15.1.19

17e Symposium InterSystems Benelux, les 5 et 6 février 2016 ‘Fueling Changes Matters’



Cette année le 15e Symposium InterSystems Benelux sur le  thème ‘Fueling Changes Matters’, (Alimenter les changements, c’est important), aura lieu le mardi 5 et le mercredi 6 février, au Radisson Blu Astrid, Koningin Astridplein, 7B, à 2018 Anvers.


 
Le Symposium est l’occasion annuelle, pour près de 250 participants, de faire connaissance avec des pratiques et des cas innovants. Véritables succès technologiques du Benelux et d’ailleurs, ils sont présentés par leurs concepteurs ainsi que des spécialistes locaux et internationaux. Par ailleurs, c’est l’endroit idéal pour rencontrer experts et dirigeants d’InterSystems et échanger avec eux des expériences dans un environnement propice à la discussion.
 

Parmi les thèmes abordés lors du symposium 2019, on remarquera:

·         Laissez-vous inspirer par le célèbre gourou de la technologie en soins de santé, Don 
       Woodlock, Vice- Président plates-formes HealthShare InterSystems, 
       https://www.intersystems.com/pulse-blog/author/dwoodlock/ et ses présentations 
      ‘Empowering Healtcare’ (Renforcer les soins de santé) et AI and Machine Learning at
       Work’ (AI et apprentissage automatique)
 
·         Apprenez à exploiter toutes les données grâce à la présentation ‘The Magic of Digital 
       Innovation’ (La magie de l'innovation numérique) par Peter Hermans, Deloitte Belgium 
       https://www.linkedin.com/in/peter-hermans-ba0927/

·         A partir de cas réels, découvrez La Transformation Digitale dans les hôpitaux belges - 
      Un exemple concret en province de Hainaut, par Melchior Wathelet, CEO Xperthis 
      (NRB)

·         Comment retirer un maximum de bénéfices de la nouvelle plate-forme InterSystems Information Exchange et le portail patients par le Prof. Dr. Mark Van Houdenhoven, CEO Sint Maartenskliniek, Nijmegen https://www.medischcontact.nl/opinie/blogs-columns/bloggers-columnisten/bloggercolumnist/mark-van-houdenhoven-1.htm.

Le mardi 5 février sera consacré à la fois à l’approche stratégique et pratique de la transformation 
digitale : transformation digitale en hôpitaux et soins aux personnes âgées ; accroitre la valeur de 
l’entreprise grâce à l’IoT ; comment démarrer la transformation digitale afin d’atteindre l’excellence 
opérationnelle. La journée se terminera par un dîner et une soirée détente. 

Le mercredi 6 février sera l’occasion d’approfondir des sujets techniques au cours du Caché User Group Benelux, la communauté indépendante ouverte gratuitement à tous les utilisateurs des technologies Caché et InterSystems http://becpp.org/blog/.

La participation au Symposium est gratuite. L’enregistrement se fait sur le site https://bnl.intersystems.com/symposium-2019 où l’on trouve le programme complet des deux journées.


17e Symposium InterSystems Benelux, 5 en 6 februari 2019 ‘Fueling Changes Matters’






De 17e editie van het InterSystems Benelux Symposium, met als thema ‘Fueling Changes Matters’, zal op dinsdag 5 en woensdag 6 februari plaats hebben in hotel Radisson Blu Astrid, Koningin Astridplein, 7B, 2018 Antwerpen.

Traditiegetrouw is het Symposium voor zijn 250-tal deelnemers uit de drie Benelux-landen de unieke gelegenheid om kennis te maken met praktijk cases en innoverende en succesvolle toepassingen uit Benelux en andere regio’s, die door hun ontwerpers en lokale en internationale specialisten van InterSystems gepresenteerd worden. Het is bovendien de ideale bijeenkomst om zowel experten als het  management van het bedrijf te ontmoeten en ervaringen te bespreken.

Dit jaar komen onder andere volgende thema’s aan bod : Hoe de digitale transformatie implementeren? Wat betekent dit voor mijn IT systemen? Moet ik mijn bedrijfsmodel wijzigen? Wat zijn de volgende stappen als ik digitaal wil gaan?
 
·         Laat u inspireren door de bekende goeroe in healthcare technologie Don Woodlock, Vice President, HealthShare Platforms, InterSystems, https://www.intersystems.com/pulse-blog/author/dwoodlock/ met zijn presentaties ‘Empowering Healtcare’ enAI and Machine Learning at Work’
·         Verneem hoe gebruik te maken van alle data met de presentatie ‘The Magic of Digital Innovation’ door Peter Hermans, Deloitte Belgium https://www.linkedin.com/in/peter-hermans-ba0927/
·      Ontdek, via praktijkgevallen, de Digitale Transformatie in Hospitalen – Een concreet voorbeeld in Henegouwen, door Melchior Wathelet, CEO Xperthis
·       Hoe een maximum aan voordelen te halen uit de nieuwe Intersystems Information Exchange platform en het patiëntenportaal, door Prof. Dr. Mark Van Houdenhoven, CEO Sint Maartenskliniek, Nijmegen https://www.medischcontact.nl/opinie/blogs-columns/bloggers-columnisten/bloggercolumnist/mark-van-houdenhoven-1.htm
 
Op dinsdag 5 februari wordt de strategische en praktische benadering besproken van de digitale transformatie: digitale transformatie in hospitalen en ouderenzorg; bedrijfswaarde verhogen met IoT; hoe beginnen met de digitale transformatie om een operationele uitmuntendheid te bereiken. De dag wordt beëindigd met een diner en een ontspannings-avond.

Op woensdag 6 februari komen technische onderwerpen aan de beurt tijdens de Caché User Group Benelux, de onafhankelijke vereniging, gratis toegankelijk voor alle gebruikers van de InterSystems Caché technologie http://becpp.org/blog/

De deelname aan het Symposium is gratis. Inschrijven gebeurt op de site https://bnl.intersystems.com/symposium-2019  waar ook het volledige programma van de twee dagen te vinden is.

Over InterSystems
InterSystems is de drijvende kracht achter wat belangrijk is: de machine achter relevante applicaties in de medische sector, de financiële wereld, de overheid en bij andere organisaties waar de zorg voor menselijk leven en levensonderhoud een rol speelt. InterSystems is een leverancier van strategische technologie sedert 1978. Het bedrijf is in private handen. Het hoofdkantoor staat in Cambridge Massachusetts, terwijl er wereldwijd diverse bijkantoren zijn voor verkoop en technische ondersteuning. De softwareproducten worden dagelijks gebruikt door miljoenen mensen in meer dan 80 landen.

Meer informatie is te vinden op www.intersystemsbenelux.com 


9.1.19

New Year’s resolutions: Get your passwords shipshape




In case there are some blank entries in your laundry list of New Year’s resolutions, we have a few tips for a bit of cybersecurity ‘soul searching’. Here’s the first batch, looking at how you can fix your good ol’ passwords.
Many of us entered 2019 with a boatload of New Year’s resolutions. Doing more exercise, fixing unhealthy eating habits and saving more money are all highly respectable goals in their own right, but could it be that they don’t go far enough in an era with countless apps and sites that scream for letting them help you reach your personal goals, which apparently also implies – you guessed it – reach your New Year’s resolutions?
Now, you may want to add a few more weighty and yet fairly effortless habits on top of those well-worn choices. Here are a handful of tips for ‘exercises’ that will do good for your cyber-fitness.
I won’t pass up on stubborn passwords
Passwords have a bad rap, and deservedly so: they suffer from weaknesses, both in terms of security and convenience, that make them a less-than-ideal method of authentication. However, much of what the Internet offers is dependent on your signing up for this or that online service, and the available form of authentication almost universally happens to be the username/password combination.
As the keys that open online accounts (not to speak of many devices), passwords are often rightly thought of as the first – alas, often the only – line of defense that protects your virtual and real assets from intruders. However, passwords don’t offer much in the way of protection unless, in the first place, they’re strong and unique to each device and account.
But what constitutes a strong password? A passphrase! Done right, typical passphrases are generally both more secure and more user-friendly than typical passwords. The longer the passphrase and the more words it packs the better, with seven words providing for a solid start. With each extra character (not to mention words), the number of possible combinations rises exponentially, which makes simple brute-force password-cracking attacks far less likely to succeed, if not well-nigh impossible (assuming, of course, that the service in question does not impose limitations on password input length – something that is, sadly, still far too common).
I’ll have no sympathy for the passphrase-cracker
Another caveat is that it’s better to refrain from phrases that have made it into the everyday lexicon. Entire books, famous quotes, or lyrics – sing, ‘Pleased to meet you, hope you guess my name’ as a bit of an extreme example that is not to be taken literally – already tend to be part of the fodder of password-cracking tools. The individual words should be in random order and, ideally, sprinkled with special characters and character substitution, all the while retaining a hidden meaning and memorability to its creator. For practical guidance about creating your passphrases, you may want to refer to this short video tutorial or to this article.
Then, of course, there is the need for each passphrase to be distinct for each account, so that a leak of one of your passphrases doesn’t reverberate through your other and possibly more valuable accounts. Alas, the dangerous practice of password recycling is ubiquitous, and attackers can exploit it hands-down with an automated technique known as ‘credential stuffing’.
It’s quite likely that you use too many online accounts to remember a distinct passphrase for each of them. In which case, it’s worth considering a reputable password vault/manager that encrypts your password storage and takes away much of the pain that password management involves. Of course, such a tool can also generate randomized and complex passwords and passphrases for you.
While then you should need to remember only one master password that, ultimately, opens all your online accounts, the pressure will be on the sturdiness and uniqueness of this one key to your digital kingdom – so it’s back to the suggestions above.
I won’t skip the second step
Another trouble with passwords/passphrases may arise when they are not only the first, but actually the only line of defense for your account security. When that barrier crumbles – commonly through a phishing attack or by attackers somehow working out your login details – an extra authentication factor that does not rely on ‘something you know’ may very well foil your adversaries.
Two-factor authentication (2FA), or multi-factor authentication (MFA), is an excellent way of boosting the security of your accounts, especially when coupled with hardware keys or dedicated apps, and less so with SMS-borne 2FA.  Although many online services provide 2FA options, few require its use. However, the adoption of 2FA has been on the rise and it’s never been easier to jump on the practice. Regardless if its implementation, signing up for 2FA wherever you can is well worth the little extra effort, as it can help in various scenarios, including when you never fell prey to a cyberattack compromising any of your passwords.
In fact, it’s quite probable that some of your authentication details will be, or have already been, stolen and posted online or made available for sale on underground marketplaces. The source of these password leaks include the many security breaches that have blighted online services, retailers, hotel chains and the like. Additionally, the targeted entity may have protected the users’ passwords with weak hashing and salting functions, or even stored the passwords in plain text. Worse still, the service provider, let alone you, may not know until quite a while later that hackers pilfered the often poorly secured data, or purchased them on the dark web, so you had no shot at taking any ad-hoc defensive measures. Again, this is also where that extra authentication factor will usually thwart any account-takeover attempts.
In fact, go ahead and see for yourself on Have I Been Pwned? whether any of your online accounts may have been part of a known breach. Aside from the almost 5.7 billion compromised accounts that the site indexes, it also has a cache of more than half a billion publicly leaked or stolen passwords in clear text that have been revealed in past breaches, so you can check yours against the database, too.
I’ll use fewer passwords
Surely a mistake, right? Well, it may sound counterintuitive, but fixing your passwords may also imply needing fewer of them in the first place. More precisely, it means cutting ties with the services you no longer use, so that you needn’t ‘look after’ your accounts with them. We all have set up accounts that we no longer use. Indeed, we may have racked up quite a few of them over the years, including some we barely remember. However, the adage ‘the internet never forgets’ fits here too, and forgetting is something you shouldn’t do, either.
The trouble with unused accounts is that each of them – even if only a vestige of your much younger self – is a potential source of danger. The service may suffer a breach exposing your password or may be sold to new owners whose intentions might not exactly be honest. Or, if miscreants take over your account, they might be able to use it to break into one of your highly valued accounts, be it by gathering private information about you, or through your failing to use a unique password for each account. Or they can just as well use it to spew out spam.
But what doesn’t exist can’t be taken over, can it? Feel no remorse: just dispatch those accounts to a better place and never look back. There are even services that promise to scale back your online footprint in bulk; that is, without you having to recall or comb through and then manually shut down each inactive account. Using a service just to help kill online accounts may not be for everybody, however, as essentially you need to take the developers of such tools at their word.
While you’re cutting the clutter, consider severing ties also with third-party apps and services that are associated with your accounts on social and other major sites, especially the apps that you no longer use. These apps, too, can be misused as other entry points for illicit data collection or even worse. To pull the plug on their access to your account and data, navigate to the privacy and/or security settings of your online service(s) of choice; from there, it usually takes only a click or two.
Next up
Staying safe online isn’t going to become any easier this year, and we’ll be back in a few days with more tips for beefing up your personal security. Next time, we’ll focus mainly on a couple of easy ways to boost the security of your wireless network.



3.1.19

What is threat cumulativity and what does it mean for digital security?


A reflection on how acknowledging the cumulative nature of cyber-threats and understanding its implications can benefit our digital security
Threat cumulativity is a term I began to use in 2018 to refer to the tendency of new technologies to spawn new threats that add to old threats without displacing them. In this article I give some examples of what I mean by threat cumulativity, some thoughts on why I came up with this term, and suggestions as to how it might prove useful in getting to grips with digital security.
Yes, security is cumulative
A few years ago, someone asked me to give a talk on the top five or six things that I had learned since I started researching computer security back in the 1980s. The first thing that came to mind was this: security is cumulative. In other words: protecting information systems and the data they process requires anticipation of new threats while defending against old threats.
So I made a slide that said “security is cumulative” and I started to include it in my talks about what is now called cybersecurity or – my preferred term – digital security. Fortunately, my presentations had already evolved in a way that illustrated the cumulative nature of threats to information systems.
In recent years I’ve given numerous talks that stressed the need for businesses to grasp the true scale of the cybersecurity problem, specifically the way it has progressed from disgruntled teenagers in hoodies hunched over keyboards in dark basements to coordinated campaigns of villainy in cyberspace. One approach I use to make my point is showing screenshots of the markets that traffic in stolen data. I also diagram the structured activity behind the creation and execution of malware campaigns.
When I first took this approach I said things like: “Don’t think random teenagers in basements, think people who go to work every day to penetrate systems and steal data.” But then I realized that was a mistake. Why? Ethically-challenged young hackers in hoodies have not gone away. Some of the biggest names on the internet learned that in 2016 when the Mirai botnet went from attacking minecraft sites to taking down a major Domain Name System provider; the story of the perpetrators was covered in depth by Brian Krebs – himself a victim of Mirai and other teenage criminals.)
Clearly, there is a need to protect information systems from well-resourced cybercriminals exploiting the latest vulnerabilities, but at the same time it would be foolish to neglect the threat from random hacker wannabees who are short on clues about consequences. Likewise it would be irresponsible for an organization to neglect anti-ransomware measures just because of a rise in cryptomining (as reported last year under headlines like Why cryptomining is the new ransomware and Ransomware is so 2017).
What cumulativity means for security
Security professionals have been dealing with the practical implications of threat cumulativity for decades. Once upon a time, computer security meant protecting a computer, a room-sized machine that usually lived behind locked doors. Threats back then included power supply issues, fire, flooding and other natural disasters. The main human threats were data entry errors or malicious code created by people authorized to use the computer, in other words: insiders. As computers got smaller and more numerous, more people learned how to use and abuse them, and the range of threats expanded to include theft of the computer and its components (the theft of an IBM PC was my first professional encounter with computer crime, circa 1986). At the same time, earlier threats like earthquakes persisted (one of my publishers lost many PCs due to overheating when the San Francisco earthquake of 1989 rendered its offices inaccessible and knocked out the air conditioning.)
The use of removable media – such as floppy disks – increased the viability of new threats like computer viruses and data theft. When the networking of computers started to happen, old threats like insider abuse and data theft were given fresh opportunities, even on small Local Area Networks or LANs. When organizations started to connect multiple offices over Wide Area Networks (WANs) then data and system access was exposed on wires that the organization itself could not protect. And of course the coming of “The Internet” took that problem to a whole new level.
Of course, at each step of the way, security professionals have warned that deploying new technology that is not “secure by design” will only add new threats to the already considerable security burden. About the middle of 2018, I articulated this aspect of threat cumulativity as a Twitter thread. Sadly, it did not “go viral,” but it did help me clarify my thoughts, so I want to share it here:
1.       For several years I have been using the phrase “security is cumulative” when briefing organizations on information security strategy. Here is how this comes about.
2.       Each step in the evolution of technology has prompted warnings about criminal abuse and unforeseen negative consequences. Many warnings go unheeded until incidents of abuse and negative consequences occur;
3.       at which point the problems are debated and measures to address them are drafted. Many of those measures are then ignored and the problem is talked down in some circles. While some measures may be implemented, it’s too late or without enough resources to make a difference.
4.       The result is new threats, even as old threats persist. I propose we call this phenomenon the cumulativity of threats. Here is an example:
5.       People exploiting vulnerabilities in software are a threat to the security of your information, which is also threatened by people using phone calls to perpetrate support scams. In other words, threats permeate the technology stack, from the telephone to the latest software.
6.       Threat cumulativity has several important implications. Most obviously, you have to guard against old threats while thwarting new ones. But threat cumulativity also has serious implications for the future of technology.
7.       For example, I would argue that – unless we change the way we have been doing things – cumulativity will negatively impact the odds of humans achieving a net improvement in the quality of life from each new generation of technology.
Ever since I wrote that, I have seen a lot of confirmation that my observations are correct. Of course, there’s probably some confirmation bias at work, but consider a single 10-day chunk of information security news randomly sampled from 2018:
That’s five examples in 10 days, five headlines that reflect the reality that “security is cumulative”. While many information security professionals have, over the years, stressed the need to learn from history, I decided that this aspect of digital security – the need to defend against an accumulating list of threats – deserved a name, hence: threat cumulativity.
Helpful language?
I assume there will be some objections to the term “threat cumulativity”. Some will say “cumulativity is not a word” and “everybody knows this already.” To the first point, cumulativity is a word, as I will explain in a moment. As for “everybody knows this already” let me clarify: if you are a security expert, you probably do know that threats are cumulative. But a whole lot of people whose work impacts security have not yet internalized the implications of this phenomenon. I think that having a term to describe the phenomenon will help to spread awareness of its implications.
As for cumulativity, it is a term used in linguistic semantics to describe an expression (X) for which the following holds: “If X is true of both of a and b, then it is also true of the combination of a and b” (Wikipedia). A commonly cited example is the expression “water”. If you combine two things that are water, what you get is more water. That said, I freely admit to not being an expert in linguistic semantics (although I do have a degree in English). Nevertheless, I think that adapting cumulativity to the security lexicon is a valid use of the word, one that can help people understand – and defend against – the phenomenon it purports to describe.
Another possible objection to “threat cumulativity” is that a better term might be “risk cumulativity.” This is a non-trivial point and so I am going to address it in a separate article. That said, I think there are good strategic reasons for using “threat” here rather than “risk”. However, I’d also like to hear what you think. Is the idea of threat cumulativity helpful? Do you see examples of this?

1.1.19

2018: Research highlights from ESET’s leading lights


As the curtain has fallen on yet another eventful year in cybersecurity, let’s look back on some of the finest malware analysis by ESET researchers in 2018
If you never got the chance to read this year’s investigations by ESET researchers into some of the most dangerous hacker shenanigans in recent years, or if you just want to refresh your memory, now is the time. Let’s cut to the chase and recall just a handful of ESET’s delvings into the murky depths of 2018’s malware, including malicious code targeting Linux servers.
The evil twin
On one occasion, it wasn’t only fellow cybersecurity professionals who sat up and took notice, as ESET researchers uncovered a rootkit that goes to especially great lengths – and, indeed, depths – in order to open a backdoor to the targeted machine. While extremely rare, rootkits that burrow all the way into the computer’s Unified Extensible Firmware Interface (UEFI) aren’t entirely unheard of, and proof-of-concept samples thereof have been seen before. However, this was the first time that such a rootkit was detected in active use.
Unsurprisingly, LoJax – as we named the rootkit – is the work of an Advanced Persistent Threat (APT) group. In this case, our research uncovered solid evidence to tie the rootkit to a particularly nefarious hacking collective nicknamed Sednit (and also called APT28, Sofacy, Strontium, and Fancy Bear). This group has made a name for itself by possessing a diverse set of insidious tools that – as previously documented, on many occasions, by ESET researchers among others – it has deployed against a range of geopolitical targets.
To implant LoJax deep inside a system’s innards, Sednit has repurposed legitimate anti-theft software for laptops, which is known as LoJack (hence the rootkit’s name). LoJax co-opts the LoJack agent in order to maintain usermode persistence, after Sednit’s operators use legitimate utilities to overwrite parts of the victim machine’s SPI flash memory, where the LoJack UEFI module resides.
LoJax is both extremely difficult to detect – particularly for security software that doesn’t incorporate UEFI protection – and exceptionally persistent. Withstanding a reinstallation of the operating system and even a replacement of the hard drive is required by legitimate anti-theft software if it is to enable its owner to track down their lost or stolen computer. After all, a hard drive replacement or an operating system reinstallation could very well be the first thing a thief will do, and it is this ability to resist removal that LoJax co-opts from LoJack.
At any rate, there is a remedy when a system is compromised with LoJax. Its owner has essentially two ways to clean up: re-program the machine’s SPI flash memory or replace the motherboard outright. Neither option is simple, however, and both go far beyond the usual process of malware removal. This, again, helps illustrate just how intrusive, persistent and ultimately dangerous of a threat LoJax is.
Does LoJax portend an explosion in malware targeting computer firmware? Hardly, given that this is not your run-of-the-mill sort of malware. However, attackers do have the habit of borrowing from the devious playbooks of their predecessors, with LoJax aiding and abetting malware writers to expand the frontiers of computer intrusions. And this only highlights the importance of effective UEFI scanning and threat blocking.
Rumor has it … no longer
In another major discovery of 2018, ESET researchers unearthed enough evidence to assert that malware known as Industroyer, which caused the hour-long blackout in and around Ukraine’s capital, Kiev, in late 2016, was the work of the same threat actor that would unleash the NotPetya (DiskCoder.C) wiper disguised as ransomware six months later.
The culprit – a prolific APT collective called TeleBots – is descended from a group called BlackEnergy, whose eponymously named malware was responsible for another breakthrough incident: a power outage that affected a quarter of a million homes in Ukraine and lasted several hours in December 2015.
The above effectively ties three of the most impactful malware-induced incidents in memory to the same threat actors.
Speculation that TeleBots hatched Industroyer was rife after ESET researchers released their findings about this most powerful modern malware that targeted industrial control systems. Incriminating evidence was missing, however – until the same ESET researchers picked apart a piece of malware that they code-named Win32/Exaramel and that shared significant code similarities with the main Industroyer backdoor.
At its simplest, Win32/Exaramel is an upgrade of the backdoor that was at the heart of Industroyer. And although the attack deploying the improved version was prevented thanks to ESET’s timely alert to Ukraine’s authorities, “the discovery of Exaramel shows that the TeleBots group is still active in 2018”. That’s reason aplenty to worry as 2018 draws to a close.
More shades of malice
TeleBots isn‘t the only heir apparent to BlackEnergy, which seems to have gone dark after the December 2015 blackout. Another nefarious collective, called GreyEnergy, has been operating in parallel, and probably in close liaison, with TeleBots. That said, the turf and modus operandi of each of the two groups differ substantially.
As revealed by another landmark piece of ESET research – the first to shine a light on GreyEnergy globally – this hacking group doesn’t court attention for its malice. Instead, it engages in reconnaissance and espionage, ostensibly in order to prepare the ground for future attacks of its own making or to grease the wheels of operations to be run by other groups. All the while, GreyEnergy aims to lie low and vanish ‘into the fog’ once it has done its job.
GreyEnergy’s malware toolkit shares a number of similarities with that of its predecessor, although GreyEnergy was actually found to be an enhancement of BlackEnergy and “with an even greater focus on stealth”. At any rate, both groups share a keenly malicious interest in the energy sector and critical infrastructure in Ukraine and Poland.
Ties between GreyEnergy and TeleBots, for their part, are evidenced by the former’s use in December 2016 of a worm, called ‘Moonraker Petya’, that turned out to be a precursor to the NotPetya worm, unleashed by TeleBots six months later. At the risk of repeating ourselves: GreyEnergy is yet another extremely dangerous threat actor that is worth watching closely.
Turning tables
First off, bear with us while we recall a few quick facts from history prior to 2018. More than five years ago, ESET researchers analyzed and helped disrupt Operation Windigo, a malicious campaign that created a botnet comprising tens of thousands of Linux-powered servers. Windigo stood out for many things, but let’s settle for just two of them:
First, at its heart was a highly advanced backdoor and credential-stealer called Linux/Ebury that abused a widely used suite of remote connectivity tools known as OpenSSH. Second, before installing itself, Linux/Ebury would check if other OpenSSH backdoors were present on the system.
Lo oking at the code allowed ESET researchers to discover other in-the-wild SSH backdoors, some previously unknown to the AV community. Fast forward to 2018 and ESET unveils new research that describes this effort, offering unique insights into the state of affairs in Linux server-side malware.
Having tracked down in-the-wild backdoors in OpenSSH servers, the researchers have documented no fewer than 21 malware families, including 12 that had not been ‘on file’ before. They include both simple (off-the-shelf) and advanced (bespoke) malware, variously operated by crimeware and APT groups.
Eighteen out of the 21 strains are fitted with credential-stealing features, while 17 contain a backdoor mode. The associated white paper provides a comprehensive view of the malware strains and their inner workings, representing a significant contribution to the body of research into Linux-specific malware.
All told, this research effort is also a reminder that, while Linux may, for whatever reasons, be hit with less malware than Windows, the security of Linux-based systems, including internet-facing servers, may not be as bulletproof as some may (want to) believe.
Conclusion
To be sure, the research sketched out above draws on only a sample of the deliberate and purposeful methods used by some of the world’s most resourceful cybercriminals. And yet, that sample is more than enough to illustrate the magnitude of the threat represented by miscreants as the curtain is set to open on 2019.
More findings from the ESET research community are available in a dedicated section on our website.