Rising Threats: Mobile Malware and IoT Cyberattacks with Zscaler’s Deepen Desai
Mobile remains a top threat vector, with 111% growth in spyware and 29% growth in banking malware. Google Android remains popular for threat actors, as the Google Play Store featured more than 200 malicious apps, which accounted for more than 8 million installs.
• The top three industries targeted by mobile malware are technology, education and manufacturing. Education saw a year-over-year increase in blocked transactions of 136%.
• The United States remains the top target for IoT cyberattacks, accounting for 81% pf them globally. It is also the second most-targeted country for malware attacks (trailing only India).
Transcript
This is Textron tv. Hi everyone, it's Alan Shimmel. Welcome back to Techstrong tv.
I'm really happy to have our next guest join us today. His name is DeepEnd Desai. Deepen is the Chief security officer, CSO at Zscaler Company.
I've been covering Zscaler, I think I've been covering Zscaler pretty much since Jay Chare started. Zscaler, uh, we left his last company and started it, but, and that's probably been, I'm going to guess 2007, 2006. Do you, do you know, 2007, Eight?
That About right? Yeah, that's about right. Yeah.
2007, 2008. So it's been a while. Deepen.
Welcome to Text on tv. It's great to have you on. As I mentioned, you're the Chief Security Officer, but you weren't born the Chief Security Officer at Zscaler.
Right. Let's hear a little bit about your, your path to becoming, uh, the CSO at Zscaler. Yeah.
So, um, thank you. Thank you for inviting me. Um, um, I've been in the field of security for over 20 years now.
Uh, I started as a researcher, uh, focused on, uh, um, defensive side of the house. And then I had, um, the experience of, uh, uh, so the offensive security as well, where I was red teaming, pen testing, um, exploit, uh, coverage, you know, um, and then, um, um, had my hands on product side as well, where building the new tech in order to defend against the evolving threat landscape. Um, throughout those 20 years, uh, I have been always on the vendor side of the house, um, uh, where the primary goal is, uh, as it stands today, number one is to make sure protecting the company infrastructure, products, services that we offer.
And being a CISO on the security vendor side, you also have, uh, the responsibility of protecting your customers. This is where I have the research and development function around cyber reporting into me as well, where, uh, we're looking at the threat landscape, um, what are the threat actors doing that is novel? How can we stay ahead of them and, and, uh, sharing insights like the one that we'll be talking about today.
Absolutely. Um, we mentioned Zscaler started 2007, 2008. Yes.
You originally, in, in my mind, Zscaler was kinda one of the first true security companies that used the cloud. Not cloud security per se, but used the cloud to deliver better security, right? Yep.
So, and also, go ahead. You, you Can, no, This is your job. You gotta explain it better than me.
Go ahead. No, it's, it's, uh, I mean, you, you reminded me of something. So I, I joined Zscaler in 2014.
Uh, it, it was, I mean, it was, it was a young company, 200 people, uh, plus a little over 200. And, uh, you, you rightly said, like we were the first company that, uh, started doing security in the cloud. Uh, true zero trust architecture when the term zero trust didn't exist because of the way we are.
Yeah. I don't think it was out yet. Yeah, exactly.
And, uh, a common thing I would hear back then, uh, was, Hey, why would we send our traffic to you, uh, for inspection? Why, why wouldn't we do it on-prem? Right?
'cause everyone had those on-prem, uh, appliances back then. The shift to public cloud was also not that aggressive. It was starting to happen.
So truly Jay had that vision, like, when things will move out, uh, you really need to have a central place, uh, where no matter where the users are, we're able to apply security consistently, uh, whether they're at home, whether they're in office, whether they're traveling. And after Covid, it became an obvious thing. Like nobody's able to now go back to that, uh, hub and spoke architecture 'cause you are not simply able to scale.
Absolutely. You know, I remember moderating a panel on, uh, it was, uh, American's Growth Capital, the A GC Partners Conference. It was always during RSA, and Jay was on my panel, and this was 2009, 2010.
And and you're a hundred percent correct. He said, look, there's gonna come a day where everything doesn't get backhoe back to the central office, where you're not gonna have these big honking boxes there that are gonna look at everything That, and, and he didn't say people would be working from home as much as he thought you wouldn't have central offices. Instead of having a hub and spoke, you would just have a awful lot of spokes and it didn't make sense to bring it all back.
Right? You would, you would move inspection closer to where, wherever the people were, whether it was in their house or at a branch office or at a customer, a partner location, right? There was going to be a, a, a cloud close by that we can do this at.
And I remember the other folks on the panel looking at him like, yeah, sure. Right. You know, what is this guy?
What kind of, what is this guy on? And, but you know what? Jay Credit, he, he called that shot and he saw it, and, uh, and, and nothing's been the same.
Right? And there's big reason why Zscaler is what Zscaler is today. Uh, of course.
It's so much more than that. Now, go deep, and you guys have thread intel and I mean, there's a, there's a lot of different pieces to the Zscaler security solutions that platform, whatever you want to call it. Uh, part of it is, is your current labs division, right?
And, you know, your own research. Why don't, if you don't mind, we're gonna jump into this threat report that you guys recently came out with, but before we do, if you wouldn't mind, give people a little insight into Threat Labs. Yeah.
So Threat Labs, um, I had the pleasure of, uh, um, building a team. Um, it's, it's a team of global security experts across seven different countries now. And, um, the way we build a team, it's actually, um, uh, four different groups and they're aligned with the four stages, four important stages of the attack.
So there's a group of researchers that are just focused on phishing, the initial access piece where the threat actor is trying to get in the environment. So these folks are heavily, uh, focused on countering that aspect, tracking the campaigns around phishing and, uh, exploit kits and things like that. The second group focuses heavily on vulnerability.
So these are zero day vulnerability exploits. The goal over there is to make sure, um, not only do we protect our customers from, uh, exploitation attempts, but also partner with some of the vendors out there where we see some of the, um, software bugs, defects being abused. The third is our malware group.
Uh, that's where we have folks that are, uh, experts in tracking malware payloads, whether it's malware impacting, uh, PCs, uh, Mac or even uh, mobile devices, uh, which is one of the report that we'll talk about today. And then the final group is focused on tracking threat actor infrastructure. So this is our command and control group, and the intent over there is we wanna make sure we're getting intelligence and coverage added into Zscaler platform to break the attack at each of these stages.
Uh, 'cause look, uh, you do have opportunity to prevent some of these advanced attacks if you have the right intel, right coverage done at each of these stages. Absolutely. And, and that's excellent.
com and look up for Threat Labs, or is there a specific place? com. Uh, either of those, uh, will lead you guys to all the great work that the team publishes.
Um, you will be able to get access to some of the tooling, uh, that the team has built and open sourced as well. com. Alright.
I think we've done our foundational work here. Na, and let's jump in. You mentioned this 2024 report, mobile iot, OT threat report.
Um, tell us about it. Yeah, so this is, uh, our annual report, uh, where the focus is on threats targeting mobile devices, iot, o, ot, uh, infrastructure. Uh, so we'll look at things like mobile malware, uh, even things like phishing campaigns, which are specifically tailored at mobile users, uh, with the intent of either compromising the identity, uh, or the device itself leading to, uh, future attacks, uh, on, on the real infrastructure.
Uh, similarly on the iot, uh, side, the goal is to gain that entry point into the infrastructure. So you may have an iot device that is exposed to the internet, or, um, a relatively weaker technology that leads the attacker to those untouched devices. We, we look at all the global telemetry from Zscaler.
We also collect telemetry from the research and tracking work that Threat Labs team does, and, uh, give an annual snapshot of that. So we published that report, uh, in October for, for what we saw in, in the previous, uh, one year. And, uh, so the key findings, if I may go through them, um, sure, number one, number one was, uh, uh, financially motivated attacks.
Uh, we were on the rise, uh, this is, uh, no surprise. The, the, um, the number one malware category that we saw was, uh, banking malware. Uh, that was, uh, a 29% growth.
Uh, there was also about 111% growth in spyware. And both of these are financially motivated, and their, their goal is either they will trick the user into providing the credentials, uh, using the malware that get installed, or they will make the user click on certain things and, and make them sign up for some premium service that will result in the threat actor getting paid out. So that was number one.
Number two is, uh, we saw campaigns where the goal was to bypass MFA. Um, and, and this is where phishing attacks, where the pages were tailored for mobile screen factor, um, and, uh, they will be able to steal the MFA code. Um, this is where using a stronger form of MFA becomes very, very critical.
If you're using SMS based MFA, if you're using, um, even, even, um, the authenticator app based MFA, uh, there are kits out there that are able to bypass that and, uh, take over the identity. The third, and this is, uh, not, not a concerning one, I would say. I mean, yes, the number wa number looks high, but over the year, the team discovered 200 plus fake applications on Google Play Store.
Uh, these are all Android malware payloads that the threat actors were able to upload to Google Play Store. And when we discovered this, we work very closely with Google's android security team, and, um, they do a good job of responding quickly. They also have ability to remotely remove these, but these 200 applications jointly accounted for about 8 million installations.
So these are 8 million devices, uh, uh, or or around about that Compromised Exactly that had the malicious applications installed. So that, so the third one, yes, go ahead. Yeah, so let me put a little context here.
Mm-Hmm. Look, when we talk about app stores, there's two app stores. There's the Google Play store and the iOS, you know, we have OTT an OTT app, actually, we had an OTT app, we pulled it.
We're putting a new OTT app up as we speak. And so we've had to go through the process of putting an app into both Google Play Store and the iOS Apple Store, as well as Roku and Amazon. Um, and they're, you know, to be fair, literally millions of apps are on these play stores are on these repos, right?
And a large percentage of the work in getting an app put on is automated of, of human never looks at it, and it's all automated, right? However, however, even more so than like code repositories, apps on a app store like this have a certain trust level built in. People see it on there.
They, they think that whether it's Apple and iOS or Google and, and Android, the, the, the, the powers that be have checked these apps and made sure that they're safe. 200 isn't a lot in the big picture, but it's still 8 million installs, 8 million people compromised. And for something that quite frankly shouldn't be, right?
They, why can't we do a better job of removing malicious apps or not even letting them in to begin with, right? And I'm not here to say Apple does a better job of it than Google. Uh, they in fact might, but what, what, what's, what's the, the vulnerability there that allows this to happen?
Yeah, look, uh, there are a lot of technical nuances on on this one. Um, Google has done a great job over the years of automating the vet vetting process. When someone uploads the app, uh, it does go through an automated pipeline.
Uh, but the internet actors also continue to evolve their tactics. So, uh, a simple example that I'll give without, uh, you know, geeking out our audience is, uh, a payload, which, which is, uh, an app that is getting uploaded when it gets uploaded, downloads a next stage payload, which is, uh, legitimate and does what the app is supposed to do at the time of submission. The file that gets downloaded from the remote destination is all legitimate.
Everything is good. Um, it gets approved, it gets uploaded. Uh, and I'm, I'm, again giving a very simplistic scenario over here.
Uh, this is in a way handled now, uh, but after the app gets uploaded, people download it, the, the next time the app visits a destination, they're able to switch the package that gets delivered and they're able to do interesting things on the end point. Now it's more complicated than how I described, but that's one way of thinking, like, okay, when the wedding happens, everything is good, it's doing what it's supposed to do at a certain stage, it starts doing, um, um, you know, the anomalous stuff or the malicious activity on the user endpoint. So Let me play devil's advocate, and again, I don't want to get too far in the weeds, but we got a technical audience.
You, you upload an app to my play store and I see your payload, you know, the check some on your payload is such and such, and now all of a sudden when you upload that app, your check something's different. Immediately I red flag you and say, why is your check something different? So, so Alan, it's not the original payload, it's the next stage that it downloads from a remote destination.
The payload remains the same, that gets uploaded, that gets installed, devices, it's, it's the Next, it's where it's pointing to on the one Yes, I gotcha Exactly that they're able to switch it. Yeah. And, and, and it's, like I said, it's not as simple as that.
They will also check the destination, all of that. But, uh, they're using certain techniques, uh, to, to basically embed a package, uh, on these devices using that original app and, and install malicious. Uh, So the moral and the lesson of this story is just because it's on these download sites doesn't necessarily mean it's safe.
Yes. Uh, look, I I would always still recommend all download these apps from official play store. That's the safest.
There's many other app stores out there where things are backdoored malicious. They will claim to give you free version of things that are available on Play Store. But there will be lot more to it than, than than the claim.
Nothing Is free, right? Yes. The one advice, uh, and and honestly this is one of the way our team tracks as well, like you should, I mean, if, if you are trying to download something that that's not that popular, uh, you should at least take a look at some of the comments.
'cause you will often find users, we've been downloaded, installed, complaining about the app that's not doing what it's supposed to do. And, uh, at times that gives away now even after the user realizes they downloaded something that's not doing what it's supposed to do, because the malware is already installed, they're not able to get rid of the actual component in, in many of the scenarios, but at least it gives a hint to the next user that falls for it. Yep.
Ethan, we're going down the rabbit hole here. We're at, we're at 20 minutes on our 15 minute interview. Um, let me, we need to wrap up a little bit for people who wanna get more information on or maybe download the whole report and take a deeper dive.
Where, where can they get it? com. The report is very, very detailed.
You will get breakdown by industry verticals. These guys are going after what type of malware categories we are seeing. Uh, there are many more best practices, recommendations including tech Stack that enterprises can deploy to protect their employees against, uh, some of the threats that we have, uh, outlined in the report because it's just an entry point, uh, the next goal for these attackers when the target your employee is to get into your infrastructure space.
Agreed. Deepen, thank you so much. I appreciate, I know we kept you over time, I apologize, but thank you for coming on Techstrong tv.
Maybe we'll talk again soon, whether it's at some conference or here on Techstrong TV RSA. You'll be in a few months. We working on that right now actually.
So, um, but thanks for all you and the Zscaler threat research team does. Thank you, Alan on ation. Thank you.
All right, deepen this I chief Security Officer at Zscaler talking about the threat Labs 2024 mobile IO, OT and OT at Mobile IOT and OT Threat Report. com. Is that right?
Get it from there. We're gonna take a break on Text Trunk tv. We'll be back in just a moment.