The insider threat and phishing, under the auspices of artificial intelligence (AI) are among topics in a cyber threat landscape report for the first quarter of 2024, by the risk consultancy Kroll. Laurie Iacono, George Glass, Keith Wojcieszek report.
We saw an evolution in techniques used by attackers, some of which may point to longer term trends in the variation and sophistication of attacks faced. In particular, with regards to phishing, we saw SMS and voice-based tactics being used, which raises concern around the potential for deep fakes and AI-type technologies to fur-ther enhance the effectiveness of phishing attacks. In the same vein, one insider threat case investigated by Kroll this quarter saw employee impersonation take place, another area where AI-type technology could be especially effective. Additionally this quarter, Krollโs investigation into the ScreenConnect CVE [common vulnerabilities and exposures] shows attackers getting faster in their exploitation of CVEs.
Two industries are the focus: technology/telecoms and construction. The former saw significant growth in insider threat cases, potentially a result of increased supply chain risk. The latter saw steady growth in email compromise over the past year, which could be driven by the nature of work in this industry, meaning that employees are often working via mobile devices or on site, where they may be more susceptible to attack.
โ
Timeline
January
โข Two zero-day vulnerabilities identified in Ivanti Connect Secure and Ivanti Policy Secure Gateways.
โข AKIRA ransomware tactics, techniques and procedures (TTPs) evolve, with threat ac-tors targeting companies with vulnerable interfacing Cisco ASA or FTD devices, then wiping those companiesโ backups before deploying the ransomware.
February
โข Kroll identified critical vulnerabilities in ConnectWise ScreenConnect that allowed for authentication bypass and remote code execution.
โข The LOCKBIT ransomware group has their operation disrupted by law enforce-ment with the takedown of their data leak site, 34 servers and account closures. Law enforcement officials also obtain decryption keys and make two arrests.
โข LOCKBIT returns towards the end of the month with new encryptors and servers for attacks, as well as an updated ransom note.
โข Change Healthcare is hit by a cybersecurity incident. Numerous healthcare organiza-tions report major outages due to the attack.
March
โข KTA248 begins a campaign of PIKABOT distribution via email and another campaign that attempts to exfiltrate NTLMv2 hashes from victim environments.
โข BLACKCAT shuts off their servers amid claims that they exit scammed, allegedly fak-ing the law enforcement seizure posted on their Tor site to avoid sharing a new ran-som payment with their affiliates.
Professional services
The sectors targeted by threat actors in the first quarter of 2024 were consistent with previous quarters. Professional services remained the focus for attacks, accounting for 24 per cent of cases, while manufacturing continued to rank at second place, with 13pc of cases, followed by financial services and health care at 9pc and 8pc respectively.
Attacks against the construction sector accounted for nearly 6pc of all Kroll incident response engagements. This was double the sectorโs peak of 3pc in the first quarter of 2023. Attacks against the construction sector are most likely to be some form of business email com-promise (BEC). A review of cases indicates that carefully crafted phishing lures designed to mirror document-signing are a common way to socially engineer victims into giving up their credentials and, in some cases, their multi-factor authentication (MFA) prompts using an attacker-in-the-middle methodology.
Construction firms may be targeted in this way for several purposes. One is for financial gain, as a result of social engineering campaigns that redirect vendor payments to a fraudulent bank account.
In other cases, the construction company is used as the pivot point for downstream attacks. In these cases, actors use unauthorised access to a userโs email inbox to phish other clients. For example, sending out fake requests for document signature to multiple vendors to gain credentials from those vendors and extend their victim access. The reason for these rising attacks may be because the industry involves many digital sign-ins via mobile devices on sites. An employee may be more likely to fall for a phishing lure if they are receiving the email on the road, making them potentially less vigilant about the signs of a fraudulent email.
Phishing techniques, tactics
Kroll observed a slight increase in email compromise, with it remaining the most common type of threat incident. Interestingly, the percentage of ransomware cases declined, potentially as a result of disruptions affecting the large ransomware-as-a-service variants such as LockBit and BlackCat. Phishing was the most likely vector for email compromise incidents. Kroll observed that in the first quarter, while phishing was typically synonymous with an email message, actors continued to evolve tactics and introduce other tactics, such as SMS lures and voice phishing, which seem to be rising in popularity.
For many firms, security controls put into place to decrease the likelihood of BEC attacks include the verbal authentication of C-level personnel (such as chief executive or financial officers). Despite the fact that these were intended to add an extra layer of authentication for requests undertaken strictly through email, Kroll has observed cases in which actors are likely using commonly available deep fake tools to clone the voices of CEOs and CFOs.
Case study
In one such case, Kroll noted repeated voicemail messages simulating the CEOโs voice to authorize fraudulent transactions. The messages were upwards of five minutes long, potentially to increase the likelihood of the scam being actioned. While employees may be more suspicious of a short message cloning the CEOโs voice, a longer messageโwhich leverages publicly available voice recordings of the CEOโarguably seems more legitimate. Such attempts highlight the increased risk that deep fakes and other AI-type technologies pose.
Insider threat by sector
A review of Kroll engagements for insider threat revealed insights into the sectors most vulnerable to such attacks. Kroll observed that cases impacting the technology/telecom sector were most likely to be insider threat cases. With most technology providers working with multiple downstream customers, an insider with access to multiple technology providers may have the ability to cascade malicious activity to clients, posing the risk of a supply chain attack.
For the first time, we also split out the proportion of insider threat engagements deemed to be intentional versus those deemed to be unintentional. In 90 per cent of cases, Kroll observes the insider threat being intentional, and therefore arguably malicious in intent, as opposed to accidental. This highlights the importance of insider threat not being overlooked as a threat incident type by companies.
Case study: employee impersonation
In one case observed by Kroll, an employee on-boarded by a third-party contracting firm began displaying suspicious behaviour. The employee, who had been given access to confidential and sensitive information due to their job role, frequently delayed communication and stopped communicating altogether once more serious questions were raised about the legitimacy of his identity. In this case, Kroll was able to help the company identify that the employed individual was accessing the network from a different country to the one they claimed to reside in. Kroll also helped identify the data at risk associated with the employee.
Although Kroll did not observe the use of deep fake technology in enhancing the employee impersonation, this case does highlight how sophisticated AI technology could result in more convincing campaigns of this type.




