Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat...

18
Mendoza, Argentina, 7 October 2013 Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro [email protected] Joint Internet Society, CITEL and ITU Workshop on Combating SPAM (Mendoza, Argentina, 7 October 2013)

Transcript of Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat...

Page 1: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Mendoza, Argentina, 7 October 2013

Rethinking Spam The Evolution of a Threat Vector

Paul J.S. Oliveria

Security Focus Lead, Trend Micro

[email protected]

Joint Internet Society, CITEL and ITU

Workshop on Combating SPAM

(Mendoza, Argentina, 7 October 2013)

Page 2: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

On a typical day, Trend Micro identifies…

Page 3: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Email is BULK of malicious activities

Page 4: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Massive impact of BOTNET TAKEDOWNS

Page 5: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Spam is GLOBAL

Page 6: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

LAR is not immune

Page 7: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Spamming as a Service (SaaS)

Page 8: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

SPAM TRENDS AND TECHNIQUES

Page 9: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

“Invisible Ink”

Concealment via HTTP formatting

Page 10: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Forging header info

Adding fake header info to hide original source

Page 11: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

URL redirection using popular sites

Inclusion of popular sites in links

Page 12: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Obfuscating URLs (“Punycoded” URLs)

Converting Unicode characters to ACII characters

Page 13: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Web bugs

Tracking IDs to check active addresses

Page 14: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

10/4/2013 14 Confidential | Copyright 2012 Trend Micro Inc.

Spam email

Compromised

website

Redirect URL

Exploit

Payload

Blackhole Exploit Kit

Page 15: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Real or Not Real?

Phish: Legit:

Page 16: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Spear-phishing email: most favored APT attack bait

Page 17: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com

Conclusion

The number of spam will continue to decrease as solutions become “basic”

The number of traditional spam will decrease as new vectors emerge

Threat actors will design highly targeted attacks using customized spam

Spam will still be “sexy” for cybercriminals

Page 18: Rethinking Spam The Evolution of a Threat Vector · Rethinking Spam The Evolution of a Threat Vector Paul J.S. Oliveria Security Focus Lead, Trend Micro Paul_Oliveria@trendmicro.com