Let's Play Hide and Seek In the Cloud - The APT Malware Favored in Cloud Services

Presented at TROOPERS16 (2016), March 16, 2016, 5:30 p.m. (Unknown duration)

Defending against Advanced Persistence Threat (APT) attacks has become a blooming topic in recent years. Organizations, enterprises, and specially governments have all been designated targets of APT attacks. Since APT attacks are well crafted with advanced tactics, potential targets of APT attacks should understand how to detect, prevent, and respond to these cyber attacks. A newfangled trend that has been affecting people's lives is the cloud service technology. Almost everybody enjoys the cost efficient and convenient features of cloud services. Yes, almost everybody, including actors. Hackers love cloud services just as much as you do, and probably even more so. When sophisticated hackers recognize the benefits of cloud services on their attack infrastructure, a second front is opened. In this talk, I will present APT malware which leverage several cloud services (including numerous blog services provided by multiple platforms, and cloud storage services such as Dropbox, Google Drive, Cloudme etc) as their attack infrastructure. I will introduce our analysis of malware and explain how actors perform their attacks through the cloud. Additionally, I will explain the advantages malware brings with cloud services and how to respond to these threats. Furthermore, I will also uncover potential targets of these trojans, which might be a bigger concern to the audience.


Presenters:

  • Ashley Shen
    Chi-en Shen (Ashley) is senior cyber threat analyst at Team T5 Inc.. Her major areas of research include malicious document, malware analysis and Advance Persistence Threat (APT). She is in charge of campaign tracking in the team and has been tracking several cyber espionage groups for years. During her MSc, she design and implement a flexible framework for malicious open XML document detection against APT attacks. Ashley is also a core member and speaker of HITCON GIRLS, the first security community for women in Taiwan.

Links:

Similar Presentations: