# Modern Bank Heist: from smash and grab to hostage situation as cyberthieves evolve
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-06-18
Category: BANKING
Category URL: https://financedigest.com/category/banking
Meta Title: Protecting the Financial Sector: Insights from Modern Bank
Meta Description: Discover the evolving tactics and sophisticated attacks targeting the financial sector, as revealed in VMware Carbon Black&#039;s Modern Bank Heist report. Stay
URL: https://financedigest.com/modern-bank-heist-from-smash-and-grab-to-hostage-situation-as-cyberthieves-evolvehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/untitled-design-88-e1595590250513-1736838894415-compressed.jpg)

_By **Tom Kellermann,** Head of Cybersecurity Strategy, VMware Carbon Black_

The financial sector is historically one of the most secure industries in the world. It needs to earn trust and convince customers that their hard-earned money is safe. Nevertheless, the fact that banks are guardians of the one thing [cyber criminals typically desire most (money) means security](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") teams are under relentless pressure.

Attackers are prepared to invest time, resources and collaborate to develop new and more effective ways to reach the [digital vault and make off with money](https://www.financedigest.com/digitisation-of-banking-the-impact-of-digital-money.html "Digitisation of Banking: the impact of digital money"). Our third Modern Bank Heist report collected the views of 25 security [leaders](https://www.financedigest.com/digital-trends-for-banking-leaders-looking-to-compete-in-2022.html "Digital trends for banking leaders looking to compete in 2022") and found that attackers are evolving and getting more sophisticated as they aim to secure long-term illicit access to banking systems. And they are capitalising on the disruption of COVID-19 to help. So, what can we learn from the [data revealed](https://www.financedigest.com/businesses-seek-better-access-to-data-to-support-environmental-objectives-bright-data-research-reveals.html "Businesses seek better access to data to support environmental objectives, Bright Data Research Reveals") in the report, and how can we combat the emerging threats?

**COVID** **-19** **surge hits financial sector**

[Among the CISOs we surveyed, 80% said they had experienced an increase in cyberattacks over the past twelve months](https://www.financedigest.com/sentiment-among-german-exporters-falls-for-third-month-in-a-row-ifo.html "Sentiment among German exporters falls for third month in a row -Ifo"), up 13% compared with a year ago. Some of this is attributable to the COVID-19 surge – separate VMware Carbon Black data showed there has been an increase in attacks on [finance sector](https://www.financedigest.com/how-embedded-insurance-can-drive-growth-and-value-for-the-insurance-and-finance-sectors.html "How Embedded Insurance Can Drive Growth and Value for the Insurance and Finance Sectors") targets of 238% from February to April 2020, and we saw ransomware attacks on the sector increase by a multiple of 9 during the same period. Closer [analysis shows that notable alerts observed in VMware Carbon Black data spiked in correlation with significant moments in the COVID-19](https://www.financedigest.com/thermasonic-ultrasound-gel-warmers-market-covid-19-analysis-major-factors-that-can-increase-worldwide-demand.html "Thermasonic Ultrasound Gel Warmers Market (Covid-19 Analysis) Major Factors That Can Increase Worldwide Demand") news cycle, indicating that attackers are capitalising on disruption to attack while the world looks the other way.

The majority (82%) of our CISOs noted an increase in attack sophistication over the [past year](https://www.financedigest.com/how-has-growth-of-marine-scrubber-systems-market-taken-off-over-the-past-few-years.html "How has Growth of Marine Scrubber Systems Market Taken Off Over the Past Few Years"), and the ways attacks are developing gives us a valuable insight into attacker behaviours that should inform our response. Overall, we’re seeing attackers moving past inelegant “smash and grab” tactics, and towards more of a “hostage situation” where their motivation is to gain and retain footholds in target networks for long term campaigns.

The Kryptik trojan and Emotet malware continue to feature among the top attack types experienced, our research has found, and these are often used in longer, complex campaigns aimed at leveraging native [operating systems](https://www.financedigest.com/robot-operating-system-market-is-witnessing-a-sustainable-growth-due-to-increase-in-demand-scrutinized-in-the-new-analysis.html "Robot Operating System Market is witnessing a Sustainable Growth Due to Increase in Demand Scrutinized in the New Analysis") tools to remain undetected or gain a base to island hop to a larger and more lucrative target. Another indication that attackers are operating for the long term is the fact that the most prevalent MITRE threat ID affecting the [finance sector](https://www.financedigest.com/time-to-act-as-cybercriminals-hot-on-the-heels-of-finance-sector.html "Time to act as cybercriminals hot on the heels of finance sector") over the past year is T1507 – Process Discovery (comprising 64% of attacks). This shows attackers are investing in increasing their knowledge of policies and procedures in financial [institutions](https://www.financedigest.com/top-5-security-technologies-that-every-finance-institution-workplace-should-consider.html "Top 5 Security Technologies That Every Finance Institution Workplace Should Consider"), the better to work out how to infiltrate them undetected. They are also ramping up their [awareness of incident response tactics and seeking blind spots](https://www.financedigest.com/being-aware-of-the-insurance-blind-spot-when-it-comes-to-driverless-cars.html "Being aware of the insurance blind spot when it comes to driverless cars") that they can exploit to remain invisible.

**Island Hopping** **experienced by** **one third**

33% of the CISOs surveyed reported experiencing island hopping, where [supply chains](https://www.financedigest.com/eliminating-payment-barriers-the-future-of-supply-chain-payments-is-digitization.html "Eliminating Payment Barriers: The Future of Supply Chain Payments is Digitization") and partners have been unwitting vectors for attacks. The most common type of attack is network-to-network, but one [fifth reported suffering watering hole type attacks](https://www.financedigest.com/prefabricated-homes-market-report-2021-by-global-key-players-types-applications-countries-market-size-forecast-to-2029.html "Prefabricated Homes Market Report 2021 By Global Key Players, Types, Applications, Countries, Market Size, Forecast To 2029"), where hackers target a website frequently visited by customers of the target and attempt to gain access credentials, or the site of the financial institution itself to launch malware into visitors’ browsers.

Island hopping-as-a-service is also on the rise. In 2019 our analysts uncovered a secondary component in a well-known cryptomining campaign that was designed to exfiltrate [system access information](https://www.financedigest.com/health-care-information-systems-market-growth-set-to-surge-significantly-during-2018-2026.html "Health Care Information Systems Market Growth Set to Surge Significantly during 2018 – 2026") that was destined for sale on the dark web. This is a significant change in behaviour that defenders need to keep on the radar as what looks like one [type of attack may be cover](https://www.financedigest.com/understanding-the-different-types-of-car-insurance-covers.html "Understanding The Different Types Of Car Insurance Covers") for another.

**“Virtual Invasions” on the rise**

Almost two thirds (64%) of those surveyed said that they had seen increased attempts at wire fraud transfer, up 17% compared with 2019. These attacks rely on attackers’ knowledge of business process gaps in the verification process, or on direct social engineering of customers or [customer service](https://www.financedigest.com/how-customer-services-has-changed-during-covid.html "How Customer Services Has Changed During Covid") representatives.

**Counter-incident response up as** [attackers evade detection](https://www.financedigest.com/how-to-detect-and-defend-from-seo-attacks-and-customer-complaints.html "How to Detect and Defend from SEO Attacks and Customer Complaints")

Almost a quarter (24%) of our [surveyed](https://www.financedigest.com/sentiment-in-uk-finance-falls-at-fastest-pace-since-2019-survey.html "Sentiment in UK finance falls at fastest pace since 2019, survey") CISOs had witnessed counter-incident response as attackers prioritise persistence and seek to retain their foothold in the financial institution’s network. This is something we expect to see escalate in the [coming year](https://www.financedigest.com/mena-infant-milk-formula-market-to-record-exponential-compound-annual-growth-rate-in-the-coming-years.html "Mena Infant Milk Formula Market to Record Exponential Compound Annual Growth Rate in the Coming Years"). Tactics such as log deletion, manipulation of time stamps and disabling of security controls will all feature as attackers cover their tracks. Related to this are destructive wiper attacks designed to “burn the evidence” of infiltration and prevent defenders conducting forensic [analysis to stop the same vectors being used in future](https://www.financedigest.com/renal-cyst-treatment-market-covid-19-industry-analysis-future-trends-opportunity-growth-regional-outlook-and-forecast-2028.html "Renal Cyst Treatment Market COVID-19 Industry Analysis, Future Trends, Opportunity Growth, Regional Outlook and Forecast 2028"). This has major implications for incident response: we need to get more clandestine.

VMware Carbon [Black Senior Threat Researcher](https://www.financedigest.com/senior-leaders-more-at-risk-of-burnout-than-ceos-according-to-new-research.html "Senior leaders more at risk of burnout than CEOs, according to new research") Greg Foss has five tips for incident response to avoid alerting adversaries:

1. **Stand up a secondary line of secure communications**

This is vital to discuss the ongoing incident. Assume all internal communications are compromised and visible to the adversary.

1. **Assume adversaries have multiple entry points**

Shutting off one entry point may not remove the attacker and may have the opposite effect by notifying the attacker you are aware of their presence.

1. **Watch and wait**

Don’t immediately start [blocking malware activity and access](https://www.financedigest.com/russia-blocks-facebook-accusing-it-of-restricting-access-to-russian-media.html "Russia blocks Facebook, accusing it of restricting access to Russian media"), or terminating the C2. You need to monitor [closely to assess](https://www.financedigest.com/home-care-chemicals-market-is-expected-to-expand-at-a-cagr-close-to-5-over-the-assessment-period-of-2021-and-2031.html "Home Care Chemicals Market is expected to expand at a CAGR close to 5% over the assessment period of 2021 and 2031") the scope of the intrusion to work out exactly what to do to fully remove the adversary.

1. **Deploy agents in monitor-only mode**

If you begin blocking or otherwise impending activities, they will realise and change tactics, [possibly leaving](https://www.financedigest.com/pope-francis-to-leave-hospital-as-soon-as-possible-says-vatican.html "Pope Francis to leave hospital as soon as possible, says Vatican") you in the dark.

1. **Deploy honey tokens or deception grids**

Particularly on attack paths that cannot be hardened.

The financial [sector](https://www.financedigest.com/the-technologies-set-to-boost-the-finance-sector-in-2022.html "The technologies set to boost the finance sector in 2022") is facing a threat that evolves as fast as it can adapt. [To combat the tactics adversaries are developing, we need](https://www.financedigest.com/scams-have-eroded-digital-trust-banks-need-to-do-more-to-combat-the-industrial-scale-of-scams-in-the-uk.html "Scams have eroded Digital Trust – Banks need to do more to combat the industrial scale of scams in the UK.") to understand more about their behaviour. That means that kneejerk shutting down of attacks [must be exchanged for a more clandestine and nuanced approach that allows us to learn](https://www.financedigest.com/lost-in-translation-why-banks-must-learn-the-language-of-their-customers.html "Lost in Translation: Why Banks Must Learn the Language of their Customers"), combined with our own collaborations across the cybersecurity and financial sector. The [digital vault is hostage](https://www.financedigest.com/how-bank-cisos-can-respond-to-a-digital-hostage-scenario.html "How Bank CISOs Can Respond to a Digital Hostage Scenario") to persistent, resilient attackers who have strategic plans for getting into and remaining in the network, so defenders need to think strategically too, if we are to stand a chance of mounting a successful counterinsurgency.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

