1
00:00:00,090 --> 00:00:01,169
In this lesson, we're going to look at

2
00:00:01,169 --> 00:00:03,666
some of the indications of malware attacks.

3
00:00:03,666 --> 00:00:05,774
Now, your understanding of the various indicators

4
00:00:05,774 --> 00:00:07,812
of malware attacks is going to be essential

5
00:00:07,812 --> 00:00:08,992
as you progress in your career

6
00:00:08,992 --> 00:00:10,688
as a cybersecurity professional.

7
00:00:10,688 --> 00:00:13,307
By recognizing the signs of a malware attack early on,

8
00:00:13,307 --> 00:00:14,756
you can better mitigate the damage

9
00:00:14,756 --> 00:00:16,749
that these attacks may cause to your systems.

10
00:00:16,749 --> 00:00:18,645
Now, there are nine common indicators

11
00:00:18,645 --> 00:00:20,596
of malware attacks that you should be aware of,

12
00:00:20,596 --> 00:00:22,346
including account lockouts,

13
00:00:22,346 --> 00:00:24,765
concurrent session utilization, blocked content,

14
00:00:24,765 --> 00:00:27,248
impossible travel, resource consumption,

15
00:00:27,248 --> 00:00:30,183
resource inaccessibility, out-of-cycle logging,

16
00:00:30,183 --> 00:00:33,481
missing logs, and published or documented attacks.

17
00:00:33,481 --> 00:00:34,602
Let's take a quick look at each

18
00:00:34,602 --> 00:00:36,537
of these different types of indications.

19
00:00:36,537 --> 00:00:38,148
First, we have account lockouts.

20
00:00:38,148 --> 00:00:40,710
Now, malware, especially those designed

21
00:00:40,710 --> 00:00:42,493
for credential theft or brute force attacks,

22
00:00:42,493 --> 00:00:44,649
will trigger multiple failed login attempts

23
00:00:44,649 --> 00:00:47,163
that could result in a user's account being locked out.

24
00:00:47,163 --> 00:00:49,532
These lockouts aren't merely an inconvenience though,

25
00:00:49,532 --> 00:00:51,491
they're a bright red flag that somebody

26
00:00:51,491 --> 00:00:53,245
is trying to break into your network.

27
00:00:53,245 --> 00:00:54,767
If you suddenly see a lot of your users

28
00:00:54,767 --> 00:00:56,179
cannot access their accounts anymore

29
00:00:56,179 --> 00:00:58,085
despite not entering an incorrect password,

30
00:00:58,085 --> 00:01:00,487
or if there's an unusual surge in locked accounts

31
00:01:00,487 --> 00:01:01,721
across your enterprise network,

32
00:01:01,721 --> 00:01:02,951
this could be a good indication

33
00:01:02,951 --> 00:01:05,495
of a malware attack that's underway.

34
00:01:05,495 --> 00:01:08,027
Second, we have concurrent session utilization.

35
00:01:08,027 --> 00:01:10,013
Now, our users should typically only have

36
00:01:10,013 --> 00:01:13,694
one active session at any given time inside of our network.

37
00:01:13,694 --> 00:01:15,477
If you notice that a single user account

38
00:01:15,477 --> 00:01:17,778
has multiple simultaneous or concurrent sessions open,

39
00:01:17,778 --> 00:01:20,502
especially from various geographic locations,

40
00:01:20,502 --> 00:01:23,314
this should really be a cause for concern and suspicion.

41
00:01:23,314 --> 00:01:24,796
Seeing concurrent session utilization

42
00:01:24,796 --> 00:01:27,184
may be a good indication that some kind of malware

43
00:01:27,184 --> 00:01:28,748
has hijacked the user's account

44
00:01:28,748 --> 00:01:31,774
is now using it for their own malicious activities.

45
00:01:31,774 --> 00:01:34,398
Third, we have blocked content.

46
00:01:34,398 --> 00:01:36,235
Modern cybersecurity tools are usually going to be equipped

47
00:01:36,235 --> 00:01:38,736
with the ability to block known malicious content

48
00:01:38,736 --> 00:01:41,760
such as certain types of files or links.

49
00:01:41,760 --> 00:01:42,593
If there's a sudden increase in

50
00:01:42,593 --> 00:01:43,696
the amount of blocked content alerts

51
00:01:43,696 --> 00:01:44,737
you're seeing from your security tools,

52
00:01:44,737 --> 00:01:47,482
this is a strong indication that a malware infection

53
00:01:47,482 --> 00:01:49,583
may have successfully penetrated your system.

54
00:01:49,583 --> 00:01:51,644
Fourth, we have impossible travel.

55
00:01:51,644 --> 00:01:54,017
Now, impossible travel refers to a scenario

56
00:01:54,017 --> 00:01:55,744
where a user's account is accessed from two

57
00:01:55,744 --> 00:01:57,736
or more geographically separated locations

58
00:01:57,736 --> 00:02:00,128
in an impossibly short period of time.

59
00:02:00,128 --> 00:02:02,160
For example, I just logged into my system

60
00:02:02,160 --> 00:02:04,446
from Orlando, Florida about 10 minutes ago.

61
00:02:04,446 --> 00:02:06,312
Now, if you see right now, that I'm trying

62
00:02:06,312 --> 00:02:07,819
to log in from New York City,

63
00:02:07,819 --> 00:02:10,179
this would be considered impossible travel

64
00:02:10,179 --> 00:02:11,498
because it takes more than 10 minutes

65
00:02:11,498 --> 00:02:12,781
to fly from Orlando to New York.

66
00:02:12,781 --> 00:02:14,472
It takes about three hours.

67
00:02:14,472 --> 00:02:16,753
Usually, if we see impossible travel,

68
00:02:16,753 --> 00:02:18,490
this is an indication that a user's account

69
00:02:18,490 --> 00:02:20,078
has been compromised, and it's often due

70
00:02:20,078 --> 00:02:21,734
to some kind of malicious activity,

71
00:02:21,734 --> 00:02:24,032
or as an aftermath of a successful malware attack

72
00:02:24,032 --> 00:02:26,211
that was able to harvest your user's credentials

73
00:02:26,211 --> 00:02:28,519
like their username and password.

74
00:02:28,519 --> 00:02:30,695
Fifth, we have resource consumption.

75
00:02:30,695 --> 00:02:33,065
Now, many forms of malware, especially Cryptominers,

76
00:02:33,065 --> 00:02:35,737
botnets, and worms, can consume a significant amount

77
00:02:35,737 --> 00:02:38,723
of system resources once you've been infected by them.

78
00:02:38,723 --> 00:02:41,661
If you're observing any unusual spikes in CPU, memory,

79
00:02:41,661 --> 00:02:43,830
or network bandwidth utilization

80
00:02:43,830 --> 00:02:45,442
that can't be linked back to a legitimate task,

81
00:02:45,442 --> 00:02:46,695
that could be an indication

82
00:02:46,695 --> 00:02:49,018
that you're the victim of a malware attack.

83
00:02:49,018 --> 00:02:51,728
High resource consumption can also lead to system slowdowns

84
00:02:51,728 --> 00:02:54,042
that make it very noticeable and impactful

85
00:02:54,042 --> 00:02:56,712
that you have a malware injection occurring.

86
00:02:56,712 --> 00:02:59,475
Sixth, we have resource inaccessibility.

87
00:02:59,475 --> 00:03:01,211
Now, ransomware is a form of malware

88
00:03:01,211 --> 00:03:02,490
that encrypts user files

89
00:03:02,490 --> 00:03:04,454
to make them inaccessible to the user.

90
00:03:04,454 --> 00:03:06,460
If you have a large number of files or critical systems

91
00:03:06,460 --> 00:03:08,273
that are suddenly inaccessible to you,

92
00:03:08,273 --> 00:03:10,462
Or if users receive messages demanding payment

93
00:03:10,462 --> 00:03:12,848
to decrypt their data, this is a pretty clear sign

94
00:03:12,848 --> 00:03:15,678
of a ransomware based malware attack.

95
00:03:15,678 --> 00:03:17,985
Seventh, we have out-of-cycle logging.

96
00:03:17,985 --> 00:03:19,641
Now, logs are crucial for understanding

97
00:03:19,641 --> 00:03:21,743
our systems and their various activities.

98
00:03:21,743 --> 00:03:22,778
If you're noticing that your logs

99
00:03:22,778 --> 00:03:24,533
are being generated at odd hours,

100
00:03:24,533 --> 00:03:25,937
or during times when no legitimate activities

101
00:03:25,937 --> 00:03:27,197
should have been taking place,

102
00:03:27,197 --> 00:03:28,444
such as in the middle of the night

103
00:03:28,444 --> 00:03:29,796
when no employees are actively working,

104
00:03:29,796 --> 00:03:31,202
this could be an indication

105
00:03:31,202 --> 00:03:33,222
that you're the victim of a malware attack.

106
00:03:33,222 --> 00:03:35,385
This kind of out-of-cycle logging could reveal

107
00:03:35,385 --> 00:03:37,743
that unauthorized data transfers or system modifications

108
00:03:37,743 --> 00:03:39,492
are being conducted by an attacker.

109
00:03:39,492 --> 00:03:41,412
So it's important to review your logs regularly

110
00:03:41,412 --> 00:03:43,784
to detect these types of infections.

111
00:03:43,784 --> 00:03:45,491
Eighth, we have missing logs.

112
00:03:45,491 --> 00:03:47,927
Now, missing logs can be a very alarming sign for us

113
00:03:47,927 --> 00:03:49,737
as cybersecurity professionals.

114
00:03:49,737 --> 00:03:51,802
Often, we're going to see that a threat actor

115
00:03:51,802 --> 00:03:53,760
or attacker will delete your system logs

116
00:03:53,760 --> 00:03:55,527
in order to hide their own tracks

117
00:03:55,527 --> 00:03:57,490
after successfully breaching your system.

118
00:03:57,490 --> 00:03:59,282
So, if you're conducting a log review

119
00:03:59,282 --> 00:04:00,746
as a cybersecurity analyst, and you see

120
00:04:00,746 --> 00:04:02,480
there's a large gap in your logs,

121
00:04:02,480 --> 00:04:04,563
or if the logs have been cleared out completely

122
00:04:04,563 --> 00:04:05,882
without any authorized reason,

123
00:04:05,882 --> 00:04:07,579
this could be a good indication

124
00:04:07,579 --> 00:04:09,425
that you are the victim of some kind of

125
00:04:09,425 --> 00:04:11,507
malicious activity or malware attack.

126
00:04:11,507 --> 00:04:14,151
And this means somebody is trying to cover their tracks.

127
00:04:14,151 --> 00:04:17,416
Ninth and finally, we have published and documented attacks.

128
00:04:17,416 --> 00:04:18,714
Now, this one is pretty obvious,

129
00:04:18,714 --> 00:04:21,428
but if a cybersecurity researcher or reporter

130
00:04:21,428 --> 00:04:22,755
publishes a report that shows that

131
00:04:22,755 --> 00:04:24,736
your organization's network has been infected

132
00:04:24,736 --> 00:04:27,309
as part of a botnet or other malware based attack,

133
00:04:27,309 --> 00:04:29,704
this will serve as your notice that you've been attacked.

134
00:04:29,704 --> 00:04:31,467
Now, hopefully your organization has

135
00:04:31,467 --> 00:04:33,057
well-trained cybersecurity professionals

136
00:04:33,057 --> 00:04:34,026
who will know that you've been

137
00:04:34,026 --> 00:04:35,910
the victim of a malware infection

138
00:04:35,910 --> 00:04:38,297
before you read about it on the cover of the New York Times.

139
00:04:38,297 --> 00:04:40,190
But if you don't, this is the final way

140
00:04:40,190 --> 00:04:41,709
that you will know that you are the victim

141
00:04:41,709 --> 00:04:43,772
of a malware attack because it's sitting there

142
00:04:43,772 --> 00:04:45,773
right on the front page of the newspaper.

143
00:04:45,773 --> 00:04:47,775
So remember, you must first recognize

144
00:04:47,775 --> 00:04:49,682
the indications of malware attacks

145
00:04:49,682 --> 00:04:51,801
if you have any hope of responding against them.

146
00:04:51,801 --> 00:04:53,725
While some indications are pretty overt

147
00:04:53,725 --> 00:04:56,388
and in your face like a ransom demand from ransomware,

148
00:04:56,388 --> 00:04:57,714
or an article being published

149
00:04:57,714 --> 00:04:59,030
on the front page of the New York Times,

150
00:04:59,030 --> 00:05:00,670
others can be much more subtle,

151
00:05:00,670 --> 00:05:02,721
and require a more in-depth and careful observation.

152
00:05:02,721 --> 00:05:04,500
Like unusual resource consumption

153
00:05:04,500 --> 00:05:06,480
or unexpected account lockouts.

154
00:05:06,480 --> 00:05:08,248
By regularly monitoring your system's health,

155
00:05:08,248 --> 00:05:09,964
user activities, and logs, you're going to be

156
00:05:09,964 --> 00:05:11,999
in a much stronger position to promptly detect

157
00:05:11,999 --> 00:05:13,712
and respond to any malware threats

158
00:05:13,712 --> 00:05:16,113
that may occur against your systems.

