Searchable transcript of Hiding in plain sight: Fake GPTs, SMTP malware and NetScaler zero-days — IBM Technology (20:43). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 It appears that hackers are infecting email applications. Panelists, I have one very important question for you. Can I use this as an excuse to not respond to my boss? Respond to your boss. But definitely just take a little bit of time to it before you do. Only don't respond if you're really sure it's infected. And you can blame it on that. Otherwise, maybe still respond.
00:23 Yeah, absolutely. I just have to wait for the threat actors to get off the Slack. Hello, and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your new host, Patrick Lucas Austin, taking over for the great Matt Kozinski, who we wish the best of luck on this next endeavor.
00:51 Am I a very advanced deepfake? Hopefully by the end of the episode, our esteemed panel will be able to figure it out. We are joined today by Michelle Alvarez, Manager, IBM X-Force Threat Intelligence, Giacomo Casoni, Senior X-Force Incident Response Consultant, and Norman Dorsch, Product Manager, X-Force. This week is the first week of Cybersecurity Awareness Month, as well as what looks like Imposter Week on Security Intelligence as we tackle a host of stories about impersonators of all sorts, be it links,
01:24 credentials, straight up anti-spam software, podcast hosts. Let's get into our first story. Huntress researchers have observed bad actors using custom ChatGPT instances to deploy suspicious links that will infect a user's computer. And cause them to download some malware. They're using a ClickFix-style malware delivery technique, as well as banking on the reputation of ChatGPT itself.
02:04 Banking on that little URL bar that shows that your GPT instance is hosted on a custom GPT page. Michelle, I want to go to you with this with this first question, how bad is this and how maybe how common is this tactic? Should I be worried about this? When I do a Google search and click a link? I think we've been talking about ClickFix attacks now for some time.
02:27 Definitely since last year. I know on this podcast we covered it in the end of year review. There's been ClickFix campaigns that have been, you know, publicized, for the last, I would say, at least two years now. And I think maybe just all of this talk about AI and frontier AI finding vulnerabilities is sort of overshadowing this notable threat that seems to continue to evolve.
02:56 Norman, what are you thinking about This, this tactic? Is it more of the same, is it, you know, taking advantage of these AI tools that make it happen faster, you know, how can we, you know, prepare ourselves? And what should we know? Yeah. I mean, in general, it still applies to the same attack chain. Right. And the general kill chain is still the same steps, but it's very powerful.
03:19 And it's more powerful than a lot of other deployment mechanisms because the user is the one actually installing the payload during that ClickFix attack. And I'm the one person on the planet that probably hates CAPTCHAs the most. I solve like 30% of them on the first try. And every other one I have to re-solve and get told I'm a bot. And it it's so frustrating for normal people to solve CAPTCHAs.
03:48 Right. And that's why when the human aspect comes in and you see, I think the typical prompt in these click attacks is, okay, prove that you're not, prove that you're human. Paste this command into your terminal, and then it executes the payload. It actually deploys the payload on the user's system and you get C2. And so that's just so powerful because the human psychology is involved.
04:16 Everybody hates CAPTCHAs. Everybody thinks, I just want to get to this page and finally get done with my day. And then I still need to do this little, I only need to do this little piece here to get to where I want to. And here we are. So very powerful. Impersonation tactic or very, very powerful tactic in general. But the general kill chain is still the same steps.
04:42 Giacomo, my question is about custom GPTs that are hosted by GPT. Is there any way that these AI companies can maybe monitor what these custom GPTs are being fed or trained on, in order to conduct these malicious attacks? I don't think they're here to stay, actually, I've seen news where they're being phased out. But in general, I think that whenever you, whenever a company, has a marketplace of sorts, like VS Code or, you know, for example, it is expected that they will have at some point, a level of responsibility in
05:20 terms of pruning out what is proven to be malicious. Right? Google has to do it from the Play Store. Apple has to do it from whatever Apple users install their applications from and so I think eventually if this becomes more popular, OpenAI will be held accountable for decision layers. But like Norman said, in terms of the kill chain, same old, same old, it's quite surprising the companies are still being affected by a ClickFix, to be honest.
05:52 But it's interesting that these links are coming from sponsored search results. I'm wondering if there's anything that these search providers can do to investigate or verify these search results. to maybe double check them and see whether they link to malicious pages or anything like that. Is that something that is a possibility or something that security researchers are hoping will happen?
06:14 Yeah, I think there's always something more that we can be doing in terms of monitoring and identifying malicious sites. But I have to mention that I think it is not surprising that organizations are still vulnerable to these attacks just because, again, they're preying on social engineering. And maybe we're doing a disservice to users, because we're calling it ClickFix, which maybe you're looking for something else.
06:45 You think something else, like just a software update that looks malicious is a ClickFix attack when it's exactly what Norman also mentioned, the CAPTCHA, which has become so commonplace that users aren't looking out for that. So I think often times the user awareness and education is a few steps behind, these types of attacks. And we think it's been around and it has for a while now, but for a lot of different types of audiences, it hasn't.
07:15 It's brand new. This is the first time they're being impacted by receiving it in the news. So I think it's just kind of that drumbeat of bringing awareness to the various audiences who may not be, as you know, cyber aware as this group here. Let's move on to our next topic before I click on the link I'm not supposed to. Rapid7 Intelligence, the Offensive Engine Division of Rapid7, detailed some new offensives using some rather traditional backdoor tactics used by threat actors, allowing them to implant Trojans
07:54 into company systems. The malware is attempting to mimic anti-spam software SpamSniper, which has been used according to Japanese B2B search platform IPROS. Used by over 6000 organizations, it's able to essentially impersonate mimic this anti-spam software by copying its process ID files, its system services, and its commonly used Linux services. According to Christiaan Beek of Rapid7 Intelligence, "These devices sit at the network edge on the path between the internet and the core, and are often trusted by the
08:36 firewall rules around them. Foothold there is well placed for long term access, particularly in telco environments." You know, Michelle, this sounds like a pretty big deal and a pretty, you know, clever tactic to sort of attack the email layer. How can defenders detect imposters in these areas, and how do you stop them from taking advantage of these sort of traditional communication protocols?
09:07 Yeah. So I think it comes down to sort of the behavioral analysis of the activity. I think it is going to be difficult because it so stealthy, that they're targeting these email gateway servers that are sort of in this trusted position, right, that they're sending our email, and so I think it is challenging with this particular type of malware. And so EDR is going to be important, right?
09:38 Once it's already on the system, making sure that you're limiting the blast radius, you know, once the the malware is within the network and there's compromise that's underway, limiting that blast radius and the lateral threat, you know, movement of the actor, across the network in particular, in this case in telco. It's very interesting you say that because in the in the same story Beek says many organizations lack a baseline of what normal outbound mail traffic looks like, which is what makes the anomaly detectable.
10:14 Norman, I see you nodding, as you're very familiar with the traffic of your mail. So I'm wondering without having that baseline, how does one detect anomalous activity? In general I do think is one of the cases where you don't necessarily have to shut anything down, but just do some really good threat hunting. And, I mean, you asked earlier, right. How do you find that stuff without looking at the mail traffic?
10:37 You don't. I think in this particular case, really the only thing you can do is like, look at outgoing mail traffic, I think Port 25, or just really look at anything on that port that's not a mail server must be something malicious, or at least is worth a closer look. So, cases like this where it's mimicry and where it's real implants that go beyond just like a file name being the same or some, some minor hashes being tried to mimic.
11:11 I think it's really important to just really look into it and be aware it's hard to detect. And then if there is a suspicion, you've really got to do some really deep level threat hunting, looking for deleted executables, looking for changes in log files, all that kind of stuff that skilled threat hunters do. And then, hopefully find evidence of a breach or even better, find evidence that it was a false positive.
11:38 Giacomo, I'm going to ask if we can maybe. I mean, I assume, since they are using AI to sort of create these malware agents. Can we use AI to detect these agents operating, within these networks? Is this a job for an AI agent to kind of sit around and and check the traffic and say, hey, this looks a little odd to me? Potentially, but I do think there has to be someone that understands the attack and the implants to collect the right data to feed into the agent.
12:10 And if anything actually, I wonder whether the impersonation itself, gives some detection opportunities because these boxes are often vendor managed, right? They should know what the baseline of their own product is. And so if something is trying to impersonate them, that in and of itself, is suspicious. But, yeah, potentially, one day AI would be able to do it all.
12:35 One interesting line, Norman, from the Rapid7 report talking about or calling it a regionalized disguise. You sort of observe you target, you find out what, you know, what tactics they use and how you can sort of blend in. Is this a, are there differences when it comes to regionalized disguise, maybe globally? Would an attack affecting an email security system in Taiwan be any different from a maybe US-based email security vendor?
13:14 I think that particular vendor, if I'm not mistaken, was very common in Taiwan and South Korea. I think in general, there's in terms of the general traffic you would use or the general attacks you would use to affect those systems. There's no real regional differences. There is regional differences in the in the types of threat actors and their goals, right.
13:41 I can't wait to never send an email again. But, until then, let's move on to our final story. We have a mass exploitation of Citrix NetScaler from potentially state linked actors targeting vulnerabilities in the platform all around the globe. So we've got Citrix disclosing eight NetScaler and NetScaler Gateway vulnerabilities, two of which were confirmed to be under exploitation with a 9.5 out of ten vulnerability rating.
14:20 The attacks date back to at least September, with groups like Palo Alto Networks telling Cybersecurity Dive that they found activity going as far back as August 21st. I'll go to you, Giacomo. Researchers are saying that applying those fixes is not enough to get the to sort of solve the problem entirely. What else do cybersecurity defenders need to worry about when fixing a huge vulnerability like this?
14:48 I'd say that fixing the vulnerability isn't enough. It probably leads back to the fact that if you have already been compromised, then you can't fix the entry point. The attackers already have access to your NetScaler. Which really ties into how hard it is to address these kinds of issues. Because NetScalers and other edge devices, Right, they have to be on the internet by virtue of what they are.
15:17 And and if there is a zero day, then obviously you cannot detect exploitation. Where you can detect though are these other persistence mechanisms. Which now you have to be looking for, if there's a chance that you have been compromised, right. So web shells or suspicious behavior that your NetScaler is carrying out. And then in terms of shutting down your NetScaler, that is a solution, obviously.
15:51 But there is quite some work ahead of time that can be done. In terms of both knowing what you should be doing when your NetScaler gets compromised because it will eventually. We've seen a lot of vulnerabilities affecting these devices in the past couple of years. And then also, you should be implementing proper segregation and zero trust. Michelle, I'm looking through my my cybersecurity bookshelf of playbooks, and I don't see my NetScaler notebook.
16:22 It's here somewhere. Should I have a NetScaler notebook or or is that overkill? Well, maybe it's not to NetScaler, but definitely you bring up a great point, that you need a playbook for different types of attacks, and you want to make sure that it's been tested. So what comes to mind also is just business continuity plans. What's your plan should you have to take your NetScaler device offline?
16:48 Or let's say you're going to keep it up, what other mitigation strategies do you have in place? How are you, and as Giacomo mentioned, right. If you've already been infected, hopefully you're working with a great incident response partner to identify, you know, how far the threat actor has moved within the environment. What have they been able to take?
17:14 And another thing there is, I know that retention of logs is very important. So I think the date you mentioned was that we've seen or they've seen them in the environment as far back as August of this year. And, I mean, we're just now finding out about this exploitation. So if your logging only goes back a month or two, you're not going to catch them from the beginning.
17:37 You're going to miss a lot of important forensic evidence in order to put the case together, figure out exactly what happened and what they've taken. Yeah, that's a great point. And I think that evidence is essential, especially when exchanging information with other security agencies. Norman, I'm seeing since this impacts, you know, companies globally, a lot of security organizations have issued advisories and exchanged information with, with each other to address this issue.
18:11 How important is that information exchange with these you know, with these security centers and how does it help mitigate the damage done by these exploited vulnerabilities? Super important. Obviously it just helps if the good guys work together closer and if we share information around zero days before they get exploited or then after exploit, come up with good post exploit strategies, right, or remediation strategies.
18:43 Then it just speeds up recovery across the globe in this particular case. I think it's also, to Michelle's point, it's so important to just look at okay, what forensic evidence might be there? How can we look at just not closing the door by patching it, but actually looking in the house? What has happened? Just make sure that these actors that might already be in get kicked out as well instead of just fixing it, or trying to fix it through a patch.
19:20 And then I do think, in this particular case, it's just proving that a remediation strategy and cyber range experiences, tabletop exercises, who does what, who makes the choice of whether to take an appliance offline or not, are just so important because here we saw, I think the article mentioned some of those hospitals that were affected in the Netherlands, they actually took the patient portals offline and made that choice of, okay, we'll accept the business disruption, for the sake of the greater good, which often
20:01 makes sense. But it's so important to know who makes that choice? What can we do? And what's the chain of command in the event something like this happening? Okay, I think that does it for this episode. I want to thank Michelle, Giacomo and Norman for joining us today. I want to thank the viewers and the listeners as well. And I want to thank our producers. Subscribe to Security Intelligence wherever podcasts are found, so that you never miss an episode. And stay safe out there.