1 00:00:00,095 --> 00:00:03,935 You found the backup wrap up your go-to podcast for all things 2 00:00:03,935 --> 00:00:06,305 backup recovery and cyber recovery. 3 00:00:06,845 --> 00:00:11,345 In this episode, we get into something that should terrify every IT and security 4 00:00:11,345 --> 00:00:13,985 professional polymorphic malware. 5 00:00:14,435 --> 00:00:18,095 This is the kind of malware that literally changes its own code. 6 00:00:18,215 --> 00:00:19,205 Its signature, its behavior. 7 00:00:19,205 --> 00:00:24,305 Even the IP addresses it talks to just so your antivirus can't catch it. 8 00:00:24,945 --> 00:00:29,775 Dr. Mike Saylor joined persona in me to break down how polymorphic malware 9 00:00:29,775 --> 00:00:35,475 works, why it's been so effective at, uh, evading detection and what the, it's 10 00:00:35,475 --> 00:00:38,205 scarier cousin metamorphic malware can do. 11 00:00:38,205 --> 00:00:39,165 That's even worse. 12 00:00:39,795 --> 00:00:43,875 Well, we also cover waterhole attacks and what behavioral detection 13 00:00:44,115 --> 00:00:45,765 actually looks like in practice. 14 00:00:46,335 --> 00:00:50,295 If you thought your antivirus or anti-malware had it covered this episode. 15 00:00:51,005 --> 00:00:54,335 Hopefully will change your mind and probably scare you a little bit. 16 00:00:54,785 --> 00:00:55,865 If you don't know who I am. 17 00:00:55,865 --> 00:01:00,875 I'm w Curtis Preston, AKA, Mr. Backup, and I've been passionate about backup 18 00:01:00,875 --> 00:01:02,915 and recovery for over 30 years. 19 00:01:03,185 --> 00:01:03,815 That's right. 20 00:01:03,905 --> 00:01:08,135 30 years ever since, uh, there were no backups of the production 21 00:01:08,135 --> 00:01:09,395 database that we just lost. 22 00:01:09,935 --> 00:01:13,800 So that's why I do this because I don't want you to do that. 23 00:01:14,190 --> 00:01:15,060 On this podcast. 24 00:01:15,060 --> 00:01:18,720 We turn unappreciated backup admins into Cyber Recovery Heroes. 25 00:01:18,930 --> 00:01:20,880 This is the backup wrap up. 26 00:01:35,993 --> 00:01:37,373 Welcome to the backup wrap up. 27 00:01:37,373 --> 00:01:40,583 I'm your host, w Curtis Preston, AKA, Mr. Backup. 28 00:01:40,583 --> 00:01:43,043 And with me, I have a guy that's starting to remind me of 29 00:01:43,043 --> 00:01:45,583 my wife Prasanna, Malaiyandi. 30 00:01:46,073 --> 00:01:46,493 How's it going? 31 00:01:46,493 --> 00:01:46,943 Prasanna. 32 00:01:49,013 --> 00:01:52,708 So basically I'm awesome because your wife is amazing, is what you're saying. 33 00:01:54,128 --> 00:01:55,268 Yeah, that's what it was. 34 00:01:55,273 --> 00:01:56,078 That was what it was. 35 00:01:56,078 --> 00:01:57,668 I was just like, you were saying something. 36 00:01:57,668 --> 00:02:00,618 I was like, man, you're starting to sound like my wife, becoming 37 00:02:00,618 --> 00:02:01,818 very predictable and how 38 00:02:01,818 --> 00:02:06,633 But in fairness, but yes, because the last episode, I was judgy mc 39 00:02:07,068 --> 00:02:07,218 Yeah. 40 00:02:07,503 --> 00:02:11,463 this time though, but be honest, right? 41 00:02:12,573 --> 00:02:14,703 You knew I was going to ask 42 00:02:14,948 --> 00:02:15,228 Yeah. 43 00:02:15,228 --> 00:02:15,738 That's what I'm 44 00:02:15,933 --> 00:02:18,903 So you did it, but you didn't actually complete it. 45 00:02:18,968 --> 00:02:19,358 whatever, 46 00:02:19,538 --> 00:02:20,648 So you failed. 47 00:02:20,798 --> 00:02:21,788 blah, blah, blah. 48 00:02:21,968 --> 00:02:23,258 Anyway, hi. 49 00:02:23,458 --> 00:02:29,128 we have also with us to watch our bickering, we have Dr. Mike Sailor, 50 00:02:29,248 --> 00:02:35,698 CEO of Black Swan Cybersecurity and co-author with me of this lovely book. 51 00:02:36,143 --> 00:02:38,363 Learning ransomware response and recovery. 52 00:02:38,363 --> 00:02:41,723 That should ship any day now for anyone who wants to order it. 53 00:02:42,063 --> 00:02:45,193 and I believe the, the electronic version is already on its way out. 54 00:02:45,493 --> 00:02:46,993 Doctor Mike Saylor. 55 00:02:47,653 --> 00:02:48,013 How's it going, 56 00:02:48,013 --> 00:02:48,223 Mike? 57 00:02:48,298 --> 00:02:48,718 everybody. 58 00:02:49,498 --> 00:02:49,773 Thank you. 59 00:02:49,843 --> 00:02:50,323 All right, 60 00:02:50,953 --> 00:02:52,153 like a married couple? 61 00:02:53,263 --> 00:02:55,183 I think we need a third party to. 62 00:02:56,338 --> 00:02:56,608 Make 63 00:02:56,698 --> 00:02:57,568 It Ha it happens 64 00:02:57,568 --> 00:02:58,258 sometimes. 65 00:02:58,978 --> 00:03:02,368 so Mike, there's a phrase that you brought up a lot in the book. 66 00:03:02,588 --> 00:03:07,163 and so I. I wanted to give you an opportunity to talk about it, to talk 67 00:03:07,163 --> 00:03:12,233 about what it is, why it matters, and is there anything we can do about it? 68 00:03:12,233 --> 00:03:16,643 And of course, what we're talking about today is polymorphic 69 00:03:16,643 --> 00:03:19,133 ransomware, AKA, the shapeshifter. 70 00:03:19,613 --> 00:03:23,063 Do you wanna start this out by talking about VeriLock? 71 00:03:23,123 --> 00:03:27,273 what was VeriLock or is VeriLock and, how does that factor into 72 00:03:27,273 --> 00:03:28,773 the, into this whole thing? 73 00:03:30,183 --> 00:03:30,423 Sure. 74 00:03:30,423 --> 00:03:36,063 Yeah, it was one of the most, talked about, polymorphic, malware, it 75 00:03:36,063 --> 00:03:41,163 functioned by compromising your computer with malware that had yet 76 00:03:41,163 --> 00:03:46,573 to be defined in a, anti-malware antivirus signature base, or heuristics. 77 00:03:47,003 --> 00:03:51,543 so it, it was designed to, to look different, to behave different, so 78 00:03:51,543 --> 00:03:53,563 that it could survive the filters. 79 00:03:54,183 --> 00:03:57,513 and it was usually delivered in a, in an attachment that. 80 00:03:59,433 --> 00:04:00,423 That you would expect. 81 00:04:00,883 --> 00:04:04,673 so if you worked in accounting, maybe it was an invoice if you worked 82 00:04:04,673 --> 00:04:09,443 in, the warehouse, maybe it was a shipping label, if you worked in, the 83 00:04:09,443 --> 00:04:13,143 computer room or the mail room, maybe it was a PO or something like that. 84 00:04:13,143 --> 00:04:18,378 So it was designed so that, you, you wouldn't suspect that attachment was, 85 00:04:18,383 --> 00:04:20,613 malware or something unsolicited. 86 00:04:21,423 --> 00:04:25,833 But yeah, when you open that attachment, the, it triggered the payload. 87 00:04:26,223 --> 00:04:32,573 The payload would drop, and start to slowly or, unsu suspiciously, deploy 88 00:04:32,573 --> 00:04:38,088 itself within the computer and start to, to, to then progress into the, the Mitre 89 00:04:38,088 --> 00:04:40,698 attack, phases of reconnaissance and. 90 00:04:41,313 --> 00:04:44,283 asset value identification spreading and those kind of things. 91 00:04:44,283 --> 00:04:50,323 So the polymorphic part of that was really designed so that, and backing up too. 92 00:04:50,323 --> 00:04:53,163 So a lot of antivirus software works on a schedule. 93 00:04:54,123 --> 00:04:57,533 So you could have the latest and greatest, antimalware in a 94 00:04:57,533 --> 00:05:00,023 ransomware software on your computer. 95 00:05:00,368 --> 00:05:07,268 Yeah, there is a period of time between infection and detection and some of that 96 00:05:07,268 --> 00:05:10,418 is analyzing how the software is behaving. 97 00:05:11,318 --> 00:05:18,698 Some of that is sending snippets of code or heuristics to the vendor and they're 98 00:05:18,698 --> 00:05:23,583 gonna sandbox it and do their analysis and then it pushes that back out as an update. 99 00:05:25,418 --> 00:05:28,808 until recently, those updates took about seven to 10 days. 100 00:05:29,318 --> 00:05:32,258 So you could be infected with something that the antivirus has 101 00:05:32,258 --> 00:05:37,788 never seen before that could maintain, persistence on that device for seven 102 00:05:37,788 --> 00:05:41,208 to 10 days before update comes. 103 00:05:41,388 --> 00:05:42,618 And that's why updates are important. 104 00:05:43,158 --> 00:05:46,128 The update comes and now your antivirus says, Hey, I found out that 105 00:05:46,128 --> 00:05:47,388 there's this thing on this computer. 106 00:05:47,388 --> 00:05:48,858 I need to clean it or quarantine it. 107 00:05:50,088 --> 00:05:51,378 So that's how it used to work. 108 00:05:52,413 --> 00:05:57,993 So now polymorphic code says, all right, now I know that on some 109 00:05:57,993 --> 00:06:01,713 periodic basis I need to change the way I look and the way I behave, 110 00:06:03,153 --> 00:06:07,113 so that even if, and I, this antivirus anti malware detected how I was 111 00:06:07,173 --> 00:06:11,103 looking and behaving yesterday, the update that comes in isn't gonna 112 00:06:11,103 --> 00:06:12,933 catch the way I look and behave today. 113 00:06:13,998 --> 00:06:15,258 Yeah, interesting. 114 00:06:15,318 --> 00:06:17,388 So hence the term polymorphic, right? 115 00:06:17,388 --> 00:06:21,108 So we morphic meaning changing and poly meaning many. 116 00:06:21,108 --> 00:06:28,078 So not only is it changing, it's changing multiple times, in a single deployment. 117 00:06:28,078 --> 00:06:29,208 Would that be the right term, 118 00:06:30,978 --> 00:06:32,148 We would call it a life 119 00:06:32,208 --> 00:06:37,538 so that, that payload has a lifespan and it would do these, these changes and. 120 00:06:38,378 --> 00:06:40,868 And I think we're gonna get into it in a little bit, but polymorphic 121 00:06:40,868 --> 00:06:46,938 code, it's coded, it's hard coded in the malware, how often to change 122 00:06:46,938 --> 00:06:48,198 the way it looks and behaves. 123 00:06:49,948 --> 00:06:54,238 could you go over what you mean by looks and behaves? 124 00:06:54,318 --> 00:06:59,868 is it, oh, I'm just changing my extension or my location where I'm running. 125 00:07:00,138 --> 00:07:06,648 Maybe it's the footprint of the malware itself, or is there like significant 126 00:07:06,948 --> 00:07:09,198 parts of the malware that change 127 00:07:09,648 --> 00:07:10,008 while it's 128 00:07:10,023 --> 00:07:13,023 changing it, it doesn't, the changing the extension or the 129 00:07:13,053 --> 00:07:15,723 file type or, or even some of the. 130 00:07:17,538 --> 00:07:22,008 The consumable content, is somewhat irrelevant to antivirus, antimalware. 131 00:07:22,388 --> 00:07:26,328 those tools are looking for, file type headers, the flags that say, 132 00:07:26,328 --> 00:07:29,238 even though it says it's a text file, it's an executable file. 133 00:07:29,868 --> 00:07:33,898 really what the polymorphic code is doing is changing the signature of 134 00:07:33,898 --> 00:07:36,448 the malware, and it doesn't take much. 135 00:07:36,498 --> 00:07:41,838 for example, If I install malware and it's hard coded to communicate back 136 00:07:41,838 --> 00:07:47,158 to a command and control server at a particular IP address, that is part 137 00:07:47,158 --> 00:07:49,978 of the signature now of that malware. 138 00:07:50,548 --> 00:07:56,638 And so when the update comes anti-malware gonna go, Hey, that file contains that 139 00:07:56,638 --> 00:08:00,028 IP address for a known bad command and control, and we're gonna quarantine it. 140 00:08:00,898 --> 00:08:04,168 So what the malware is hard coded to do is say, use that IP 141 00:08:04,168 --> 00:08:05,663 address for the first 72 hours. 142 00:08:06,763 --> 00:08:09,953 And then change it to this other IP address, increment 143 00:08:09,953 --> 00:08:12,273 by one or 10, or, some math. 144 00:08:12,853 --> 00:08:15,943 and that will coincide with the threat actors changing their 145 00:08:15,943 --> 00:08:19,003 lease on the command and control server, or they build a new one. 146 00:08:19,573 --> 00:08:24,798 and so that's an example of how that antivirus update is gonna miss the change 147 00:08:24,798 --> 00:08:27,338 that this malware made, to how it behaves. 148 00:08:28,148 --> 00:08:28,508 Gotcha. 149 00:08:28,508 --> 00:08:34,478 So it isn't necessarily as an example, changing out the underlying, say 150 00:08:34,478 --> 00:08:38,438 on a window system DLLs that it's leveraging or other things like 151 00:08:38,993 --> 00:08:40,013 Oh, it could for sure. 152 00:08:40,113 --> 00:08:44,233 Notepad Plus is in the news, and so maybe it's using Notepad plus. 153 00:08:44,933 --> 00:08:49,413 and some of the related, file structures and support files that are associated 154 00:08:49,413 --> 00:08:53,503 with Notepad puts plus, and that helps it do, the first day or two 155 00:08:53,503 --> 00:08:57,903 worth of activity and then it changes its behavior to start using, the 156 00:08:57,933 --> 00:09:03,893 DLLs, in Microsoft calculator or, or, maybe from the command and control. 157 00:09:03,893 --> 00:09:05,663 It downloads additional modules. 158 00:09:06,143 --> 00:09:09,943 And so now the file structure or the file, the malware itself has changed. 159 00:09:09,943 --> 00:09:12,703 It's no longer a 150 kilowatt file. 160 00:09:12,703 --> 00:09:15,883 Now it's a megabyte file, and because we've added stuff 161 00:09:15,883 --> 00:09:17,143 to it, it's been rewritten. 162 00:09:17,323 --> 00:09:19,643 So now, all the metadata's changed. 163 00:09:19,643 --> 00:09:21,333 and there's any number of examples. 164 00:09:21,363 --> 00:09:24,843 just get creative on how you can modify how a file looks and behaves. 165 00:09:25,203 --> 00:09:27,093 And bad guys are doing that because. 166 00:09:28,503 --> 00:09:29,373 Antivirus. 167 00:09:29,523 --> 00:09:33,633 In a lot of cases, most cases, those signatures are point in time things. 168 00:09:34,233 --> 00:09:38,298 And so you've got a, you've got a period of oper, of time to operate as malware 169 00:09:38,298 --> 00:09:39,828 before those signatures get updated. 170 00:09:40,818 --> 00:09:43,968 There's even malware that detects based on it. 171 00:09:43,968 --> 00:09:48,648 It'll detect what antivirus you're using and behave differently based on that. 172 00:09:48,648 --> 00:09:52,098 So if you've got trend micro versus eset versus. 173 00:09:52,423 --> 00:09:54,623 McAfee or some CrowdStrike. 174 00:09:55,113 --> 00:09:58,443 it will just, it will identify that first and then behave 175 00:09:58,443 --> 00:10:02,593 accordingly, based on the antivirus capabilities and update schedules. 176 00:10:04,858 --> 00:10:08,118 Let's go back to, when we, you were talking about Viralock. 177 00:10:09,128 --> 00:10:12,238 one of the things I read about it was that it would send a document that 178 00:10:12,238 --> 00:10:16,248 you were expecting, but change it so that it was actually an executable. 179 00:10:16,968 --> 00:10:21,748 And this is, this is going, this is gonna happen a lot, but that 180 00:10:21,748 --> 00:10:25,888 seems like something that, that the average person wouldn't fall for. 181 00:10:26,128 --> 00:10:29,368 You're changing invoice dot doc to invoice doc exe. 182 00:10:31,108 --> 00:10:33,928 And then people gonna click on that anyway. 183 00:10:35,743 --> 00:10:40,513 some people just don't realize it and some people are just very busy, right? 184 00:10:40,513 --> 00:10:42,763 So I've gotta get through a hundred invoices today, and 185 00:10:42,763 --> 00:10:44,083 there's another invoice, right? 186 00:10:44,083 --> 00:10:45,253 So they're just trying to do their job. 187 00:10:46,158 --> 00:10:49,548 and so yeah, very often bad guys, again are taking advantage of human 188 00:10:49,548 --> 00:10:52,668 nature, Right, We're just, we're too busy to be diligent. 189 00:10:55,188 --> 00:10:58,218 when you're like, Hey, I expected that sort of document to come here 190 00:10:58,318 --> 00:11:00,018 I'm gonna ask a dumb question 191 00:11:00,068 --> 00:11:05,018 in Windows it does, it, does it have to have, do XE to be an executable? 192 00:11:05,078 --> 00:11:10,648 I know there's DLLs, but don't, doesn't it have to have XE to 193 00:11:10,648 --> 00:11:13,138 actually be an executable, or can it just run with anything? 194 00:11:14,513 --> 00:11:20,083 So there are a few file types like, self-expanding, containers, 195 00:11:20,133 --> 00:11:21,603 like a zip or a tar ball. 196 00:11:22,123 --> 00:11:27,583 so there's a couple, and it doesn't have to say EXE in order to execute 197 00:11:27,583 --> 00:11:31,703 like an EXE because again, I can call a file, whatever, I can call 198 00:11:31,703 --> 00:11:34,343 it A DLL, and it'll look like a DLL. 199 00:11:34,933 --> 00:11:39,313 Because Windows is associating the file extension with what it thinks 200 00:11:39,613 --> 00:11:41,293 is necessary to open that file. 201 00:11:41,293 --> 00:11:42,943 So that's why that icon changes. 202 00:11:43,273 --> 00:11:47,023 But if you double click on it, windows goes, Hey, wait, I thought it was a 203 00:11:47,023 --> 00:11:52,183 DLL or a text file, and I'm opening what I think is associated with 204 00:11:52,183 --> 00:11:53,563 that file type and it's not working. 205 00:11:53,563 --> 00:11:56,473 So file corrupted, file not readable, whatever. 206 00:11:57,148 --> 00:11:58,948 Because I just changed the extension. 207 00:11:58,948 --> 00:12:02,488 But if you look at the file itself in the binary, there's actually 208 00:12:02,488 --> 00:12:08,008 file type flags and headers that identify it as an executable. 209 00:12:08,248 --> 00:12:12,718 So you just have to know how to address that file as an 210 00:12:12,718 --> 00:12:13,888 executable without double 211 00:12:13,888 --> 00:12:14,203 clicking on 212 00:12:14,283 --> 00:12:16,263 What I'm hearing you say is if you double click on it, 213 00:12:16,263 --> 00:12:18,173 it's got the wrong, extension. 214 00:12:18,233 --> 00:12:21,323 It's not gonna do the thing you want it to do, but there is a way to run it. 215 00:12:21,793 --> 00:12:22,153 Okay. 216 00:12:22,483 --> 00:12:22,873 All right. 217 00:12:23,443 --> 00:12:27,753 So if I think though about polymorphic ransomware. 218 00:12:28,698 --> 00:12:35,808 Isn't a lot of ransomware implementations where you're downloading modules from 219 00:12:35,808 --> 00:12:40,848 command and control servers, wouldn't all of those fall under this classification? 220 00:12:42,793 --> 00:12:43,013 No. 221 00:12:43,338 --> 00:12:46,248 so traditional, or we would call it static. 222 00:12:46,338 --> 00:12:50,148 and correct me if I misunderstood your question, but, all of the 223 00:12:50,148 --> 00:12:56,323 additional, so there is a, the point of polymorphic or metamorphic, which 224 00:12:56,323 --> 00:13:02,118 I think we'll get to in a minute, is to, evade detection and built in. 225 00:13:02,118 --> 00:13:06,888 There is also sometimes a capability of disabling antivirus because we're 226 00:13:06,888 --> 00:13:10,558 now resident on the machine and, we can escalate privileges and. 227 00:13:11,323 --> 00:13:12,583 Issue commands especially. 228 00:13:12,733 --> 00:13:18,503 And there's vulnerabilities disclosed recently, of pretty elementary ways of 229 00:13:18,503 --> 00:13:21,083 disabling windows Defender as an example. 230 00:13:21,683 --> 00:13:22,343 so there's that. 231 00:13:22,343 --> 00:13:28,393 then all the other files I call down, are just adding to, my base, executable. 232 00:13:28,903 --> 00:13:31,733 And so it's not my executable plus five other files. 233 00:13:31,793 --> 00:13:35,513 It is my base executable that's creating a new executable and in 234 00:13:35,513 --> 00:13:38,843 a lot of cases, cleaning up after my, cleaning up after myself. 235 00:13:39,263 --> 00:13:39,623 Gotcha. 236 00:13:39,653 --> 00:13:40,943 it's always evolving, if 237 00:13:41,033 --> 00:13:41,333 yep. 238 00:13:41,453 --> 00:13:45,183 And one other thing to add about, vi lock is, that made it a little 239 00:13:45,183 --> 00:13:51,933 different is that as it infected other files, it replicated itself. 240 00:13:52,923 --> 00:13:57,093 So it wasn't just ransomware, it was also a virus. 241 00:13:57,633 --> 00:13:58,373 And so you could. 242 00:13:59,573 --> 00:14:02,693 Let's say you, you paid the ransom and you decrypted all your files. 243 00:14:02,693 --> 00:14:06,743 now all those files still have the virus in them and could very well just 244 00:14:07,013 --> 00:14:09,953 become reinfected or communicable now, 245 00:14:10,373 --> 00:14:11,123 Oh. 246 00:14:11,633 --> 00:14:13,373 others that you might share those files 247 00:14:13,508 --> 00:14:14,378 Communicable. 248 00:14:15,288 --> 00:14:17,238 now you brought up the term metamorphic code. 249 00:14:17,248 --> 00:14:19,108 how is metamorphic versus polymorphic? 250 00:14:20,923 --> 00:14:24,053 So polymorphic is primarily hard-coded changes. 251 00:14:25,158 --> 00:14:27,618 this is going to happen in 24 hours. 252 00:14:27,618 --> 00:14:29,568 This is gonna change from this to that. 253 00:14:30,138 --> 00:14:35,298 Metamorphic does its own like almost AI analysis of what needs to change and it 254 00:14:35,298 --> 00:14:37,068 does it when it thinks it's necessary. 255 00:14:37,578 --> 00:14:40,998 So metamorphic is actually a lot more scary than polymorphic. 256 00:14:41,778 --> 00:14:42,468 Interesting. 257 00:14:42,568 --> 00:14:43,768 and is there. 258 00:14:45,238 --> 00:14:48,853 An understanding of like how common either of those two types are. 259 00:14:49,853 --> 00:14:53,208 Polymorphic iss probably pretty common 'cause that's just easy to do. 260 00:14:54,138 --> 00:15:02,688 Metamorphic is like nation state, CIA scary stuff, so probably pretty prevalent. 261 00:15:02,688 --> 00:15:03,823 You just, we just don't know about it. 262 00:15:04,638 --> 00:15:09,018 Do you have an example of a metamorphic ransomware attack out there? 263 00:15:10,018 --> 00:15:12,883 And it's okay if you don't off the top of your head. 264 00:15:15,373 --> 00:15:15,808 I don't. 265 00:15:16,393 --> 00:15:16,693 Okay. 266 00:15:16,733 --> 00:15:17,023 Okay. 267 00:15:17,953 --> 00:15:21,808 When, like nothing like VE lock, like not a tool like VE lock. 268 00:15:24,728 --> 00:15:25,958 I'll keep thinking about it as we 269 00:15:25,958 --> 00:15:30,498 talk, but, I, I've got scenarios in mind without necessarily 270 00:15:30,498 --> 00:15:33,258 any identifiable names to put 271 00:15:33,258 --> 00:15:33,528 on it. 272 00:15:34,668 --> 00:15:36,228 With the stuck net. 273 00:15:37,018 --> 00:15:37,258 which? 274 00:15:37,258 --> 00:15:37,618 Which is the 275 00:15:37,618 --> 00:15:37,768 one 276 00:15:38,043 --> 00:15:40,618 Stuck Stucks nut was hard coded. 277 00:15:40,918 --> 00:15:41,248 Okay. 278 00:15:41,698 --> 00:15:42,713 so that was polymorphic. 279 00:15:43,148 --> 00:15:46,798 even, Like some of the other ransomware, like the hit target, it was hard coded 280 00:15:46,798 --> 00:15:50,798 to look for point of sale systems it would move from one asset to the other. 281 00:15:50,798 --> 00:15:53,438 Cleanup after itself behave a little different, hard coded. 282 00:15:53,718 --> 00:15:53,868 Yep. 283 00:15:55,218 --> 00:15:57,878 Yeah, I could just see, I could just see the malware like 284 00:15:57,878 --> 00:15:58,808 crawling through the thing. 285 00:15:59,108 --> 00:16:00,458 Are you a point of sale system? 286 00:16:00,548 --> 00:16:01,028 Nope. 287 00:16:01,208 --> 00:16:05,258 I have I have a conceptual example of metamorphic code and it was 288 00:16:05,258 --> 00:16:06,368 called the Frankenstein virus. 289 00:16:07,358 --> 00:16:10,758 It was developed, I'm having trouble remembering his name, but it was developed 290 00:16:10,848 --> 00:16:13,128 out of the University of Texas at Dallas. 291 00:16:13,548 --> 00:16:14,268 Oh. 292 00:16:14,688 --> 00:16:19,248 And essentially what it would do is a framework would be downloaded that 293 00:16:19,248 --> 00:16:22,788 completely harmless, like nothing would think this framework was an 294 00:16:22,788 --> 00:16:27,528 issue at all, but as this framework executed, it would look for resources. 295 00:16:28,258 --> 00:16:29,488 it would feed off the land. 296 00:16:29,668 --> 00:16:34,858 So what software, what applications, what DLLs do you have on this computer? 297 00:16:34,858 --> 00:16:38,428 And it would assemble its malware based on what's available to it. 298 00:16:39,523 --> 00:16:40,783 That's crazy. 299 00:16:40,918 --> 00:16:45,548 be an example of metamorphic, but I don't think that made it out of the lab. 300 00:16:45,713 --> 00:16:48,533 Yeah, and I'm guessing with a lot of the AI stuff, we might 301 00:16:48,533 --> 00:16:50,303 see more of this in the future. 302 00:16:50,888 --> 00:16:51,128 Yep. 303 00:16:52,098 --> 00:16:55,928 making, making mean people smarter, but being stupid. 304 00:16:56,238 --> 00:16:59,598 something in the research that came up something called a waterhole attack. 305 00:16:59,868 --> 00:17:02,838 Mike, is this, does that, is that relevant in this discussion? 306 00:17:03,753 --> 00:17:04,263 It is. 307 00:17:04,263 --> 00:17:06,243 And so it, it's similar to that one, 308 00:17:06,243 --> 00:17:09,303 to many strategy that bad guys have. 309 00:17:09,783 --> 00:17:14,793 what's my least, level of effort that results in the largest possible gain? 310 00:17:15,303 --> 00:17:21,903 And looking for opportunities to attack victims in, in how they collaborate. 311 00:17:22,458 --> 00:17:29,298 So Microsoft Teams, zoom, WebEx, slack, SharePoint, all of those are 312 00:17:29,328 --> 00:17:30,768 what we would consider Waterholes. 313 00:17:30,768 --> 00:17:36,928 We, we go to those things to, interact with coworkers, update documents, 314 00:17:36,928 --> 00:17:38,578 share documents, store documents. 315 00:17:38,578 --> 00:17:42,358 So if I can compromise that water hole, then I've got a, I've got a 316 00:17:42,358 --> 00:17:44,458 larger pool of potential victims. 317 00:17:46,163 --> 00:17:53,243 if I can infect that one, that one file in SharePoint, that everybody like 318 00:17:53,243 --> 00:17:57,653 time, here's the time sheet template or the expense template, right? 319 00:17:57,653 --> 00:17:58,703 I'm gonna go infect that. 320 00:17:58,703 --> 00:18:01,393 So now everybody downloads that to do their time sheets in their 321 00:18:01,393 --> 00:18:03,998 expenses, and I'm infecting everybody that opens that template. 322 00:18:04,233 --> 00:18:07,083 Is that because they're, there are, they're using like macros? 323 00:18:07,083 --> 00:18:08,108 Is that what you're talking about there? 324 00:18:09,168 --> 00:18:12,823 It could be macros, it could be, you know, uh, polymorphic code. 325 00:18:12,913 --> 00:18:16,863 It could be viralocker on your time sheet template. 326 00:18:17,388 --> 00:18:19,908 It's just something that a whole bunch of people are accessing. 327 00:18:20,043 --> 00:18:20,053 right? 328 00:18:20,853 --> 00:18:23,973 That's a, that's an interesting, you want to talk about the things that 329 00:18:24,033 --> 00:18:30,813 a polymorphic, piece of code does to make sure that it continues to live. 330 00:18:32,748 --> 00:18:38,268 Yeah, so well, the life of polymorphic is somewhat known depending 331 00:18:38,268 --> 00:18:39,738 on the antivirus that you use. 332 00:18:40,248 --> 00:18:44,058 And so some of the older, traditional ones that code is only gonna live for, 333 00:18:44,168 --> 00:18:47,018 a couple of weeks, if you're using 334 00:18:47,143 --> 00:18:48,713 while malware is running wild in 335 00:18:48,758 --> 00:18:49,448 a couple of weeks. 336 00:18:50,708 --> 00:18:54,638 and I'll add to that, that single deployment of that code is a couple 337 00:18:54,638 --> 00:18:59,228 of weeks, but really what happens in the real world is that code will 338 00:18:59,228 --> 00:19:05,198 likely establish access that then can be multiplied into different threads. 339 00:19:06,563 --> 00:19:10,573 And so this is, here's another example of a red teaming exercise that we did. 340 00:19:11,093 --> 00:19:14,013 and this is a, an example of that coordinated effort among 341 00:19:14,013 --> 00:19:15,723 different attack skill sets. 342 00:19:16,053 --> 00:19:20,103 So one of the guy on our team, our chief engineer, knew how to write malware. 343 00:19:20,623 --> 00:19:22,938 I know how to break into buildings and social engineer people. 344 00:19:23,858 --> 00:19:25,838 another guy is on our team. 345 00:19:25,888 --> 00:19:28,708 we call him the ghost 'cause no one ever remembers seeing him. 346 00:19:28,958 --> 00:19:31,598 so very good social engineer, but also very technical. 347 00:19:32,018 --> 00:19:37,118 So he and I together infiltrated a physical building, social engineered 348 00:19:37,268 --> 00:19:40,058 employees as if we were from it. 349 00:19:40,328 --> 00:19:44,178 So I was dressed like this with a certain tie, and so I was the IT manager. 350 00:19:44,688 --> 00:19:47,388 And he just had a polo shirt on and, with, slacks. 351 00:19:47,388 --> 00:19:51,738 And so he was the IT engineer and together we, I had my cup of coffee and 352 00:19:51,738 --> 00:19:56,923 my clipboard and together we presented a level of legitimacy and confidence 353 00:19:56,923 --> 00:20:00,413 and we just started asking people, Hey, before you leave today, it looks 354 00:20:00,413 --> 00:20:01,313 like you're getting ready to leave. 355 00:20:01,313 --> 00:20:05,093 We just need to run an inventory application on your machine 356 00:20:05,093 --> 00:20:07,643 because we're doing some upgrades to make things work better. 357 00:20:07,643 --> 00:20:08,813 We all want things to work better. 358 00:20:08,863 --> 00:20:10,183 I don't need your password or anything. 359 00:20:10,183 --> 00:20:11,533 I just don't log off yet. 360 00:20:12,608 --> 00:20:18,388 with their current session, active, plug in a self deploying USB drive, that would 361 00:20:18,388 --> 00:20:23,278 create a shell, a reverse shell from that workstation all the way back to our chief 362 00:20:23,278 --> 00:20:27,448 engineer sitting at the hotel saying, all right, got one, move to the next desk. 363 00:20:27,778 --> 00:20:31,738 And so that malware and that thread lived on that computer for a week. 364 00:20:32,128 --> 00:20:34,948 But we would do that, 20 to 50 times. 365 00:20:35,278 --> 00:20:35,458 And. 366 00:20:36,913 --> 00:20:40,408 The reason you do that persistence, that multi-threaded persistence is because 367 00:20:40,408 --> 00:20:44,398 antivirus and most computers don't all do the same thing at the same time. 368 00:20:44,983 --> 00:20:48,283 So a week from now when antivirus signatures update to catch our 369 00:20:48,283 --> 00:20:53,593 malware, we would see those persistent threads start to drop, right? 370 00:20:53,593 --> 00:20:58,033 But because we have access to that computer, we've already got the next 371 00:20:58,033 --> 00:21:01,768 payload ready, and so we deploy our next. 372 00:21:02,503 --> 00:21:08,113 Payload to one of those active threads, and then it spreads backwards to the other 373 00:21:08,113 --> 00:21:10,093 machines that were previously compromised. 374 00:21:10,093 --> 00:21:13,543 So now we get our threads back because we managed to change 375 00:21:13,543 --> 00:21:14,923 the signature of our malware. 376 00:21:15,553 --> 00:21:16,243 And so even though the 377 00:21:16,603 --> 00:21:20,353 malware may only last a week or two, because I have access to the environment, 378 00:21:20,353 --> 00:21:25,803 I just need to deploy a new, a fresh copy that the antivirus hasn't seen before and 379 00:21:25,833 --> 00:21:27,813 restart the clock on another week or two. 380 00:21:28,668 --> 00:21:30,258 So it's basically like trying to play whack-a-mole. 381 00:21:30,258 --> 00:21:34,008 So as someone who's trying to defend against this, what do you do? 382 00:21:34,218 --> 00:21:37,608 Like it seems like you're never going to stay ahead of them. 383 00:21:37,608 --> 00:21:38,178 So 384 00:21:39,863 --> 00:21:39,983 I. 385 00:21:40,083 --> 00:21:44,233 but all of those things, are identifiable if you have a baseline. 386 00:21:44,693 --> 00:21:46,253 the way that malware works. 387 00:21:47,888 --> 00:21:52,328 If you have a baseline, you can start to look for deviations from that baseline. 388 00:21:52,328 --> 00:21:54,518 So that's your perimeter IP addresses. 389 00:21:54,518 --> 00:21:59,868 You're connected to data volume, network protocols being used, 390 00:22:00,318 --> 00:22:01,308 File access patterns. 391 00:22:01,623 --> 00:22:04,763 ingress, egress, ingress egress, file integrity. 392 00:22:04,933 --> 00:22:05,893 So who touched it? 393 00:22:06,313 --> 00:22:07,303 What did they do? 394 00:22:07,783 --> 00:22:10,273 network and endpoint behavior. 395 00:22:11,053 --> 00:22:12,163 User behavior. 396 00:22:13,063 --> 00:22:16,673 All of those things you can baseline and start to track deviations 397 00:22:16,853 --> 00:22:18,053 if you have the right tools. 398 00:22:18,293 --> 00:22:20,933 And bad guys know, a lot of people don't have the tools. 399 00:22:21,113 --> 00:22:25,403 And even if you did, there's a subset of people that do that's that, that, 400 00:22:25,408 --> 00:22:27,263 that don't look at it 24 hours a day. 401 00:22:27,608 --> 00:22:28,268 Yeah, so 402 00:22:28,323 --> 00:22:32,953 what's interesting about that, that, engagement I was describing where we 403 00:22:32,953 --> 00:22:35,008 deployed all that ransomware, we did. 404 00:22:35,873 --> 00:22:37,073 We did a ton of different things. 405 00:22:37,073 --> 00:22:41,333 We had thir 12 objectives to achieve, and they gave us like 406 00:22:41,333 --> 00:22:44,063 180 days to achieve 12 objectives. 407 00:22:44,573 --> 00:22:47,183 We achieved 11 objectives in seven days, 408 00:22:47,768 --> 00:22:48,158 Wow. 409 00:22:48,713 --> 00:22:51,423 and then we spent the rest of the time helping them, identify the 410 00:22:51,423 --> 00:22:52,443 problems and fix the problems. 411 00:22:52,443 --> 00:22:55,653 But one of the problems, and this goes back to the behavior, is because we 412 00:22:55,653 --> 00:22:59,673 had access and one of our objectives was to exfiltrate a lot of data. 413 00:23:00,453 --> 00:23:04,563 And we decided to do a little bit to achieve the objective and then do a lot to 414 00:23:04,563 --> 00:23:06,093 see how much it would take to get caught. 415 00:23:06,903 --> 00:23:09,873 And in the debrief, we were talking to the firewall admin and 416 00:23:09,873 --> 00:23:12,793 said, look, do you review your firewall logs and your bandwidth? 417 00:23:12,793 --> 00:23:15,543 And he is yeah, every morning I come in, I said, okay, the other 418 00:23:15,543 --> 00:23:17,253 day we pegged your bandwidth. 419 00:23:17,943 --> 00:23:19,083 what did you think about that? 420 00:23:19,143 --> 00:23:20,523 He said, I thought it was weird. 421 00:23:20,883 --> 00:23:23,283 But then the next day when I came in and it was still pegged, 422 00:23:23,283 --> 00:23:24,243 I just thought it was normal. 423 00:23:25,903 --> 00:23:27,653 yeah, you're can't help you buddy. 424 00:23:27,703 --> 00:23:33,793 so what you're talking about there is shifting from pattern, like file pattern 425 00:23:33,793 --> 00:23:37,143 recognition to behavioral, recognition. 426 00:23:37,193 --> 00:23:38,303 I'm not shifting to it. 427 00:23:38,303 --> 00:23:39,503 But adding, so 428 00:23:39,503 --> 00:23:40,793 security's all about layers. 429 00:23:40,853 --> 00:23:43,823 What, how many things can I put between me and the bad guys so that I can 430 00:23:43,823 --> 00:23:47,183 identify things faster and respond faster before they get to what they 431 00:23:47,183 --> 00:23:49,033 want or they spread and so yeah. 432 00:23:49,528 --> 00:23:52,438 It's like when I build a house, do I just need a yard? 433 00:23:53,338 --> 00:23:55,228 it'd be nice to have a sidewalk and a curb. 434 00:23:55,318 --> 00:23:56,608 It may be a fence, right? 435 00:23:56,608 --> 00:23:59,268 So it's all those things that are gonna help me determine when someone 436 00:23:59,268 --> 00:24:00,678 comes off the street towards my house. 437 00:24:01,878 --> 00:24:07,798 So it can detect things like the, the, it can detect just weird stuff 438 00:24:07,798 --> 00:24:11,398 like you talked about a mass upload tra, a mass upload of traffic. 439 00:24:11,398 --> 00:24:15,668 It could also obviously detect, a lot of encryption going on. 440 00:24:16,128 --> 00:24:16,788 what other 441 00:24:16,858 --> 00:24:17,538 But it could, it could, 442 00:24:17,568 --> 00:24:18,468 might it notice? 443 00:24:19,143 --> 00:24:22,863 it could also be, over the last six months, Curtis 444 00:24:23,013 --> 00:24:25,083 does not work after 6:00 PM. 445 00:24:25,848 --> 00:24:28,938 He does not log in, or if he does, he, this is what he does. 446 00:24:29,018 --> 00:24:30,518 he has this behavior during this period of 447 00:24:30,518 --> 00:24:32,618 time and this behavior during another period of time. 448 00:24:32,828 --> 00:24:35,078 And that could be during the day, it could be the weekends. 449 00:24:35,478 --> 00:24:39,138 you open Microsoft Word, you open the internet. 450 00:24:39,418 --> 00:24:46,558 but today you opened Excel and Notepad and you went to 50 websites, and those 451 00:24:46,558 --> 00:24:46,658 could 452 00:24:46,978 --> 00:24:47,638 Notepad. 453 00:24:48,823 --> 00:24:51,703 Those could all be harmless activities, but they'll be flagged 454 00:24:51,703 --> 00:24:53,413 as a deviation from normal behavior, 455 00:24:56,023 --> 00:24:56,353 and that's 456 00:24:56,353 --> 00:24:58,163 how you get ahead malware, not because 457 00:24:58,163 --> 00:25:00,153 it's identified as truly suspect. 458 00:25:00,213 --> 00:25:01,538 It's identified as a deviation. 459 00:25:02,328 --> 00:25:04,608 I don't work after four, by the way, just for the record, 460 00:25:04,728 --> 00:25:04,938 but. 461 00:25:06,688 --> 00:25:07,508 That's five o'clock. 462 00:25:07,568 --> 00:25:10,988 I know in one of the previous points you discussed sort of these 463 00:25:10,988 --> 00:25:15,218 tools, Curtis, I think at some point we're gonna have a podcast episode, 464 00:25:15,218 --> 00:25:17,703 maybe talking about some of these 465 00:25:17,763 --> 00:25:19,503 yeah, Of the various tools. 466 00:25:19,503 --> 00:25:19,773 Yeah. 467 00:25:20,073 --> 00:25:20,403 Yeah. 468 00:25:21,183 --> 00:25:24,393 Can't cover everything in one episode or even 10 episodes. 469 00:25:24,513 --> 00:25:25,023 It's a lot. 470 00:25:25,023 --> 00:25:26,133 It's a lot to cover. 471 00:25:26,403 --> 00:25:31,723 so in this topic of polymorphic ransomware and also metamorphic ransomware, can 472 00:25:31,723 --> 00:25:35,078 you think of anything that we haven't covered that you think is important? 473 00:25:37,483 --> 00:25:38,323 So one of the things that. 474 00:25:41,023 --> 00:25:43,818 It is important to security cybersecurity specifically. 475 00:25:43,848 --> 00:25:46,308 'cause cybersecurity impacts everything. 476 00:25:46,308 --> 00:25:50,898 if it turns on and has value it, cybersecurity has a, there's a risk to it. 477 00:25:51,288 --> 00:25:53,958 So we're also limited. 478 00:25:55,258 --> 00:25:58,188 from a defense perspective, by our resources. 479 00:25:58,188 --> 00:26:00,558 So that's time, money, tech people, 480 00:26:00,978 --> 00:26:01,368 right? 481 00:26:01,668 --> 00:26:05,088 And so one of the things that's very important to an organization or even 482 00:26:05,088 --> 00:26:11,138 individuals is identify those things that are really valuable, where they are, and 483 00:26:11,468 --> 00:26:15,458 invest more in protecting that thing. 484 00:26:15,788 --> 00:26:20,728 and then start to, pull away from that to add layers as resources become available. 485 00:26:21,163 --> 00:26:25,813 But if you don't, if you don't identify or you don't know where the important things 486 00:26:25,813 --> 00:26:30,473 are and you just decide to blanket, cover everything, if you had a hundred computers 487 00:26:30,473 --> 00:26:35,143 and your budget's, a thousand dollars and that's $10 a computer, nine out of 488 00:26:35,143 --> 00:26:40,613 10 of those aren't as important and you could have invested more, in capabilities 489 00:26:40,653 --> 00:26:43,653 and recoverability in that one computer. 490 00:26:44,178 --> 00:26:47,338 Uh, and, do the kind of, the bare minimum good hygiene on the others. 491 00:26:47,698 --> 00:26:53,008 But then, segmentation, hardening, good policy, good monitoring, good response. 492 00:26:53,008 --> 00:26:56,278 Have a response plan, uh, good backups. 493 00:26:57,338 --> 00:27:01,478 what I'm hearing though is just like in, in backup and recovery, 494 00:27:01,898 --> 00:27:05,088 we talk about not everything is the same from a recovery perspective. 495 00:27:05,088 --> 00:27:06,783 there are applications that have a much. 496 00:27:07,638 --> 00:27:11,448 A higher business value and much higher business criticality. 497 00:27:11,448 --> 00:27:15,228 And so you're not gonna back up Joe's laptop the same way you buy, you 498 00:27:15,228 --> 00:27:17,138 back up the primary database server. 499 00:27:17,138 --> 00:27:20,368 And it sounds like the same is true of, cybersecurity. 500 00:27:20,418 --> 00:27:20,898 It is. 501 00:27:20,898 --> 00:27:25,038 And so yeah, your retention, classification, or even identification, 502 00:27:25,468 --> 00:27:29,908 that's all risk-based, value-based approach to applying resources to protect 503 00:27:30,118 --> 00:27:31,858 what you think is the most valuable. 504 00:27:31,978 --> 00:27:34,938 What's gonna keep your organization running, and how fast can we 505 00:27:34,938 --> 00:27:36,468 recover if something bad happens? 506 00:27:37,013 --> 00:27:37,583 All right. 507 00:27:37,583 --> 00:27:41,393 Mike, thank you for continuing to contribute to my cyber depression. 508 00:27:42,393 --> 00:27:43,058 Hey, don't pull your hair 509 00:27:43,188 --> 00:27:43,758 Yeah. 510 00:27:43,978 --> 00:27:44,488 too late. 511 00:27:44,698 --> 00:27:44,908 Too 512 00:27:44,908 --> 00:27:45,298 late. 513 00:27:45,298 --> 00:27:45,658 Yeah. 514 00:27:45,918 --> 00:27:46,518 Prasanna. 515 00:27:46,688 --> 00:27:49,103 Oh, too, that was hurtful right there at the end. 516 00:27:49,163 --> 00:27:51,343 Anyway, thanks Prasanna. 517 00:27:53,603 --> 00:27:54,108 You're welcome. 518 00:27:55,343 --> 00:27:56,963 And thank you to the listeners. 519 00:27:57,113 --> 00:27:58,373 That is a wrap.