying to identify these bad behaviors right and building they have it enable then to effectively identified that they are facing an attack and that way they become honest and an extension of the cybersecurity analysts are defending a company. I used to make these analogy with my customers right in real life when Going through a dark Street, you know, you identify danger immediately, right? They're not they're not signs in the cyberspace about these issues.
But we have to behave in the same way. Like when when we want to cross the street, we don't cross it like that. Right?
We stop we take a look to the left take a look to the right or Northeast we cross the street the same is true in the cyberspace. Every click got an end user is given is either defending the organization or a spouse in the organization to risk. So spending time and effort on training.
The employees is a good thing and it's something that if don't correctly can truly add value to organization. The other thing is what happened if they use your false affecting of these attacks and then you need to have the capabilities that enables you to identify the that behavior is happening in your organization and the one thing That is the common denominator of all type of attacks is that those malware those malicious artifacts have to use the network. There's no other way.
They have to use the network electrons have to go through the network and onto adversarial infrastructure. So the best way is to assess what's happening in the network. We call that measuring compromise measuring was the level of contacts of adversarial infrastructure that exists in your neighboring the minute you identify that that behavior you stop that behavior you are affect your effectively stopping the catastrophic result.
They may come after that. Are we in danger of that whole ad medium becoming ineffective because people will stop clicking on all these ads in the first place because they're just going to assume that they're somehow infected and they'll be conditioned over time just to shy away from I think the online advertising advertisement industry. It's in it is in the best interest of the industry that that we we solve this problem because at the end of the day, it may happen what you're just saying, right?
So the end user may just be afraid of clicking into any AD. We don't want that to happen. But at the same time we want to make sure that we protect our company.
Like I said before the best way to do so is by measuring the level of compromise that it's been a net within an organization that will protecting and the network is the best vehicle to identify those Barbie behaviors. There's no other way. I I kept saying this if a piece of malware is gonna cause harm the only postal way for the abuse of malware to do so is to utilize the network.
If therefore the network provides the ultimate source of Truth or what's going on from the compromise point of view in an organization we do so we identify those early signs of compromise as we call it the same as we call it. We eliminate those contacts and as a result, we eliminate the catastrophic we sold American after that. Is it getting harder to identify the sources of this malware in this content?
Because it seems like at least from my perspective. If I look at some of these new AI tools that people are creating. It's just gonna let the bad guys create.
Malicious websites more efficiently and they'll be more of it than ever. So, you know, are we in danger being overwhelmed? I think we are Michael I think.
So two things that are happening traditionally cyber security operation operators. They want to have just one alert that they have to upgrade and that alert is gonna stop. Everything else and that other better be a very important error a critical error alert, right?
I typically deal with my customers about the traditional way of say your security operations because it might be the server security that tells them hey in five minutes this piece of malware. It's gonna start encrypting. And if that is your mindset for savior Security operation, the end result will be catastrophic because you're not gonna have five minutes to eliminate that problem.
So the mindset of cyber security operation is changing towards identifying the early signs of an attack. Those early signs when you identify those early signs those attacks never evolve into something that becomes more critical in your organization. So to answer your question.
Yes, it's becoming more complex with identify pieces of my work, but we have led that to happen. Right? We we decided to take actions only when alert or critical.
Well, it is in our soul discretion to take actions when those alerts are very simple when there is signs of fishing in my network when there are signs of contacts with infrastructure. That is Distributing malware that one it's on the cyber security operator to add that way to behave that way. I think tools have to be better building their habit within cyber security operators.
Yeah. It is way better to handle a small alert and to hango a critical is Tell you many many hours. I know the weekend to fix it.
Right number one on the second part of the equation. You had the bad guys that are evolving their attacks infinitely. Right?
And they're doing something that is clever. Right? I think they are hacking these valid domains.
There are Domains from companies they have businesses with other companies. So it becomes harder for the big thing for the Target to identify. The dogs contacts are coming from upper Southern University because there are in fact coming from the company they're doing business with is a Bend or of the other company.
So it it becomes more and more it requires more structunity with identify the contact that's coming from company a from which I have Bali business with in recently communicate with is in fact bringing an infection into my neighbor and I go back to the network again. Then the network will tell you that behavior. If you're contacting the website of the organization if you sharing an email with our organization, and that's fine, but if you're contacting the website of the organization and that website Downloading a piece of malware then that's for sure not good and all that information.
It's something that you can take out from the network. Maybe we need to change our mindsets a little bit because we grew up with this model of Castles and modes to defend the network, but it seems like yeah, if you think about this from any kind of military perspective any battle that is fought inside of your territory is going to cause collateral damage and you're just gonna there's gonna be a cost and maybe we need the battle to be, you know, not inside our networks, but on somebody else's Network or somewhere in the middle stream somewhere. And so maybe that's where our mindset needs to go is that despite needs to be fought not within our network, but out in the shared network area where we can do it in a more collaborative and cohesive approach.
I think I agree with that seeming Michael and I go One Step Beyond right? I believe the mindset that have inundated cyber security in the past 25 years in which I deploy an ETR. I deploy a firewall in that fire was gonna stop today's attacks and tomorrow's attacks needs to go away right not to it's gonna be able to stop 100% of the attacks.
So I need to change the mindset right there right the from I have these walls that will protect me today and forever to I have these controls and I need to identify when they are. Sorry is knocking on my door when they are sorry is sniffing in my network when identify that I use my controls to do a better job of protecting my organization and that's exactly what we do a loom, right? We are assess the state of the network identify a threat and once we identify that trip we Trade defense using your current server defenses in place and when you adopt this model, Michael, you start seeing two main things number one.
The whole different elements that you're using in your network to defend yourself start adding you more value and you don't need to get a new tool for every new thread because threats are going to continue to evolve. I believe they are good technology. So there just need to be orchestrated in a way that's more effective and efficient for the organization and the second thing that you do is now use your cyber security teams are operating in a more relaxed environment what they are only tackling small problems all the time versus what's happening today.
They're all afraid of the new ransomware. There's gonna come the next week. All right.
Well folks you heard it here announcement prevention is still worth a pound of cure in this digital age. Hey Army. Thanks for being on the show.
Thank you for having me. All right back to you guys in the studio.