https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Hackers

Malicious Hackers Exploiting MSPs, DHS Warns

  • Written by Allison Francis
  • December 27, 2018
Cybercriminals are targeting MSPs as a way to get inside their customers’ networks.

Back in October, the U.S. Department of Homeland Security (DHS) issued a warning aimed at managed services providers (MSPs), managed security service providers (MSSPs) and cloud services providers (CSPs) that cyber gangsters are exploiting them to hack into their customers’ networks. And that they are doing so undetected.

The alert, called the Advanced Persistent Threat Activity Exploiting Managed Service Providers, cautions all providers, and highlights the exact nature of the attacks.

So what exactly is happening?

Clever and cunning as ever, malicious hackers are aiming at the “weak links” – i.e. MSSPs, MSP and CSPs – to get to their customers. DHS’ National Cybersecurity and Communications Integration Center (NCCIC) has been tracking this for more than two years, focusing on bad actors who are using advanced persistent threat (APT) tools designed specifically to break into the networks of both MSPs and CSPs and thereby the infrastructure of their customers.

The worst part about this is that the threat actors are exploiting the trusted relationship between provider and customer. They know that providers share sensitive information back and forth with their clients, and they are using these opportunities to slip into the customer’s network unnoticed.

“Threat actors appear to be leveraging stolen administrative credentials (local and domain) and certificates, along with placing sophisticated malware implants on critical systems,” stated the NCCIC in the alert. “Depending on the defensive mitigations in place, the threat actor could possibly gain full access to networks and data in a way that appears legitimate to existing monitoring tools.”

Victims of these attacks have been identified in the areas of IT (service providers included), energy, health  care, communications and critical manufacturing. The DHS is strongly advising service providers to lock down their systems and data and develop a “defense-in-depth strategy” to protect their assets and prevent against further risk and attacks.

In addition, included in the report is a set of best practices for MSPs for this specific scenario.

“[The] alert from the Department of Homeland Security confirms that small businesses, and their managed service providers, are the new attack vector for cybercriminals, and the risks are severe,” says Brian Downey, senior director of product management at Continuum. “The report, which analyzed a phishing attack on MSPs, has three key details that service providers should be aware of:

  • The attack capitalized on stolen credentials, making multi-factor authentication critical to securing end-clients.
  • Signature-based malware detection is not enough to protect against the initial infection.
  • Once the attackers were inside the service provider, they used common admin tools to move laterally to end-customer networks. This highlights the ineffectiveness of Remote Desktop Protocol (RDP) and heightens the need for more tightly-controlled remote management tools.”

Downey goes on to say that the report reinforces the need for advanced endpoint protection on all systems, isolating any unprotected systems into a separate network.

“MSPs should also ensure that they are leveraging DNS protection as a secondary line of defense, that they are using more secure tools than RDP, and that all remote access requires multifactor authentication,” urges Downey.

Tim Brown, VP of security of SolarWinds MSP, says that the ongoing advanced-persistence-threat (APT) actor activity attempting to infiltrate global MSP networks is a healthy, strong reminder that MSPs need to be vigilant about cyberhygiene.

“Bad guys will look for the easiest way in, so be sure to take care of the basics,” says Brown. “Don’t forget multifactor authentication; turn on AV; patch; monitor logs and look for suspicious activity. The U.S. Cert office lays out a number of these best practices, all of which we consistently cite and agree with.”

Obviously this is a developing story, but it’s a good kick in the pants in terms of buckling down on basic “cyberhygiene,” as Tim Brown calls it. Don’t be the “weak link” cybercriminals are looking to target.

Find the Department of Homeland Security warning to MSPs and CSPs here, with more in-depth info specifically for MSPs here.

Tags: MSPs Endpoint MSSP Insider Network Security MSPs

Most Recent


  • Black Hat expo hall 2022
    The Gately Report: Black Hat USA Edition with Cisco, IBM, CISA, More
    Black Hat USA has come roaring back since the COVID-19 pandemic.
  • Making Waves
    7 Channel People Making Waves This Week at Microsoft, Rackspace, RingCentral, Avaya
    Hackers targeted one UCaaS firm by impersonating the company's IT department.
  • Welcome Mat
    Okta Names Splunk Vet New Global Channel Chief
    Okta's global channel chief left the company in June.
  • Mergers acquisitions m&a goldfish crackers
    Latest M&A: IBM, Vonage, Nokia, GoTo, Nitel, Ensono, Huntress, More
    One cybersecurity company's $22 million July acquisition was its largest to date.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here
  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

The Gately Report: Black Hat USA Edition with Cisco, IBM, CISA, More

August 12, 2022

7 Channel People Making Waves This Week at Microsoft, Rackspace, RingCentral, Avaya

August 12, 2022

Oracle Cloud & AT&T, AWS Lead Cloud News Roundup

August 12, 2022

Industry Perspectives

View all

How to Take Shared Responsibility for Securing Cloud

August 11, 2022

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

ThreatLocker Preaches Zero Trust, Addresses Industry Competition

ScienceLogic Debuts New Partner Portal

August 9, 2022

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

June 27, 2022

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Twitter

ChannelFutures

.@splunk vet Bill Hustad named @Okta's new #channelchief. dlvr.it/SWXmws https://t.co/ILQesul0Cz

August 12, 2022
ChannelFutures

The Gately Report: #BHUSA edition with @Hacker0x01, @Cisco, @SaltSecurity, @CISAgov, @ExtraHop, @IBMSecurity, more.… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Channel People Making Waves Include: @kencarnesi, @szebenisz, @vasujakkal, @brettsmith52, @DaveMichels… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Nancy Henriquez, VP of Sales & Marketing at MSP 501 award-winning @synetek, touches on the importance of gathering… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

.@Equinix's new hire is a familiar face in the telco channel. dlvr.it/SWXV6v https://t.co/jIg0LrZ4DO

August 12, 2022
ChannelFutures

Missed the news this week from @OracleCloud and @ATTBusiness? We've got it here. Plus, news from @AWSCloud and… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Huge channel-impacting acquisitions in the past month. We've got details on @IBM, @nokia, @GoTo, @EnsonoIT,… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Boost privacy by design with #shiftleft mindset and add #security to cloud deployments from start, says… twitter.com/i/web/status/1…

August 12, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X