April 14, 2023 By Alan O Dwyer 3 min read

Information-stealing malware has become extremely pervasive in recent years. This malware harvests millions of credentials annually from endpoint devices and enterprises across the globe to devastating effects.

Using highly automated and orchestrated attack methods, threat actors and initial access brokers provide an endless supply of compromised credentials to cyber criminal syndicates who use those credentials as early points of entry into company networks, databases and critical online applications.

Due to evolving tactics and variants, this type of malware has proven to be highly evasive against many current security solutions. Most victim organizations only become aware of credential theft after those credentials appear for sale on dark market sites or as part of credential-based intrusions. Consequently, the overall mean time to detect (MTTD) allows ample opportunity for threat actors to put the stolen credentials to use, greatly increasing the likelihood of data access, network compromise or ransomware.

In times of ever-increasing risk, organizations must find new ways to protect their credentials against the plague of info-stealers.

An alternative solution

Knowing that information-stealing malware will likely bypass security tools and successfully steal user credentials, I recently proposed an alternative detection method.

CredInt is both OS and device-agnostic. It employs readily available technologies and a systematically created credential pair saved onto each end-user device. In addition, it also utilizes a web-accessible login portal used to initiate alert logic when those specific credentials are attempted.

Following the attack cycle

From the attacker’s perspective, the millions of credentials that are harvested will always require some validity checking (at scale) to verify that the stolen credentials are active and marketable. This becomes the reliable constant in the attack cycle where malicious activity can be instantly observed.

By purposely creating a unique credential pair tied specifically to an end-user device for immediate identification, the “CredInt” pair can be used to trigger an alert when attempted against a corresponding web portal registered for the specific credential combination.

Uses, limitations and expectations

The concept of CredInt poses no actual harm or risk to the end user or the organization that deploys this method. It only comes into action once attackers have already successfully extracted credentials and attempted to use them.

Additionally, this method is not overly complicated to deploy or manage. Current web-app technology could be tailored for this specific controlled functionality and to protect the anonymity of both the web portal and the backend collection servers. It is scalable and retroactively compatible with all devices.

In a traditional honeypot implementation, a system is purposely exposed to entice and attract attacker activity. Unfortunately, false positives are a frequent result. CredInt is different: it’s a detection method only. No direct interaction is expected or provided on the end user device. It is designed as an alerting function based on anticipated external attack-chain events of compromised credential validation.

CredInt will also provide incredibly high-quality cyber intelligence and forensic value on the identified victim machine. That data can be shared across other security platforms and internal security teams to further bolster protection.

Finally, many organizations run OTP or MFA and password manager authentication solutions to provide enhanced access controls. CredInt will still provide an observable security event if a victim machine suffers browser-sourced information-stealer malware, which may have gone undetected. This includes detection on devices that store other critical data such as Crypto Wallets, Tokens or API Keys.

It’s clear that organizations must start implementing new methods of securing their data. To combat info-stealing malware, CredInt proposes one possible solution.

More from Risk Management

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today