Sometimes the worst cyber-attacks are hiding in plain sight. Rather than overt, noisy methods of attack of the past, adversaries are increasingly taking a stealth approach, according to recent analysis of Microsoft vulnerabilities.
Beyond Trust’s Microsoft Vulnerabilities Report shows the number of critical flaws has doubled year on year, from 78 to 157. Elevation of privilege vulnerabilities now account for 40% of all disclosed issues, alongside a 73% rise in information disclosure flaws.
Experts say the nature of the flaws suggests attackers are prioritising stealthier methods that allow for quiet privilege escalation and lateral movement using legitimate credentials and living off the land tactics.
What should firms be doing to detect and mitigate these quiet breaches?
Quiet Trend
Part of the reason quiet tactics are favoured over noisy malware campaigns is the fact they are difficult to spot. Attackers increasingly “live off the land,” abusing legitimate tools already present on the system such as PowerShell, because activity generated by trusted binaries “blends into normal administrative noise,” according to Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University. “There is no malware for an antivirus to flag.”
There is also a move towards token theft and abuse of OAuth consents in cloud environments, where an attacker “never touches the endpoint at all,” Curran tells SC Media UK. “It seems the perimeter breach is no longer the story, but rather what happens in the short period afterwards, when someone moves laterally using credentials that appear entirely legitimate.”
Razvan Ionescu, head of offensive security services at Pentest-Tools, thinks the survey results show an interesting trend. “As a pen tester, what piqued my interest almost instantly was that privilege escalation issues were 40% of the Microsoft vulnerabilities disclosed last year. Combined with the 73% increase in information disclosure flaws, this suggests risk sits increasingly often beyond the initial-access stage, in the middle of the attack chain – rather than at the point of entry, which was traditionally the riskiest surface.”
Ionescu describes how this mirrors what he sees during penetration tests. “Initial access is often unremarkable: A valid or default credential, an exposed and outdated service, a compromised token, or a remote-access pathway without adequate protection opens the door. The real impact happens when we combine this foothold with weak identity controls, misconfigurations and vulnerabilities that enable access to additional systems.”
The platforms most at risk from stealthy attacks are often the ones businesses rely on most heavily. Cloud platforms, identity systems, collaboration tools and business applications such as Microsoft 365, Azure and Dynamics 365 have “become prime targets” because they “contain valuable data and sit at the centre of day-to-day operations,” according to Tom Lovell, principal consultant at Infinity Group.
In many incidents, attackers aren't even exploiting a single critical vulnerability, he says. “They're using stolen credentials, abusing legitimate administrative tools and moving through environments while appearing to be authorised users.”
Multiple seemingly low-risk weaknesses are being chained together to achieve privilege escalation and gain access to sensitive systems, according to Lovell.
“From our experience, the biggest risk isn't always the vulnerability itself, but what happens after access is obtained,” he says. “Once attackers gain access to a trusted account, they can operate undetected for weeks or months while blending in with legitimate business activity.”
AI Risk
Technology such as AI is being used by defenders to find holes in software that can lead to attacks, but experts say AI could also super-charge these types of breaches.
The task of managing software flaws is increasingly challenging, with tech giants reporting record patching cycles. In July, Microsoft released fixes for 570 new vulnerabilities. “This single month alone accounts for nearly half of what 2020 saw across the entire year: 1,268 flaws,” points out Richard Werner, cybersecurity platform lead at TrendAI.
This is the influence of AI on the defender side, he says. “It's not the quality we're worried about; the sheer volume of vulnerabilities will overwhelm most defenders' ability to patch.”
On the attacker side, AI is likely to make “established tradecraft faster and cheape,r” according to Alexander Leslie, senior advisor at Recorded Future. “It is being used by attackers to compress reconnaissance, vulnerability discovery, social engineering and code adaptation,” he says. “All of this means security teams have a higher frequency and volume of threats to triage.”
AI is likely to make attacks faster, more scalable and significantly harder to defend against, adds Lovell. Looking ahead, he predicts attackers will increasingly use AI to automate reconnaissance, identify privilege escalation paths and “combine multiple low-risk vulnerabilities into effective attack chains.”
CISO Action
The Microsoft report says that patch management alone is insufficient, however, it’s still an important factor in overall security.
Patching “remains essential,” and organisations should “continue to remediate vulnerabilities as quickly as practical,” says Lovell. However, the reality is that patching cannot always happen immediately, he says. “Critical business applications must be tested, operational dependencies need to be considered and rushed deployments can sometimes introduce outages or instability. This creates an unavoidable window of exposure that attackers are increasingly exploiting.”
Lovell thinks the focus therefore needs to be on reducing risk while patches are being assessed and deployed. “CISOs should combine strong vulnerability management with intelligent extended detection and response, continuous monitoring and 24/7 security operations centre capabilities that can identify and disrupt exploitation attempts in real time.”
An "assume breach" mindset remains critical, he adds. This means enforcing least-privilege access, implementing phishing-resistant multi-factor authentication, monitoring for abnormal behaviour and ensuring responders can rapidly contain threats before attackers are able to establish persistence, escalate privileges or move laterally through the environment.”
The priority now is privilege, agrees Curran. He advises CISOs to “ruthlessly enforce least privilege, performing tasks such as stripping standing admin rights, using just-in-time elevation, and auditing service accounts that are frequently over-privileged and forgotten.”
Overall, it’s possible to reduce the impact of stealthy attacks by taking a few simple steps. The starting point is to limit reach through least-privilege enforcement, strong segmentation, credential hygiene and continuous validation of trust boundaries, says Curran. “Focus like this should enable CISOs to sleep more soundly.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist