Living Off The Land
Cybercriminals are “living off the land” with techniques that use legitimate software and functions in a system to perform malicious actions on that system. Based on third-quarter events, Trellix has identified a trend in tools used by adversaries who are attempting to remain undetected. While state-sponsored threat groups and larger criminal threat groups have resources to develop tools in house, many turn to binaries and administratively installed software that may already be present on a target system to carry out distinct phases of an attack.
Adversaries may gather information on technologies used from job postings, customer testimonials advertised by vendors, or from an inside accomplice.
Tags: