Unmasking Robin Banks with Hank Schless of Lookout
During this interview, Hank Schless will discuss a new phishing kit targeting customers/users of financial institutions and crypto exchanges. “Robin Banks” operates as a phishing as a service (PhaaS) and leverages MFA bypass as one of its core tactics. Robin Banks provides yet another example of how MFA is not as bulletproof as people think – as proven by Scattered Spider and other threat actors working bypasses into their attack chains.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm really happy to have a first time guest on our show. Uh, I want to introduce you to, his name is Hank Sch Less. Hank is the Director of Global Security Campaigns at Lookout.
Hey, Hank, welcome to Text Drunk tv. Great to have you on. Thanks A lot, Alan.
Glad to be here. Glad to be your first timer. Absolutely.
So, Hank, as we were talking about off camera, not everyone on here is gonna know who you are. Maybe there's a few that, you know, you gave a heads up. Hey, I'm on text drunk.
But, uh, why don't you, why don't we start there? Why don't you kind of give our audience a little bit of the Hank Scheff story? Sure.
Um, so let's see where to start. Um, so I've been at Lookout now, uh, just over five years. Actually.
Just had my, my five year anniversary a couple, a couple weeks ago. Um, and in that time, I've, I've really, uh, been focused on helping people understand, you know, why it started when we were just a mobile security company. Why is the mobile device such a critical part of, you know, the greater security strategy?
What are the real risks around mobile? Um, and then it's been really interesting over the last five years watching that evolve as Lookout has evolved, right? So, um, you know, since then we've moved into, um, the Secure Services Edge, SSE, uh, industry or, or space as well.
Um, so, you know, especially in the last probably 18 to 24 months, it's really been helping people understand how those two things work together, right? We really look at things from the aspect of what is that modern kill chain and how does that tie into the modern data protection strategy where you have so much more, and we're gonna talk about this today, so much more, uh, occurrence where, uh, or so many more occurrences where mobile is actually becoming sort of the preferred initial threat vector for an attack, but not just stopping there, really, you know, targeting users to get their credentials and then, you know, the attacker spins 'em around their desk and then tries to log in, you know, to, to corporate apps or corporate infrastructure. And then suddenly you kind of have the formation of this full, uh, of this full modern attack chain.
So that's, you know, and, and I find it fascinating for one thing, I love, uh, working with the folks here and learning about, you know, all the threat intelligence work we do, finding really, uh, really interesting stuff that because of the size of our mobile dataset, only we can find. And then, uh, you know, speaking to the folks who are more focused on the cloud side and saying, Hey, how did these things tie together? And then helping people understand that.
So that's really where my passion lies here and what I've been doing here for the last few years. Love it, love it, love it. Now, Hank, I, you know, I, I've known about Lookout.
I've been familiar with Lookout for many, many years. I, I had a good friend of mine, Mike Murray. Unfortunately, he's not with us anymore.
Great men. Great men, Yeah, Mike. So I knew Mike from the early two thousands.
I knew Mike about 20 something years. Um, so, you know, he, he introduced me to Lookout, and I of course spent a lot of time and we covered Lookout a whole bunch, but we haven't heard from Lookout lately. So it's, it's great to get an update, if you wouldn't mind.
Now, not everyone out here knows Lookout though, you know, so why don't, for, if you wouldn't mind give people sort of a, I mean, you, you, you kind of wove it into your own story. Mm-Hmm. But it, it really used to be just a, it was a mobile security play, right?
And now, as you said, you've incorporated Edge security as part of it as well. Um, but the other thing about Lookout that I don't, and I'm sorry to put words in your mouth, if I, if I'm wrong, Correct me, You know, but the other thing about Lookout is, you know, from a thread, intel security research point of view, before it was a cool thing to do. Lookout was doing that.
Mm-Hmm. And, um, if you don't mind maybe a little bit about that. That's a, I'm, I'm happy you asked about that.
And, and I'm happy that you knew Mike because he was a, an, an intelligent, incredibly intelligent, uh, man. And he actually, when I first joined, uh, I only had about a year or so working with him, but it was really, he really sparked my, I mean, I've always been interested in security, but he really got me fired up about that threat intelligence, uh, stuff. Mm-Hmm.
And really, and really what it 'cause because the interesting thing was that it was always about what it could do for people, right? It's, it's always interesting to find things. And, you know, we've, we've found, uh, you know, almost 2000 novel malware, mobile malware families over the last, uh, I guess it's been now decade or so.
Um, but if, and that's all great, right? But if you can't, if you can't help people understand why it matters, you know, what's the point? I think one thing he did a really good job of was helping people understand why it mattered.
And so, when I think about the research that we do at Lookout, um, the cool thing with mobile is that it really spans so much, right? We, we do a lot of research into, um, you know, what nation states are doing. Um, in particular, especially over the last few years, we've seen a lot of, we've made a lot of discoveries around state sponsored surveillance wear of certain populations.
So for example, uh, Chinese sponsored surveillance wear targeting the, the Uyghur Muslim population. And, and everyone knows what's, you know, what's going on over there. Um, we've seen, you know, similar things where, um, you know, the, the nation state itself is understands just like how every cyber criminal understands that everybody has a phone, right?
And if there's a way that you wanna compromise the individual, right, which is really where we're seeing these attacks shift, then the easiest way frequently to get to them is through their phone, right? And so the threat intelligence that we do is, has really evolved where, you know, we're really starting to see and follow the trend of these attacks are really more focused on the enterprise now. So when you have, and the advantage, honestly, that we have is that we have the world's largest mobile security dataset, bar none.
Um, we're just about to, um, pass 300 million mobile apps, uh, that feed, um, our set. And what that does is that it gives us, so in addition to the apps, we have, uh, about 220 million mobile devices and over 400 million what we call web items. So URLs, certificates, things, things like that.
Um, and what you can do with all of that data is not just tie it all together and say, okay, we have this, all this telemetry, all this information to be able to correlate activity across the mobile surface, but also understand where there might be a mobile component of desktop focused, uh, malware campaigns as well. We just made this discovery, uh, few months ago about, uh, a PT 41 who is a well-known advanced persistent threat group. We actually discovered a, an Android component of some of their more, uh, more frequently used, uh, malware campaigns, surveillance wear campaigns, et cetera.
So it's really starting to span out from just looking very narrowly at the mobile device and really spanning out at, at pulling it into, again, like I said before, that modern kill chain. Absolutely. Thanks for that, Hank.
Hey, we're going to, you know, we're gonna continue in that vein with a new threat that, uh, the team discovered. Before we do though, for anyone who wants to get more information on lookout security, what's the URL they should go to? com.
We'll take you to our, uh, our company page. If you're interested in reading more about our threat intelligence, um, you can either go to that URL and then in the top right corner there's a, uh, a button that says Visit the Lookout Threat Lab. We actually just released this, uh, a couple weeks ago.
com/threat hyphen intelligence. Um, and in there is where you'll find a lot about what we've discovered, uh, the data that we see out in the world, and then also our take on a lot of other, you know, it's, it's inevitable that other people discover things too, right? So, um, our take on a lot of, of those attacks and really just helping people understand how vulnerable the, the mobile, uh, the mobile surface is.
Excellent. Alright, Hank, we got all that outta the way. Let's jump into now what we wanted to talk about today.
And that is a new threat discovery around, um, Robin Banks. Well, I, I'm gonna assume a lot of people in our audience don't even know what Robin Banks is, so maybe we should start there. Alright, so, um, so Robin Banks is a phishing as a service kit, which is an interesting, you know, everything is as a service these days.
Um, we've seen these phishing kits pretty, you know, they, they pop up very frequently. Um, but the interesting thing about this is that, uh, Robin Banks targets, uh, financial institutions and cryptocurrency exchanges. Um, and this is actually the discovery we made was, um, an additional discovery.
Um, Robin Banks was originally, uh, discovered about a year and change ago, but then they basically went underground. And then, uh, one of our researchers came across some, some interesting developments, uh, seeing some, uh, similar URLs popping up on different, uh, on different, uh, cloud providers. Um, the, the actors basically went, uh, to, um, I think it was, uh, orange based in Rome, not Romania, I can't remember exactly where it was, but, uh, you know, basically diversified where they were, uh, where they were hosting the, the malicious sites used, uh, to deliver the, the phishing kit.
Um, so that was sort of the first tip. And then the second thing we saw, which was really interesting, was that the attackers are developing the, the kit to now include, uh, what's called an MFA bypass. So multi-factor authentication bypass.
And I think this is, you know, we can dive into this a little bit more if, if you'd like, but what's really interesting is that, um, so Robin Banks is, is kind of another instance where we're seeing attackers use SMS, in this case, text messages as the way that they deliver the phishing link to the individual. Um, it's another, you know, again, another instance of that, uh, trying to compromise credentials. And this is actually not so different from, you know, everybody heard about the attacks on Caesars and MGM, uh, earlier in the year those started with a mobile phishing attack.
So we're seeing, like I said, we're seeing this more frequently. So what's really concerning about Robin Banks in particular is that it's capturing those user entered, uh, MFA tokens through it, it uses some actor in the middle capabilities, uh, with a proxy. And again, we're seeing this with more frequency.
Um, and attackers are actually getting a lot better at exploiting the mobile device. And since it's usually the second form of authentication, being able to circumvent those, those MFA solutions pretty directly, That's why we can't have nice things, right? Um, yeah.
So as iPhones get more expensive, they're just gonna get, you know, they're more proof of that. Yeah, I, I hear you. So, Hank, what are we to do?
What, what can people do here to be on guard? I mean, the usual, be smart. Don't click on links that you're not familiar with.
Mm-Hmm. You know, email, unsolicited email, stuff like that. Right?
Right. I mean, I think that all, look, all of that advice will forever hold water, right? Um, if it's sort of what, you know, like if you have a gut feeling that, that this is a weird message, the odds are it probably is.
Um, you know, things like, don't be scared to report to your security team that you think you might have received a phishing link. It could, it could save the whole company. Um, but I think what's really important is at, at, at the executive level.
'cause I think that, I think that sort of the, the practitioner manager, director level people understand that we're seeing a lot more of these, of these attacks, right? Because those are the people who have the visibility into what's, what's actually going on. But the thing that's, that's challenging is that that visibility doesn't always exist on the mobile device.
And again, I'm focusing on mobile here. 'cause that's, that's really where, uh, where the actors behind Robin Banks are, are focusing their initial, initial steps in the attack. And so I think it's really important at the executive level for CISOs, CIOs, et cetera, um, even, even CEOs, right?
To understand why mobile plays such a critical risk in that modern kill chain. I know I keep using that term, but I think it's so important and also that that greater data protection strategy. So the first step, like I said, is even just to have visibility into what's going on on those mobile devices.
I mean, you, you can't say something's wrong or right if you don't, even if you can't even see what's going on there in the first place. And then as you have that visibility, really making sure those devices are protected. So, you know, the pushback we get on that a lot as well.
I use, I use MDM mobile device management, right? But those solutions, the thing I always say to that is those solutions are called management solutions for a reason to really get that visibility and protection, you need to look at mobile threat defense, right? MTD is, is is the, uh, solution class for that.
And, you know, because without, I would say that without that visibility, you're basically missing a critical set of, of data points that would help inform your greater, uh, security strategy. And what's more is that, uh, actually protecting against mobile phishing attacks, like this one, like Robin Banks actually isn't that tough. If you have the right solution in place, it's, it's, it's pretty straightforward.
Um, but you just kind of, it's almost, uh, you know, understanding that there's this sort of last unsecured frontier, right? That everybody, like I said, everybody has a phone. So whether you issue those phones to, to your employees and they have to use certain ones, or you use, I mean, hey, I use my, my personal device for work, right?
But I have look at on there, it's, you know, it's sort of like you have to make sure that regardless of how you choose to allow your employees to work from anywhere, access data from anywhere, that whatever they're using, whatever endpoint they're using to access to that information is, is properly secured. Got it. Hank and, and I'm not looking to point fingers at a particular country necessarily, but the folks behind Robin Banks, you know, where is this a nation state thing or is it more of a cyber crime gang or, you know, financial gain kind of thing?
Yeah. You know, the interesting thing about them, that's a, it's a good question. Um, the interesting thing is that, like I said, this is a, a phishing kit that's available, right?
Um, so no, it's not nation state sponsored in, in fact, what's interesting about this is that the fact that a, a phishing kit like this that could be available to really any, uh, any cyber criminal of any level contains this MFA bypass tactic, which in my opinion is sort of more evidence of you see this happen, MFA bypass used to be something that was a pretty advanced technique. And really to your, to your, you know, to your point Alan, like something that we may only see that, you know, in advanced, you know, cyber crime group, a PT nation, state backed group, whatever it may be, would use. But as is frequently the case, there's sort of this trickle down effect where it's now becoming more broadly available to sort of your everyday cyber criminal.
And so, um, the other thing too is that it's, the thing with these kits is that they can be very easily tweaked to fit the needs of whoever is using it. So while right now we're seeing this phishing kit identifies Robin Banks targeting financial institutions and cryptocurrency exchanges, right? We could very likely see, and this is again, the great thing about the lookout having so much data, is that we could see similar artifacts, uh, in other, you know, down the road in other pieces of malware or phishing kits that pop up using pieces of this one, if that makes sense.
Um, so it's just sort of, again, when you talk about the evolution of, uh, of these kits and of the way that the ways attackers think and the tactics they use, you sort of see this, this trickle down, and then you kind of see it spread out. Um, and kind of like, you know, uh, as my, my boss just used on a call, like, like, like warm jello spreading across a plate. You just gotta see it.
Mm-Hmm. Start to spread. That's a visual.
That's a visual. Hank, we're about outta time. You know, I want to thank you for a making us smart about Lookout Big, you know, bringing, raising Robin Banks, uh, fishing as a service, uh, threat, you know, into our field division here.
Man, don't be a stranger. Come back on and keep us posted as lookouts, finding good stuff that we all need to know about. Keep up the good work.
Awesome. Thank you so much. Right to this has, this has been great.
Um, and, uh, yeah, look forward to coming on again soon. Good stuff. Hank Sches, director of Global Security campaigns at Lookout.
com and check him out there and find out more about this Robin Banks phishing as a service, that's Robin, like as in robbing banks. Um, but the little play on words, they're nothing if not clever, these bad guys. Anyway, we're gonna take a break here on Tech Drunk tv.
We'll be back in a moment.