Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

Cloud Threats Memo: Cloud Storage Services are Increasingly Exploited to Deliver Malware

Aug 02 2022

A new long-running phishing campaign, allegedly originating from Vietnam and active since 2018, is targeting professionals on LinkedIn with the final objective to compromise their corporate Facebook accounts.

The campaign, dubbed “Ducktail,” has exclusively financial motivations, aiming to not only steal business-specific details from the compromised corporate Facebook accounts (which, by the way, are exfiltrated via Telegram bots), but also to leverage the privileges to hijack the payments, replacing the financial details, or even to run their own Facebook Ad campaigns with money from the victimized firms. 

Unsurprisingly, this campaign exploits the cloud in multiple familiar ways throughout its attack chain. This is not only because a consumer cloud application, Facebook, is the final target, and another very popular application, LinkedIn, is used to identify the potential targets and establish the conversation, but also, most importantly, because three legitimate cloud services, Dropbox, iCloud, and MediaFire, are used to host the malware payload that the victims are convinced to download via social engineering once they are approached by the threat actors on LinkedIn.

The attackers exploit the digital trust on a professional network, LinkedIn, to lure the victims and use  three legitimate well-known and trusted cloud services to deliver the malicious payload. A consolidated modus operandi to simplify the attack model, given that cloud services provide simplified hosting, and a more evasive delivery mechanism that increase the chances of success (and Dropbox seems to be the preferred choice of the attackers lately).

How Netskope mitigates the risk of legitimate cloud services exploited for malicious purposes

Dropbox, iCloud, and MediaFire are among the thousands of cloud services for which the Netskope Next Gen SWG can provide granular access control through the Cloud XD engine recognizing dozens of activities such as “Login,” “Create,” “Download,” etc. In the case of Dropbox, it is also possible to distinguish corporate and personal instances enforcing different policies, for example preventing potentially dangerous activities (such as upload and download) from unmanaged cloud storage services or personal accounts, coaching the users to a safer, corporate-approved alternative.

And in case the cloud service is exploited to deliver malware, this risk can be mitigated thanks to Netskope Threat Protection, part of the NG-SWG, which provides an effective defense against modern evasive threats regardless of the nature of the traffic (web or cloud) with a layered approach that offers multiple engines, ranging from antivirus to cloud sandboxing, plus additional detectors based on machine learning to detect Office documents containing malicious macros and portable executables. If needed, the capabilities of the threat protection engine can be further enhanced, integrating external technologies (such as threat intelligence feeds or endpoint technologies), via Cloud Exchange.

Stay safe!

author image
Paolo Passeri
Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.