During the ESET European Cybersecurity Day virtual event, the results of the ESET Industry Report on Government, created in accordance with the forecasts of the European Commission, CERN and Europol, were presented
Milan, 5 May 2021 – The cybersecurity strategy of the European Union, and that of all government organizations globally, has been tested not only in its shift to “digital by default”, but also by the COVID-19 pandemic, the mass movement towards remote working, and threats such as cyber-espionage, ransomware and supply-chain attacks. In particular, the most demanding challenge, and the enemy, common to all government organizations, are advanced persistent threat (APT) groups.
APT groups that use advanced tools
The report by ESET, a global leader in the cybersecurity market, on Government Organizations examines the threat landscape that APT operators are implementing, and highlights its complex nature with a particular focus on EmissarySoldier, a malicious campaign carried out by the APT group LuckyMouse through its SysUpdate toolkit to compromise computers, some of which were running the popular Microsoft SharePoint application.
The analysis on LuckyMouse examines the relatively unknown SysUpdate toolkit – the first samples of which were detected in 2018. Since then, the toolkit has seen various stages of development. LuckyMouse's current modus operandi is to install itself via a template that uses three components: an application vulnerable to DLL hiijacking, a custom DLL file library that executes the useful content, and a Shikata Ga Nai encoded payload. Since SysUpdate's modular architecture allows its operators to limit the visibility of malicious code, ESET researchers have not tracked down any suspicious modules, but believe this will be a challenge to be addressed in future analyses. LuckyMouse grew its business in 2020, however, likely through a retooling process where various features were gradually integrated into the SysUpdate toolset.
Understanding how the tools exploited by APT groups like LuckyMouse evolve is of fundamental importance given that government organizations are invested with the responsibility of ensuring stability for citizens, companies and towards other nations. LuckyMouse, and other APT groups, pose a threat to governments and also to public bodies that typically use popular collaboration platforms such as Microsoft SharePoint and digital services.
Featured government organizations
2020 and 2021 saw ESET collaborate on various research, including with organizations of the caliber of the European Organization for Nuclear Research (CERN, Europol and the French National Cybersecurity Agency ANSSI). Many of their perspectives, shared during the virtual event and in the report, highlight that government organizations and their IT infrastructures are considered default targets.
The Report highlights the need for technology experts to continue to support government organizations in closing security gaps and monitoring APT groups' approaches, techniques and procedures through appropriate endpoint detection and response technologies at their disposal.
To download the report see Welivesecurity.com






