Deepen Desai, Zscaler | RSAC 2023
Deepen Desai joins Mitch at RSA to discuss the Zscaler ThreatLabz 2023 Phishing Report.
Transcript
This is texturung TV. Hey, welcome back to rsac here in San Francisco. Rsac 2023 rear Moscone West in our broadcast alley Booth with the tech strong interviewees conversationalist people that are speaking talking all kinds of great folks, which I do have a pleasure of being joined by one another one of our great folks who are on today.
Deepan Desai who is headed Global ciso and head over your research and operations organization at zscaler. Welcome. Thank you.
Thank you for having me. That's a lot of things to do a company. So introduce yourself and tell us a little bit more about what you do there and what you see scaler does sure so deep into high on the global system and head of security research.
It's part of my job. I'm responsible for making sure the global z-scale Cloud infrastructure and products are secure and then I also have a team of Global Security Experts that's tracking through that landscape and the goal over there is to make sure we're Detection intelligence to our platform and protect thousands of organizations. Globally.
Fantastic. What's your background curious to work? How do you come to the security industry?
Yeah. I've been I've been in the security industry since the beginning so it's been almost 20 years now always been on the vendor side of the house building products building newer detection Technologies and always on the security side of the house. Well, that's comforting being the global ciso that you've got that all that expertise and experience bringing with you to know.
Yeah, you have to do you have to have the best security yourself, you know customers accounting on it for me. Yes. So talking about the threat landscape you all just issue to 2023 report about that.
So tell us a little bit about the report that's an annual thing that you do and maybe just to start off with what were some of the themes that came out of it. Right. So we just published as a flash week our annual fishing report we do this every year.
So as part of this report the threat lab scene the security research arm took a look at the entire 2020 to security events campaigns that we saw out there and these were campaigns mostly targeting Enterprises and different industry verticals. 2% increase in 2022 compared to the year before fishing as everyone know is the starting point many of the attacks. These days are multi-stage attacks gone are the days where they will just send a malware binary in the email and pop you this is the stage one where after they've done the Recon.
They know who they're going after that's why the fishing attacks come in and we've seen lot of evolution in the tools tactics procedures that these cyber criminals are using in order to make these fishing attacks successful. Interesting. I wonder what are some of the reasons why you we see this increase obviously because it works right if it didn't work they wouldn't do it.
But why why is it working more frequently? Where's more where we more susceptible to click on something or you know catch us mission Attack on text, right? So then I'm multiple reasons.
I'll start with the couple areas where we saw a lot of success and then the technology that the bad guys are using to make these attacks successful as well. So all in all we saw Microsoft properties being one of the top most targeted properties in terms of getting access to the credential so think of Office 365 one drive SharePoint, the second one was the crypto exchange binance that was another one that they went after and the goal over here is once they are able to get those credentials. There are then able to perform Financial scam they're able to perform data theft by logging into the Is Enterprise accounts and also use it to perform stage 2 stage 3 attacks?
Right phishing attacks? Don't stop just with credential theft it leads to the next stage attacks in many of the cases. It will lead to things like ransomware and info stealer getting planted inside the environment.
Another reason why we're seeing a lot of these attacks becoming more successful like back in the days. We used to tell our users. Hey, look at the padlock sign right in your browser.
Make sure you're visiting the site don't click on links that appear from someone that you don't know unsolic cited emails. What we see now is these folks are leveraging, you know, the cloud storage service providers like whether it's Microsoft One drive or Dropbox or Google or AWS name? They take advantage of the Wild Card certificate that these popular vendors offer for the storage service.
The fishing page is hosted over there. If you look at that green padlock sign, it will be all good. It will have a wild card issued by one of these Azure or gcp.
And then the pages are very very sophisticated like they're leveraging AI ml to generate some of these Pages automatically and at scale. And once the user Falls for it. We're now seeing the thread actors also able to bypass things like multi-factor authentication.
I'll talk a little bit more about that as well. Now, why is this problem growing? The number we're one reason is the Advent of fishing as a service.
There are a lot of fishing kits open source commercial that are now being offered as a service. So you don't really need to know everything in order to conduct these large-scale attacks. We just subscribe to one of these as a service model and you have you know off the shelf things already set up for you.
You just put in the Target and then you have a control panel where you can log in and all the victim information is at your fingertip. It really is a business essentially. We had some a gentleman on who does after the incidents happening.
He's talking about how many of these kids it's not just kids go download something. It's like there's even support for some of the fishing kits another attack tools that you can use. It's pretty amazing.
I mean, it makes sense why it's gotten that to that point, but Yeah, I'm not sure. I wish everyone here but we are right. Yeah.
Yeah, and and yeah, I mean some of the if I may there are a couple case studies that I'll talk about number one, and this was This was sad concerning but they were going after folks that are getting laid off and I was one of the scam that threat lapse team discovered in Feb March timeframe job scams are not new but these these attacks that we discovered were specifically targeting tech industry vertical where folks were being laid off and they will go to those employees with a job position that some of the other companies have live on their side and and the end goal over here is to scam them. They're getting all their pii information and they will also ask them to pay money to ship it equipments offer training and stuff like that. So that was one the second one and this was very very targeted in nature is where we saw combination of mission, which is fishing being delivered over SMS.
And wishing which is voicemail fishing, right? So what we saw was a lot of exacts. I mean, I'm giving an interview right now, right?
I'm like, hey, this is deep in the side. They will take that voice snippet or they could even use AIML to generate that. They will then make a call to the victim.
So you are the victim. They're trying to fish they will make a call to you and they will use that snippet. Hey, this is deep into sigh and then it will cut it off.
So you will get a voicemail with my my real voice that's sort of an authentication right they're trying to do and then they will follow it up with text messages where they will say. Hey, I'm having a bad Network issue over here. Can you do X Y and Z and that's what they they scam the end user.
You have to go do a deep fake exactly feel our own voice exactly. Interesting. So let's talk a little bit about obviously we need to do some things differently to be able to defend ourselves against ourselves and our customers our users.
What are some of the new things we can do now or need to start doing? So I'm sure everyone's been hearing about zero trust. It's been used and abused is what I'll call it.
But honestly the answer over here is two things one is you need to have a zero trust architecture implemented and I'll explain what that entails that's number one zero trust architecture. Number two is continuous security awareness training as well because you need to let the end user know and at times you should have an architecture that allows you to train the user at the time. They're about to make that mistake.
So you get a link you click on the link. The architecture should prompt the user that they're about to visit something. That's not Office.
365 right? That's very very important. Zero trust architecture the way I when I talk to Security leaders, I always ask them.
Hey, it's a journey right? It's not like a flip of a switch and you're now zero trust. There are four major buckets that you should look at number one is what are you doing to eliminate your external attack surface or reduce your external Tax Service the attackers go after things that are exposed to the internet right when they're planning an attack number two is do you have consistent security controls in place?
To prevent compromise no matter where your employees or users are whether they're inside the office traveling or working from home, which is what the era of our world today hybrid environment. Number three is what is your blast radius? There will be a tax that will be successful whether it's fishing or any other attack.
You need to have a true zero trust architecture Implement which will have segmentation that will prevent and contain the threat on the asset where it successfully manage to compromise. So no lateral propagation should be allowed and that's really the difference between an incident and an all-wide breach when you when you have proper architecture implemented and then finally, they're all after your data right even fishing attacks. Once they have your credentials.
They're gonna steal your information. So you need to have a consistent data loss prevention scanning enabled with full TLS inspection for anything that egress is your endpoints your assets your server environment your Cloud workloads. That's that's important.
So Illuminate external attack surface prevent compromise prevent lateral movement and prevent data acceleration and you mentioned PLS workload like everything's encrypted now. So yeah. Yes, we want that little padlock that simple, you know moniker up there for for end users to know that it's encrypted but that all means we don't have visibility into the stream unless unless you perform TLS inspection and that's where you know zskiller helps thousands of organization.
You need a cloud native proxy based architecture where your terminating the connection in the cloud you're making a connection on behalf of the user and you're inspecting everything that flows in and out and the goal over here is very simple. Don't let anything bad get in and don't let anything good leak out and that's that's the end goal. Fantastic, so you've been doing security a long time been to RSA many times.
What's the kind of the vibe? Would you picking up from RSA? It's very different than last year last year was sort of kind of subdued and are we coming back or not this year as a much much bigger energy bigger Vibe.
I think a lot. Yeah a lot of good activity good Talks, by the way, I will I was gonna ask you're doing a talk, right? I'm doing a talk as well on and it's actually focused around fishing how tread actors are able to bypass multi-factor authentication.
We're actually going to do a live demo. Hopefully demo gods are with us, but there will be a demo of how adversity in the middle attacks are being executed in the wild but coming back to your I mean, there are a lot of good topics. I think public Cloud Security will remain at the top Insider threat is another one that's actually a priority for me as well for for securing our And then the third is openai the chat GPD, right?
How are you going to harness the power of large language models. We're doing a lot of stuff in zscaler as well to to make things efficient help with thread detection and also help our customers right where they're able to make better decisions. But at the same time how to do it more securely you're seeing reports of companies inadvertently leaking proprietary information because they don't understand well how those things function right?
So I think that will be another one to watch out for I think too. Maybe it's already happening but just like we can generate code through chat GPT. We could generate fishing kits and code to do all that.
It's gonna become easier, right? Exactly. Yes.
Well, good luck on your talk and your demo. That's great. People love demos.
Love to see something working. Thank you. Thanks for taking time to stop by and talk to us about the report books can download it at the zscaler site.
Yes. com. And that's where fishing report will be available to download.
We also publish our research on anything new that we discover, right? And these are not me too blogs. These will always be something that's new and unique where we have perspective in terms of what ttps were observed in these campaigns.
Yeah, great. When you have a research team like you do you can do that don't have to republish other people's blogs. Well, thank you.
Do you find this been great and again good luck with your talk and thanks just coming by do you find decide who is global CSO and head of the research and operations at zscaler? Again, we say we have fantastic guests another perfect example, and we appreciate you sharing with us. We'll be right back don't go away.
If you are here at at rsac go out and check over and check out the devops connect devsecop session happening in Moscone south on 308 and a lot of good stuff happening there too. And Look up the pan session on Thursday. Take care.
We'll be back. Thank you.





