Malware attacks using machine identities doubled in 2019

Venafi claims machine identity capabilities have been commoditized and added to off-the-shelf malware

Commodity malware campaigns using machine identities are increasing at a rapid pace, according to a Venafi report, which reveals that this type of attack doubled between 2018 and 2019.

According to the Venafi threat intelligence team, malware attacks using machine identities, including high-profile campaigns like TrickBot, Skidmap, Kerberods and CryptoSink, grew eightfold over the last 10 years. In the second half of the last decade, these attacks increased even quicker.

Venafi threat intelligence researcher Yana Blachma states that while machine identity capabilities were once used primarily by high-profile threat actors and nation-state actors, they have since been commoditized and added to off-the-shelf malware.

As a result, Blachman says, these campaigns have become more sophisticated and harder to detect.

“For example, massive botnet campaigns abuse machine identities to get an initial foothold into a network and then move laterally to infect further targets," Blachman explained.

"In many recorded cases, bots download crypto-mining malware that hijacks a target’s resources and shuts down services. When successful, these seemingly simple and nonadvanced attacks can inflict serious damage on an organization and its reputation". 

An uptick in microservices, DevOps projects, cloud workloads and IoT devices on enterprise networks also complicates the misuse of machine identities. Though there are more than 31 billion IoT devices worldwide, the number of connected mobile devices will reach 12.3 billion by 2022. Venafi predicts 500 million new logical apps will be created between 2018 and 2023 too.

To communicate with one another securely, each application and device must have a machine identity to authenticate itself. Machines don’t rely on usernames or passwords to establish trust, privacy or security. Instead, cryptographic keys and digital certificates serve as machine identities. Unfortunately, organizations without such measures in place are already experiencing malware attacks designed to exploit machine identities.

According to Kevin Bocek, vice president of security strategy and threat intelligence at Venafi, human-centric security models are no longer effective in protecting against these threats.

“To protect our global economy, we need to provide machine identity management at machine speed and cloud scale. Every organization needs to ensure they have full visibility and comprehensive intelligence over every authorized machine they are using in order to defend themselves against the rising tide of attacks,” says Bocek.

Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Recommended

Biden looks to shore up the electrical grid’s cyber security
Security

Biden looks to shore up the electrical grid’s cyber security

15 Apr 2021
PowerShell threats increased over 200% last year
cyber security

PowerShell threats increased over 200% last year

14 Apr 2021
New DNS vulnerabilities put millions of IoT devices at risk
Internet of Things (IoT)

New DNS vulnerabilities put millions of IoT devices at risk

13 Apr 2021
Hackers leak data from dark web marketplace
cyber security

Hackers leak data from dark web marketplace

9 Apr 2021

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget
Mobile Phones

Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget

13 Apr 2021