dr kenneth geers the role of malware in chief research ... · comodo malware detections. sentosa...

46
The Role of Malware in Intelligence Operations VB 2018 / Montreal Dr Kenneth Geers Chief Research Scientist Comodo Cybersecurity

Upload: others

Post on 02-Jun-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

The Role of Malware in Intelligence Operations

VB 2018 / Montreal

Dr Kenneth Geers

Chief Research Scientist

Comodo Cybersecurity

Page 2: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Dr. Kenneth Geers PhD, CISSP

Atlantic Council Senior Fellow

NATO Cyber Centre Ambassador

Professor: Ukraine

20 yrs USG: US Army, NSA, NCIS, NATO

Publications

• Understanding Cyber Conflict

• Cyber War in Perspective

• Tallinn Manual

• Strategic Cyber Security

• The Virtual Battlefield

[email protected]

@KennethGeers

Page 3: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Applications

Trojans

Worms

Viruses

Backdoors

Page 4: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Malware Timeline

Russia

USA

Poland

Page 5: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Switzerland

United States

Russia

South Africa

Malware Ratio Analysis

Page 6: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Brazil

Cape VerdeMay 14-15

UkraineJuly 29

USAAug 18-21

EgyptAug 2

Trojan Detections by Country

IndonesiaChina

BangladeshAug 13-14

BrazilAug 9-10

IraqJuly 1-2

India

Page 7: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Worm Detections by Country

TurkeyApr 19-25

IndiaMay 27-28

RussiaApr 16-23 Indonesia

BrazilJul 2-6

Canada

Page 8: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

UkraineApr 19

UkraineMay 24

MalaysiaAug 23Ukraine

Aug 5

UkraineJun 24

Virus Detections by Country

Page 9: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Backdoor Detections by Country

United Kingdom

Russia

Italy

Page 10: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

March 13

Tro

jan

sV

iru

ses

Wo

rms

Foreign Intelligence

Page 11: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Malware type:trojans

Mar 29 – Apr 1

Page 12: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

U.S. InaugurationJan 20, 2017

USA / Russia / China

Comodo Malware Detections

Page 13: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections
Page 14: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Sentosa Island

Page 15: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

June 20-21

VirusDetections

Page 16: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Oct 2

Kh

ash

ogg

i dis

app

ears

Oct 18

ExploitDetections

BackdoorDetections

VirusDetections

Oct 18

Oct 18

Oct 2

Kh

ash

ogg

i dis

app

ears

Oct 14

Oct 19

Oct 14

App / Trojan / WormDetections

TrojanDetections

WormDetections

Turkey Saudi Arabia

Page 17: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

June 14-15

Virus

Trojan

Law Enforcement / Counterintelligence

Page 18: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

April 25-27

Page 19: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

June 4

Page 20: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 24

Trojan downloader

Page 21: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 28Business

Page 22: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

March 12-13

Saint Kitts and NevisDetections

Page 23: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 24

“Cyber War”

Page 24: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

March 28

Page 25: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Syria

Jun 12

Jun 19Apr 9-12

May 24 – Jun 3

Aug 9-16 Sep 8-9May 3

UN seeks inquiry into “Russian” Idlib airstrikes

Possible US, Israeli military action in Syria

Int’l tension over CW War mostly over;

World turns attention to Idlib

Int’l concern over Idlib, chemicalweapons

OPCWinspectors in Syria

Chemicalweapons attack;US airstrikes

Page 26: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 31

May 9Jul 6

Aug 2

Mar 17

Battle for Yemeni port

Saudi bombing;Peace talks;US visit to SA

Yemeni missile hits Saudi industrial target;Yemeni drone hits Saudi HQ in Yemen Saudis escalate

Yemen port siege

Missiles fired at Riyadh from Yemen;Saudi airstrikes vs. Yemeni Presidential palace

Yemen

Page 27: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Apr 10Apr 23

May 21-23

Jul 16Aug 8

Mar 17-18

Sep 2

Palestine appeal vs. Israel at UN

Anger at video of Palestinian shot by Israeli sniper

2 Israel soldiers killed;Army raids West Bank

Palestine submits ICC referral for “Israel crimes”

Israeli airstrikes in Gaza

Israeli airstrikes in Gaza

US defunds UNRWA

Palestine

Page 28: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 20

Apr 9

Apr 28

Jun 16Jul 24

Aug 23

Israel/Iran tension;Currency crisis

Pompeo in Saudi Arabia, calls for new Iran sanctions

Pompeo threatens to “crush” Iran

Political protests in Iran

US-Iran tension

Iran

Page 29: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Democracy

Page 30: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

VirginiaNov 2017Gubernatorial Election

Page 31: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

July 1-4

April 18

Page 32: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

May 18-25

Page 33: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

USA: trojan detectionscolored by state

OhioJul 22-Aug 4

Page 34: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

E = Election / R = Referendum / S = Snap election call / V = Vote recount

EE E R R S E R R E E V E E

Comodo Malware Detections

Page 35: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections
Page 36: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections
Page 37: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Arizona

SuspiciousApplications

Page 38: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Florida

SuspiciousApplications

Page 39: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Minnesota

Oct 8-12

Adware

Adware /TrojanAdware /

Trojan

Page 40: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Missouri

Oct 13

Adware /Trojan

Page 41: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

New Jersey

Adware /Trojan /

Ransomware

Page 42: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Nevada

SuspiciousApplications

Page 43: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Tennessee

SuspiciousApplications

Page 44: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Wisconsin

SuspiciousApplications

Page 45: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections

Trojans

Worms

Backdoors

Viruses

Page 46: Dr Kenneth Geers The Role of Malware in Chief Research ... · Comodo Malware Detections. Sentosa Island. June 20-21 Virus Detections. Oct 2 s Oct 18 Exploit Detections Backdoor Detections