Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Highly Evasive and Adaptive Threats (HEAT) Will Dominate Modern Attack Techniques in 2024
By Poornima DeBolle, co-founder and chief product officer, Menlo Security
Cybercriminal playbooks are constantly changing, oftentimes faster than IT and security teams can keep up. After years of technological innovation, we are still coming face to face with threats that sneak past our most comprehensive security platforms. Today’s threat actors are becoming more creative, familiarizing themselves with the modern security tool stack and launching attacks that evade security controls. Throughout my career, and specifically in this past year, I have seen these Highly Evasive Threats target web browsers, using a variety of evasive techniques to get around detection-based security tools. In 2024, Highly Evasive and Adaptive Threats will continue to take center stage and dominate the attack landscape, requiring a shift in the way we protect against these threats.
Types of Highly Evasive and Adaptive Threats
Recently, we have seen several breaches in headlines that fall into the category of highly evasive threats. Legacy URL Reputation Evasion (LURE), wherein attackers evade URL filtering defenses that categorize domains based on trust by using newly created websites and categorizing them or infiltrating trusted websites with malware. A recent example of this type of attack was a credential phishing campaign that leveraged malicious Google ads to place fraudulent Amazon Web Services (AWS) websites in Google search results. At one point, the fake website even ranked second under the actual AWS website, showcasing how cybercriminals were able to add a redirection step to evade detection by Google’s ad fraud detection systems.
SEO poisoning is a type of cyberattack that attempts to exploit SEO algorithms for malicious purposes. It involves the manipulation of website content and code in order to raise its ranking on search engine results pages (SERPs). For example, Menlo Security researchers have noticed that the top result for a Honda manual leads to a Russian cybercriminal site, highlighting that the scale of SEO poisoning is at a level we haven’t seen in previous years. Through a combination of technical and social engineering tactics, they can make malicious sites appear more legitimate and desirable than they are. Another example earlier in 2023 was when cybercriminals distributed fake installers by using poisoned Google Ads to drop a Python-based malware that steals information.
In the recent Ducktail malware campaign that also evaded existing security tooling, threat actors sent out malware camouflaged as a PDF file hidden among images of authentic products from well-known companies. In this case, cybercriminals strategically evaded detection tools by infiltrating trusted images and links.
Responding to These Threats
These Highly Evasive Adaptive Threat campaigns are well-crafted, thought out, and have very high success rates. Given the success rates and the fact that cybercriminals don’t like to reinvent the wheel/techniques if they don’t have to, these attack methods will be used and reused in more campaigns going forward. Organizations must consider advanced browser security solutions that can thwart these evasive attacks.
The significance of and reliance upon the web browser among today’s workforce – whether with in-office or remote workers – is not going to slow down. Rather than an increase in volume and frequency of attacks, we are witnessing an increase in the effectiveness of the attacks, despite the continued investment in security infrastructure. According to Gartner, worldwide end-user spending on IT security is projected to total $215 billion in 2024, an increase of 14.3% from 2023. Organizations are spending billions of dollars on security products, yet security attacks continue to make headlines daily. CISOs recognize the danger of highly evasive threats that are targeting the browser and are adding browser security to their strategic plans for 2024 and beyond. However, there are multiple routes to consider.
Enterprise Browsers, a new browser (in addition to Chrome, Edge, Firefox, and Safari) with security controls for the enterprise, are gaining in popularity. In a tight economy, Palo Alto Networks bought Talon for $625M and Island has raised $285M in venture funding. This market enthusiasm is a recognition of the importance of browser security. However, adding yet another browser that needs to be managed, patched against zero-day vulnerabilities compounds the problem of ever-expanding attack surface that CISOs are grappling with. Add that to how difficult it can be to ensure seamless integration between SaaS applications and the enterprise browser, and they are now faced with an additional complexity on the right architecture for browser security.
To secure the browser, CISOs will look to different offerings that go beyond installing a new enterprise browser. Google and Microsoft are already updating capabilities of their browsers to address the needs of the enterprise. Whether managing existing browsers like Chrome and Edge or using browser extensions for the last-mile security, browser security must remain a top priority when facing the onslaught of Highly Evasive Adaptive Threats in 2024.
##
ABOUT THE AUTHOR
Poornima co-founded Menlo Security, bringing years of product management experience to the table. Before Menlo, she was a product management executive at Juniper Networks, responsible for cloud security, security management, and security analytics. She joined Juniper via its acquisition of Altor Networks, where she was vice president of product management and business development. Prior to that, she was head of business development at Check Point in product management and engineering roles. Poornima holds an MSCS from Arizona State University.





