1
1

00:00:00,240  -->  00:00:01,073
<v ->Another part</v>
2

2

00:00:01,073  -->  00:00:03,660
of threat classification is to describe the different types
3

3

00:00:03,660  -->  00:00:07,440
of adversary tools collectively described as malware.
4

4

00:00:07,440  -->  00:00:10,560
Now, we're not going to cover the basic malware like viruses
5

5

00:00:10,560  -->  00:00:13,830
and worms and Trojans and root kits and ransomware
6

6

00:00:13,830  -->  00:00:15,590
because you should already be familiar with all
7

7

00:00:15,590  -->  00:00:18,780
of those from your a plus and your security plus studies
8

8

00:00:18,780  -->  00:00:21,870
and we are way beyond that inside this course.
9

9

00:00:21,870  -->  00:00:23,220
Instead, we're going to focus
10

10

00:00:23,220  -->  00:00:26,700
on three types, commodity, malware, zero day malware
11

11

00:00:26,700  -->  00:00:28,260
and command and control.
12

12

00:00:28,260  -->  00:00:30,570
When I talk about commodity malware, we're talking
13

13

00:00:30,570  -->  00:00:32,610
about malicious software applications that are
14

14

00:00:32,610  -->  00:00:36,660
widely available for sale and are easily obtained and used.
15

15

00:00:36,660  -->  00:00:38,160
Now, you can usually find these
16

16

00:00:38,160  -->  00:00:40,590
on the dark web or the dark net, and there are
17

17

00:00:40,590  -->  00:00:43,890
online marketplaces where you can buy remote access Trojans
18

18

00:00:43,890  -->  00:00:47,280
things like Poison ivy, dark Comet, and Extreme Rat
19

19

00:00:47,280  -->  00:00:49,680
and many other types of malware out there.
20

20

00:00:49,680  -->  00:00:51,570
These things are all available online
21

21

00:00:51,570  -->  00:00:53,850
for a fee where you can download them
22

22

00:00:53,850  -->  00:00:55,440
and then start using them as part
23

23

00:00:55,440  -->  00:00:57,870
of your attacks if you're a bad guy.
24

24

00:00:57,870  -->  00:01:00,930
Now, these are commodity malware because they are generic
25

25

00:01:00,930  -->  00:01:04,470
off the shelf pieces of malware, but there are also targeted
26

26

00:01:04,470  -->  00:01:06,390
or custom malware that can be developed
27

27

00:01:06,390  -->  00:01:08,460
and deployed with a target in mind.
28

28

00:01:08,460  -->  00:01:10,980
When you're dealing with commodity malware, it's generic
29

29

00:01:10,980  -->  00:01:12,510
it's going against everybody
30

30

00:01:12,510  -->  00:01:14,640
but when you're dealing with targeted or custom malware
31

31

00:01:14,640  -->  00:01:16,770
there is a specific target in mind
32

32

00:01:16,770  -->  00:01:19,726
and so knowing this can help you identify that malware
33

33

00:01:19,726  -->  00:01:22,800
and if you determine it's commodity or targeted
34

34

00:01:22,800  -->  00:01:24,510
this can help you determine the severity
35

35

00:01:24,510  -->  00:01:27,720
of an incident because if somebody is using targeted malware
36

36

00:01:27,720  -->  00:01:30,390
against your organization, there is a higher severity
37

37

00:01:30,390  -->  00:01:33,090
to that incident for you because you are being targeted.
38

38

00:01:33,090  -->  00:01:34,710
You're not just randomly hit
39

39

00:01:34,710  -->  00:01:36,660
by some drive-by piece of malware,
40

40

00:01:36,660  -->  00:01:37,560
and so this is something that's
41

41

00:01:37,560  -->  00:01:39,390
important for you to consider.
42

42

00:01:39,390  -->  00:01:40,680
Now, the next thing we have to think
43

43

00:01:40,680  -->  00:01:43,590
about here is a zero day vulnerability and a zero
44

44

00:01:43,590  -->  00:01:46,620
day vulnerability is any vulnerability that is discovered
45

45

00:01:46,620  -->  00:01:50,100
or exploited before the vendor can issue a patch for it.
46

46

00:01:50,100  -->  00:01:52,620
Now, this is where we get our zero day malware
47

47

00:01:52,620  -->  00:01:54,270
from is malware that attacks.
48

48

00:01:54,270  -->  00:01:56,250
This is zero day vulnerability.
49

49

00:01:56,250  -->  00:01:58,800
When we talk about zero day, this is usually applied
50

50

00:01:58,800  -->  00:02:01,500
to the vulnerability itself, but in recent years
51

51

00:02:01,500  -->  00:02:04,230
people talk about zero day malware as well
52

52

00:02:04,230  -->  00:02:05,790
as they start referring to the attack
53

53

00:02:05,790  -->  00:02:08,610
or the malware that is exploiting that zero day.
54

54

00:02:08,610  -->  00:02:10,470
You may see either term being used
55

55

00:02:10,470  -->  00:02:13,020
on the exam when they talk about zero day
56

56

00:02:13,020  -->  00:02:15,930
they may be talking about the vulnerability or the malware
57

57

00:02:15,930  -->  00:02:19,080
so read the question to understand the context.
58

58

00:02:19,080  -->  00:02:20,820
Now, the next thing we have to think about when we talk
59

59

00:02:20,820  -->  00:02:23,640
about this zero day malware is how serious is it?
60

60

00:02:23,640  -->  00:02:27,060
Well, zero day exploits are big business.
61

61

00:02:27,060  -->  00:02:28,454
These things cost a lot
62

62

00:02:28,454  -->  00:02:30,870
of money and a lot of time to develop.
63

63

00:02:30,870  -->  00:02:33,300
For example, if you're a bug bounty person
64

64

00:02:33,300  -->  00:02:35,970
and you start finding zero day vulnerabilities
65

65

00:02:35,970  -->  00:02:37,890
you can actually get lots of money
66

66

00:02:37,890  -->  00:02:39,720
for turning those over to the company
67

67

00:02:39,720  -->  00:02:42,180
because they don't want those out on the open market.
68

68

00:02:42,180  -->  00:02:45,180
But you can also sell those to different governments
69

69

00:02:45,180  -->  00:02:48,570
and law enforcement agencies, and even on the dark web
70

70

00:02:48,570  -->  00:02:50,760
and some of these zero day exploits have gone
71

71

00:02:50,760  -->  00:02:52,860
for millions of dollars.
72

72

00:02:52,860  -->  00:02:53,760
There is one that sold
73

73

00:02:53,760  -->  00:02:57,030
for over $1 million that targeted Apple iPhones.
74

74

00:02:57,030  -->  00:02:59,580
These things are big business now
75

75

00:02:59,580  -->  00:03:01,320
because they cost so much money
76

76

00:03:01,320  -->  00:03:04,350
most adversaries will only use a zero day vulnerability
77

77

00:03:04,350  -->  00:03:06,510
for a very high value attack.
78

78

00:03:06,510  -->  00:03:07,770
They're not going to waste these
79

79

00:03:07,770  -->  00:03:09,900
and so generally what you're going to see is
80

80

00:03:09,900  -->  00:03:12,630
that people tend to try to attack something
81

81

00:03:12,630  -->  00:03:14,850
with a generic or off the shelf piece
82

82

00:03:14,850  -->  00:03:17,400
of malware first and get into the network.
83

83

00:03:17,400  -->  00:03:19,050
And if that target is valuable enough
84

84

00:03:19,050  -->  00:03:20,880
and they can't get in through other means
85

85

00:03:20,880  -->  00:03:23,430
then they would go and use their zero day.
86

86

00:03:23,430  -->  00:03:24,900
Often countries
87

87

00:03:24,900  -->  00:03:27,960
and nation states are stockpiling these zero days
88

88

00:03:27,960  -->  00:03:29,160
so that they can use them
89

89

00:03:29,160  -->  00:03:31,680
as they're doing their spying and their espionage
90

90

00:03:31,680  -->  00:03:35,070
and other things that are a very high value for them.
91

91

00:03:35,070  -->  00:03:36,450
Now, the third thing we want to talk
92

92

00:03:36,450  -->  00:03:38,820
about is command and control, but before we do that
93

93

00:03:38,820  -->  00:03:41,538
we need to talk once more about APTs.
94

94

00:03:41,538  -->  00:03:43,750
APTs originally referred to the person
95

95

00:03:43,750  -->  00:03:47,070
but now it refers more to the ability.
96

96

00:03:47,070  -->  00:03:50,081
An APT is an attacker's ability to obtain, maintain
97

97

00:03:50,081  -->  00:03:51,840
and diversify access
98

98

00:03:51,840  -->  00:03:55,410
to network systems using different exploits and malware.
99

99

00:03:55,410  -->  00:03:57,390
This can be done through commodity malware
100

100

00:03:57,390  -->  00:04:00,030
or through targeted or custom malware.
101

101

00:04:00,030  -->  00:04:03,270
Either way, when that attacker gets into your system
102

102

00:04:03,270  -->  00:04:04,650
they don't want to get out
103

103

00:04:04,650  -->  00:04:07,020
and generally you're going to find nation states
104

104

00:04:07,020  -->  00:04:10,710
and organized crime actors have this APT capability.
105

105

00:04:10,710  -->  00:04:12,200
Now, in terms of classification
106

106

00:04:12,200  -->  00:04:14,790
we talked about our knowns and our unknowns.
107

107

00:04:14,790  -->  00:04:17,790
When we talk about APTs, these are considered unknown.
108

108

00:04:17,790  -->  00:04:20,370
Unknown meaning we know that they're out there
109

109

00:04:20,370  -->  00:04:21,960
we know they're trying to attack us
110

110

00:04:21,960  -->  00:04:23,880
but we don't know exactly how they're going to do it
111

111

00:04:23,880  -->  00:04:26,220
because they're always modifying their techniques
112

112

00:04:26,220  -->  00:04:28,080
and they're always getting better all the time.
113

113

00:04:28,080  -->  00:04:31,110
And so this makes them a known unknown threat.
114

114

00:04:31,110  -->  00:04:33,210
Now, when we deal with APTs, a lot
115

115

00:04:33,210  -->  00:04:36,210
of times they will go out and use commodity malware
116

116

00:04:36,210  -->  00:04:38,909
or other off-the-shelf technologies to try to infect
117

117

00:04:38,909  -->  00:04:41,460
as many machines as possible.
118

118

00:04:41,460  -->  00:04:42,960
Then they'll have those report back
119

119

00:04:42,960  -->  00:04:46,410
to what's called a C2 node or a command and control node.
120

120

00:04:46,410  -->  00:04:48,600
Now, a C2 node is any infrastructure
121

121

00:04:48,600  -->  00:04:51,639
of hosts and services with which attackers direct distribute
122

122

00:04:51,639  -->  00:04:54,450
or control malware over botnets.
123

123

00:04:54,450  -->  00:04:57,150
And so often they will build up these large botnets
124

124

00:04:57,150  -->  00:05:00,090
especially if you're dealing with a crime organization.
125

125

00:05:00,090  -->  00:05:01,500
Now, as they do this
126

126

00:05:01,500  -->  00:05:03,660
you're going to have all these different machines all
127

127

00:05:03,660  -->  00:05:05,160
around the world that connect back
128

128

00:05:05,160  -->  00:05:08,970
to the bot master who is in charge of the C2 network
129

129

00:05:08,970  -->  00:05:11,262
and they can then issue a command to use those machines
130

130

00:05:11,262  -->  00:05:13,440
in any way they see fit.
131

131

00:05:13,440  -->  00:05:15,630
They may use them as a pivot point into somebody
132

132

00:05:15,630  -->  00:05:18,300
else's network to attack the network from there.
133

133

00:05:18,300  -->  00:05:20,400
So as law enforcement tries to track it back
134

134

00:05:20,400  -->  00:05:24,720
they find this innocent bot as opposed to the bot master.
135

135

00:05:24,720  -->  00:05:26,880
Also, we can take all these machines
136

136

00:05:26,880  -->  00:05:29,160
and then use them to attack a single target
137

137

00:05:29,160  -->  00:05:30,630
if we're doing a distributed denial
138

138

00:05:30,630  -->  00:05:32,310
of service attack, for instance
139

139

00:05:32,310  -->  00:05:34,590
and this is the whole idea of using a C2 node.
140

140

00:05:34,590  -->  00:05:35,580
It's this single point
141

141

00:05:35,580  -->  00:05:39,030
of contact that we can then use to talk to everybody else
142

142

00:05:39,030  -->  00:05:42,090
across our networks to do the bidding that we want to do
143

143

00:05:42,090  -->  00:05:44,220
and APTs use this a lot.
144

144

00:05:44,220  -->  00:05:46,920
Now, what is usually the target of an APT?
145

145

00:05:46,920  -->  00:05:50,100
Well, generally they're going to target financial institutions
146

146

00:05:50,100  -->  00:05:52,290
healthcare companies, and even governments
147

147

00:05:52,290  -->  00:05:55,080
because they all have large PII data sets
148

148

00:05:55,080  -->  00:05:56,880
and that can be turned into money.
149

149

00:05:56,880  -->  00:05:57,960
Additionally, they may go
150

150

00:05:57,960  -->  00:06:00,390
after governments to carry out political objectives
151

151

00:06:00,390  -->  00:06:02,400
like interfering in elections or spying
152

152

00:06:02,400  -->  00:06:04,650
in another country to figure out what they're going to do
153

153

00:06:04,650  -->  00:06:06,900
in the larger geopolitical spectrum.
154

154

00:06:06,900  -->  00:06:08,160
Now, one other key thing
155

155

00:06:08,160  -->  00:06:12,210
about an APT is generally an APT is not a single person
156

156

00:06:12,210  -->  00:06:14,100
but it is a group of people.
157

157

00:06:14,100  -->  00:06:15,960
Generally, you're going to have a staff that has
158

158

00:06:15,960  -->  00:06:17,760
different realms of expertise.
159

159

00:06:17,760  -->  00:06:20,680
For instance, I may have one person whose job it is to break
160

160

00:06:20,680  -->  00:06:23,040
down the front door and get into the system.
161

161

00:06:23,040  -->  00:06:25,860
I may have another person whose job it is to make sure
162

162

00:06:25,860  -->  00:06:28,140
that when they're in that system they have persistence
163

163

00:06:28,140  -->  00:06:29,520
and they don't get kicked out.
164

164

00:06:29,520  -->  00:06:31,530
I may have another person who's a linguist who
165

165

00:06:31,530  -->  00:06:33,750
can help me translate the information I'm getting.
166

166

00:06:33,750  -->  00:06:35,850
For instance, we talked earlier about the fact
167

167

00:06:35,850  -->  00:06:38,901
that Russia and China and North Korea all have teams
168

168

00:06:38,901  -->  00:06:41,729
of APTs that go out and attack other companies
169

169

00:06:41,729  -->  00:06:43,950
and countries and things like that.
170

170

00:06:43,950  -->  00:06:47,100
Well, if I'm in China and I break into an American company
171

171

00:06:47,100  -->  00:06:49,200
their information is probably written in English
172

172

00:06:49,200  -->  00:06:52,170
and if my hacker only speaks Chinese or Mandarin
173

173

00:06:52,170  -->  00:06:53,220
that would be an issue.
174

174

00:06:53,220  -->  00:06:54,420
So we may have a linguist there to
175

175

00:06:54,420  -->  00:06:56,700
help translate that information for them.
176

176

00:06:56,700  -->  00:06:58,050
This is all the type of thing we have to think
177

177

00:06:58,050  -->  00:07:00,570
about when we think about APTs because they are well funded.
178

178

00:07:00,570  -->  00:07:01,770
They have a team of people
179

179

00:07:01,770  -->  00:07:04,530
and they are all working together against you.
180

180

00:07:04,530  -->  00:07:06,540
Now, I had just mentioned the idea of persistence.
181

181

00:07:06,540  -->  00:07:08,280
What is persistence?
182

182

00:07:08,280  -->  00:07:10,470
Persistence is the ability of a threat actor to
183

183

00:07:10,470  -->  00:07:13,800
maintain covert access to a target host or network.
184

184

00:07:13,800  -->  00:07:15,630
This means that once I break in
185

185

00:07:15,630  -->  00:07:18,540
I can stay in your network for long periods of time.
186

186

00:07:18,540  -->  00:07:21,960
Studies have shown that the average APT is on your network
187

187

00:07:21,960  -->  00:07:24,990
for six to seven months before they are detected.
188

188

00:07:24,990  -->  00:07:27,780
That is a long time, and they can do a lot of stuff
189

189

00:07:27,780  -->  00:07:30,027
on that network without you ever knowing they're there.
190

190

00:07:30,027  -->  00:07:31,110
And so that is going to be one
191

191

00:07:31,110  -->  00:07:32,190
of the things we have to start figuring
192

192

00:07:32,190  -->  00:07:34,950
out is how do we detect these APTs?
193

193

00:07:34,950  -->  00:07:36,870
How can we find if they're in our network?
194

194

00:07:36,870  -->  00:07:38,160
And as we go through this course
195

195

00:07:38,160  -->  00:07:40,140
we'll talk more about indicators of compromise
196

196

00:07:40,140  -->  00:07:41,820
and how we can start detecting them earlier
197

197

00:07:41,820  -->  00:07:44,513
in the cycle so we can get them out of our network quicker.
