18
1 MCAFEE CONFIDENTIAL McAfee Confidential The League of Nations

The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

1MCAFEE CONFIDENTIAL

McAfee Confidential

The League of Nations

Page 2: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

2MCAFEE CONFIDENTIAL

Page 3: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

3MCAFEE CONFIDENTIAL

Innovation

The malicious document launches a PowerShell script.

Script downloads and reads an image file from a remote location

The attackers used the open-source tool Invoke-PSImage, released December 20, to embed the PowerShell script into the image file.

Page 4: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

4MCAFEE CONFIDENTIAL

Hidden in Plain Sight

Page 5: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

5MCAFEE CONFIDENTIAL

A small history lesson

Page 6: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

6MCAFEE CONFIDENTIAL

2013: Re-org

Unit 91

Espionage & Destruction

Unit 110

Tools development and Recon

Unit 128

HUMINT

Unit 180

Financial targeted Operations

Unit 413

Tech. Recon & Social Eng.

Page 7: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

7MCAFEE CONFIDENTIAL

Page 8: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

8MCAFEE CONFIDENTIAL

Page 9: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

9MCAFEE CONFIDENTIAL

Innovation unchained

Capitalizing the NYC Terror attack. Documents sent to military related

personnel

Once opened the document contacts control server to drop first stage of

malware

The document uses the DDE technique to invoke Powershell to download

Seduploader

Page 10: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

10MCAFEE CONFIDENTIAL

A global industry

Page 11: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

11MCAFEE CONFIDENTIAL

Outsourcing Operations

We've seen an increase in nation-states contracting private companies to accomplish hacking

operations and intelligence gathering. These groups operate with incredible sophistication, while

enjoying a cloak of semi-protected "status" for their malicious activities.

Source: Cybereason

Page 12: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

12MCAFEE CONFIDENTIAL

Our work has just got harder

Page 13: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

13MCAFEE CONFIDENTIAL

Page 14: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

14MCAFEE CONFIDENTIAL

Fightback – still continues…..

10/4/2017

Page 15: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

15MCAFEE CONFIDENTIAL

Page 16: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

16MCAFEE CONFIDENTIAL

Crime Pays?

10/4/2017

Page 17: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

17MCAFEE CONFIDENTIAL

Stay in touch

@Raj_Samani

Page 18: The League of Nations - FIRST...The League of Nations MCAFEE CONFIDENTIAL 2 MCAFEE CONFIDENTIAL 3 Innovation The malicious document launches a PowerShell script. Script downloads and

18MCAFEE CONFIDENTIAL

McAfee, the McAfee logo and [insert <other relevant McAfee Names>] are trademarks or registered trademarks of McAfee LLC or its subsidiaries in the U.S. and/or other countries.

Other names and brands may be claimed as the property of others.

Copyright © 2017 McAfee LLC.