Listen to this episode

Unraveling BlackTech: A Deep Dive into Advanced Persistent Threats and Network Security

0:0016:35

Recorded October 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this news roundup episode, host Craig Petronella of Petronella Technology Group shares highlights from recent cybersecurity and compliance headlines. He discusses a Cisco zero day exploit, CVE 2023-20109, tied to BlackTech, a Chinese state-sponsored advanced persistent threat that, according to a joint advisory from the NSA, FBI, CISA and Japan's NISC, modifies router firmware on network edge devices to hide its activity and pivot from international subsidiaries to headquarters in the United States and Japan.

Craig argues that Cisco has priced out many small businesses and warns that legacy products without active subscriptions cannot be patched and will eventually be exploited. He then covers the ransomware attack on Johnson Controls, saying a group called the VX Underground, known as the Dark Angels, claims to have stolen 27 terabytes of data and is holding it for ransom. Craig also relays an FBI warning about dual ransomware attacks and closes with defensive guidance on offline backups, phishing-resistant MFA, user account audits, remote desktop protocol hardening and network segmentation.

Worth remembering

Key takeaways

  1. Craig cites a joint advisory from the NSA, FBI, CISA and Japan's NISC describing BlackTech modifying Cisco router firmware to persist and pivot between subsidiaries and headquarters.
    “blacktech has been observed modifying router firmware on Cisco routers to maintain a stealthy persistence and pivot from international subsidiaries to headquarters in Japan and the United States”
  2. Craig argues the BlackTech intrusions show why you should have logging and a SEM solution constantly monitored by a security operations center or in-house cybersecurity experts.
    “this is why you should have logging and a SEM solution that is constantly being monitored by either a security operations center or staff on your team of cybersecurity experts”
  3. Craig warns that older products without an active subscription stop receiving updates, and these legacy devices are the ones hackers will target.
    “And if you have an older product and you don't get the updates, that's called a legacy product, and that legacy product is a risk to your network.”
  4. Craig says strong data backup, disaster recovery and business continuity allow recovery without paying, but attackers count on most organizations not doing this preparation.
    “Now you can recover from a ransomware attack without paying the ransom if you have strong data backup, disaster recovery and business continuity.”
  5. Craig strongly advises annual tabletop exercises and penetration testing to confirm third party backup tools are capturing data and that recovery actually works.
    “you need to do the tabletop exercises and the pen testing to test and make sure that you can recover”
  6. Craig relays an FBI warning that dual ransomware attacks hit victims with a second variant between two and 10 days after the first to pressure faster payment.
    “They're saying that they hit a victim with one of these variants and then between two to 10 days, they hit them again with a different variant.”
  7. Craig says MFA is required by cybersecurity insurance providers at the time of recording, and recommends software authentication apps or hardware tokens over cell phone one-time pins.
    “Try to avoid a cell phone one-time pin usage, because then that subjects you to some type of SIM swap attack.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

What if you had a front-row seat to one of the most riveting stories in cybersecurity today? Join us as we unravel the story of the Chinese state-sponsored Advanced Persistent Threat, BlackTech, and their exploitation of the Cisco Zero Day CVE 2023-20109. We dissect their strategy of modifying router firmware on Cisco routers, maintaining a stealthy persistence, and pivoting from international subsidiaries to headquarters in Japan and the U.S. We also shed light on their target: branch routers and the abuse of trusted relationships within corporate networks. In addition, we touch on the recent ransomware attack that Johnson Controls faced and the FBI's warning about dual attacks with diverse ransomware variants.

As we navigate the dense terrain of cybersecurity, we promise to enlighten you on network segmentation, a crucial measure for enhanced security and cost savings. We will guide you on creating network enclaves to handle sensitive information securely and discuss the benefits of firewall and switch segmentation for absolute separation of network communications. Furthermore, we emphasize the importance of adhering to the latest security standards like CMMC for better compliance. This episode is a goldmine of practical solutions for network security, making it essential for anyone who lives in the digital world. Stay tuned for this enlightening experience on the pressing issues in cybersecurity today.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.