Skip to content

MSPs putting a stop to “hide and seek” within their environments with ESET Cloud Office Security

Amidst increased obfuscation of multistage malware attacks, MSPs need an effective way to secure cloud communication while avoiding the need for multiple unique network connection authorizations.

The days of simple and easily detectable malware are long gone. Recent campaigns by both OilRig and MuddyWater advanced persistent threat (APT) groups show that threat actors are constantly seeking new ways to hide their multistage malware attacks among files of commonly used cloud services. 

This presents a dilemma for managed service providers (MSPs) that rely heavily on cloud-based solutions. But how should MSPs defend against increasingly sophisticated attacks without the burden of trying to control every single stream of communication within the MSP environment?

A growing market and a growing threat

With the never-ending hunger for cloud-managed services, it is no surprise that the MSP market is constantly expanding, and business reports, such as MarketsandMarkets, expect further growth by around $100 billion U.S. dollars within the next five years.

Both MSPs and other outsourced business practices have proven to be the answer for countless companies seeking high-end solutions for reasonable prices. But there are two sides to every coin. Professional communications, services, and shared files all moving to the cloud has created a new breeding ground for sophisticated malware.

Threat actors deploying this malware are often profit-driven and/or state-sponsored APT groups using command-and-control (C&C) servers to communicate with compromised devices over targeted networks. When successful, these servers can issue commands to steal or encrypt data, spread malware, disrupt web services, and more.

To enable this approach, APT groups need to establish persistence within the targeted businesses, obfuscating malicious files and processes among legitimate ones.

A draft email you’ll never send … nor ever even wrote

ESET researchers have described recent attacks in detail while following the evolution of campaigns run by the OilRig group.

To avoid cybersecurity scanning tools, OilRig has not been deploying fully fledged malware but, instead, has scaled its attacks. While the initial attack vector of the recent campaigns remains unknown, presumably it was a phishing email. This email would contain a downloader that wouldn’t cause any specific damage but, as the name implies, is designed to secretly download additional malware from the internet. Several versions of these downloaders have been documented by ESET researchers.

Studying these downloaders, it is clear that OilRig is keenly focused on identifying new ways to obfuscate malware deployment using legitimate cloud service providers for C&C communication.

The first in the series, SC5k downloader, uses the a shared Microsoft Exchange email account and Microsoft Office Exchange Web Services API for C&C communication. Within this email account, the attackers create draft messages with hidden commands. Once the downloader infests a device, it will log in to the same account to receive both the commands and the payloads to execute. Its successor, OilCheck, works similarly but uses the Outlook mail API in Microsoft Graph. 

New versions of OilRig downloaders, ODAgent and OilBooster, communicate using the Microsoft Graph OneDrive API. They access a OneDrive account controlled by the attackers for C&C communication and exfiltration.

The evolution of malware-hiding capabilities was also recently noted in the case of another APT group linked to Iran called MuddyWater

In a separate MuddyWater campaign, described by DeepInstinct, the APT group reused previously known remote administration tools and hid them in the cloud-based content management system (CMS), called Storyblok, to host archives with compromised files.

ESET to help deal with the dilemma

The hiding capabilities of present-day C&C attacks have pushed businesses toward higher control over their network traffic. From standard network monitoring, it can go as far as individually authorizing any network connection.

However, the higher the control, the higher the workload on MSP admins and technicians who are already drained from a never-ending stream of alerts. So what do businesses choose: strict control that comes with alert fatigue or lower security standards that can result in a data breach?

With its MSP Program, ESET can help businesses deal with this dilemma. The program is based on the ESET PROTECT solution, which provides multilayered protection, and its higher tiers also integrate ESET Cloud Office Security (ECOS), which is designed to protect Microsoft 365 and Google Workspace applications.

ECOS — effectiveness in numbers*

  • 750,000 email threats detected
  • 360,000 phishing emails blocked
  • 21 million spam emails captured

*7-month period in 2023

In fact, these ESET security solutions can disrupt the described C&C processes at several stages, which means that companies don’t have to focus on network control as much.

Anti-phishing protection

Though the initial attack vectors of OilRig and MuddyWater campaigns are unknown, both APT groups have successfully kicked off their campaigns with phishing emails in the past. ECOS prevents users from accessing web pages known for phishing once they click on the phishing link in the email.

Antimalware protection

ESET’s defense against malware eliminates all types of threats. Moreover, ECOS scans all new and changed files in OneDrive, Google Drive, Microsoft Teams, and SharePoint Online.

ESET LiveGuard Advanced

If ESET malware detection engines detect a never-before-seen type of threat, they pass the file to the ESET cloud-based sandboxing tool ESET LiveGuard Advanced for further assessment.

Multi-tenant

ECOS multi-tenant functionality allows you to protect and manage multiple Microsoft 365 and Google Workspace tenants from one ESET Cloud Office Security console.

Conclusion

The growth of cloud-based business practices has ushered in cloud-based cyberattack tactics that MSPs need to deal with. And the results can be dire. With their privileged access to business networks, compromised MSPs can also be dangerous for their clients by triggering a supply chain attack.

The good news is that you don’t need to face those threats alone. Since its foundation in 1992, ESET has developed a robust multilayered defense system capable of stopping C&C attacks at different stages and much more. ESET solutions are also available for MSPs as a part of the ESET MSP Program. Don’t be the weak link in supplier relationships. Be the strongest. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Japan partner Canon Marketing Japan Inc. to succeed once again

  • ESET Japan partner Canon Marketing Japan Inc., has secured first rank in the Nikkei Computer Customer Satisfaction Survey 2023.
  • Along with other solutions that Canon Marketing Japan Inc. provides, ESET’s business and enterprise solutions achieved exceptional satisfaction in crucial areas such as performance & functionality, reliability, operability, cost, and support. 

BRATISLAVA, — December 19, 2023 —  ESET, a global cybersecurity leader, announced that its esteemed Japanese partner, Canon Marketing Japan Inc., has proved their leadership in providing valuable products and services and secured the top-ranking award in the Nikkei Computer Customer Satisfaction Survey 2023. Canon Marketing Japan Inc. took first place in the “Security Product” category for the eleventh consecutive year.

In this survey by Nikkei Business Publications, a prominent content provider in Japan, approximately 1 000 IT decision makers at publicly listed companies, private companies with sales of more than 20 billion Yen, and government offices were surveyed. Providers were assessed across seven groups of criteria and categories: Overall Satisfaction, Performance & Functionality, Reliability, Operability, Cost, Support, and Intent to renew. Respondents assigned satisfaction scores for each category, and final scores were then calculated as an average of points across these categories.  Canon Marketing Japan Inc. outperformed competitors in Overall Satisfaction, being the top vendor in the list ranking for the eleventh year in a row. ESET’s PROTECT solutions in particular achieved an exceptional Overall Satisfaction score of 76.1 points, a remarkable six points above the vendor average. Notably, the solution received top scores for ‘Performance/Functionality’ (79.9) and ‘Cost’ (77.7), surpassing industry standards across all evaluation categories.

At the heart of Canon Marketing Japan Inc.’s offer lie ESET’s award-winning security solutions with cutting-edge technology. ESET PROTECT Platform offers a robust defense against cyber threats, based on superior research.  Incorporating advanced features like multilayered detection, machine learning, and cloud technologies provides a unique balance of prevention, detection and response capabilities.. While information security management is an important management issue for companies and organizations, the lack of human resources has recently become a major concern. Canon Marketing Japan Inc. supports customers by reducing the burden of installing and operating security products and by providing solutions that include Security Services such as ESET PROTECT MDR.

“Nikkei Computer Customer Satisfaction Survey’s consistent recognition of our partnership with ESET speaks volumes about the exceptional quality of their ESET PROTECT solutions”, said Naotaka Koshimizu, Senior General Manager of the Security Solution Planning Group at Canon Marketing Japan Inc. “Ranging from ESET Endpoint Security to ESET PROTECT solutions – these are the core of Canon Marketing Japan Inc. cybersecurity services, thanks to which we have been able to maintain the highest level of customer satisfaction for many years. The innovative MDR protection is an easy-to-deploy security management solution, that not only fortifies our clients’ digital perimeters but also significantly alleviates operational burdens. This powerful combination ensures our customers can focus on their core objectives, confident that their digital assets are safeguarded by industry-leading technology and expertise.”

Hiroya Kuroda, Country Manager at ESET Japan added, “Our partnership with Canon Marketing Japan Inc. is built on a shared commitment to providing innovative security solutions. We are immensely proud of this collaboration, which over the years has not only elevated our security offerings but also enriched our relationship with our clients. The success highlighted by the Nikkei Computer Customer Satisfaction Survey’s recognition underscores the consistent excellence of our collaborative efforts and the unwavering commitment to providing cutting-edge security solutions.”

Discover more about ESET PROTECT solutions here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Better to watch Troy than have trojan malware on your Android TV

Alžbeta Kovaľová

A group of malware researchers recently discovered a new trojan variant of the notorious Mirai malware botnet. The story of Mirai has been a fascinating one, to say the least. From one of the most prevalent and widely detected threats dating back to 2016 to its many variants and global reach that never truly seems to die, the Mirai botnet has evolved to hijack consumer-grade Internet of Things (IoT) devices on and off for more than seven years. The creators have since been caught; however, Mirai-based botnets remain a threat as the code lives on. It has given birth to many variants and continues to mutate, resulting in the tale at hand today.

A botnet is a large network enslaved by threat actors. Botnets are mainly used for DDoS attacks and stealing of data, but can be misused for other malicious campaigns as well.

This new variant of the Mirai malware has been spotted infecting inexpensive the Android TV set-top boxes of millions of users. This new trojan is a new version of the “Pandora” backdoor that first appeared in 2015.

Its primary targets are budget-friendly Android TV sets, but ESET Mobile Security has been able to block it on both Android TVs and Android smartphones in over 30,000 instances since September 2023. The way it infects a device is by the user downloading a seemingly legitimate app to stream content. These apps can be downloaded from websites dedicated to smartphones, TVs, and Fire TV Sticks.

The apps themselves promise to provide a wide range of TV shows and movies for the user to watch for free, via a trial account or with a premium account. The specifics of this particular type of threat is that its malicious functionality doesn’t present visually to the user, and there are virtually no signs that any malicious activity is happening on the device, or signs that the app might be malicious. Even the permissions the apps asks for don´t appear to be intrusive.

 

One of the reasons people are tending to opt for cheaper streaming services and TV boxes may be the cost of living crisis, as well as the high prices associated with multiple mainstream streaming platforms. However, there are costs to users who try to get “a deal.” These cheaper hardware options are often manufactured quickly without much thought to their security, a feature they share with many other IoT devices. This leaves them more vulnerable to tampering, specifically the potential for firmware alterations. So, even for those who are conscious and selective about the apps that they install, the device might arrive to them with preloaded malware.

The importance of trusted security software

As we have established earlier, in this instance, to the naked eye, it is virtually impossible to realize whether or not a device has been infected. Furthermore, since users have no way of knowing if apps they’d like to use with their devices are malicious or not, they would have no reason to uninstall and delete them from their devices.

To avoid infection and worry, users can employ ESET Mobile Security (EMS), which is able to detect and block this and similar threats during the download process, even before installation occurs. This means that the threat never reaches the user. EMS can also be used to scan already existing apps and downloads to double-check that you haven’t bought the devil in disguise. In the case of a malicious app or download, EMS alerts users that malicious code has been detected — as seen on the picture below.

 

While it is always essential to stay alert, use of a security solution proves itself time and time again to be critical in combating the cyberthreats of today. It adds a layer of security, one that human vigilance cannot, and ensures you have a smooth, safe, and uninterrupted online experience.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Threat Report: H2 2023 full of significant security incidents, AI-themed attacks, and Android spyware cases

  • ESET has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry from June 2023 through November 2023.
  • Cl0p, a notorious cybercriminal group known for carrying out ransomware attacks on a major scale, launched the extensive “MOVEit hack,” which surprisingly did not involve ransomware deployment.
  • ESET Research has identified specific campaigns targeting users of AI tools such as ChatGPT and the OpenAI API.
  • SpinOk spyware increased the overall count of Android spyware cases.
  • Android/Pandora malware compromised smart TVs, TV boxes, and mobile devices to utilize them for DDoS attacks.

BRATISLAVA — December 19, 2023 — ESET has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry and from the perspective of ESET threat detection and research experts, from June 2023 through November 2023. The second half of 2023 witnessed significant cybersecurity incidents. Cl0p, a notorious cybercriminal group known for carrying out ransomware attacks on a major scale, garnered attention via its extensive “MOVEit hack,” which surprisingly did not involve ransomware deployment. In the IoT landscape ESET researchers have identified a kill switch that had been used to successfully render the Mozi IoT botnet nonfunctional. Amidst the prevalent discussion regarding AI-enabled attacks, ESET has identified specific campaigns targeting users of tools such as ChatGPT and the OpenAI API. With spyware, there has been a significant increase in Android spyware cases, mainly attributed to the presence of the SpinOk threat.

“The Cl0p attack targeted numerous organizations, including global corporations and US governmental agencies. A key shift in Cl0p’s strategy was its move to leak stolen information to public websites in cases where the ransom was not paid, a trend also seen with the ALPHV ransomware gang,” explains ESET Director of Threat Detection Jiří Kropáč.

A new threat against IoT devices, Android/Pandora, compromised Android devices — including smart TVs, TV boxes, and mobile devices — and used them for DDoS attacks. ESET Research also noticed a considerable number of attempts to access malicious domains with names resembling “ChatGPT,” seemingly in reference to the ChatGPT chatbot. Threats encountered via these domains include web apps that insecurely handle OpenAI API keys, emphasizing the importance of protecting the privacy of users’ OpenAI API keys.

Among Android threats, SpinOK spyware is distributed as a software development kit and is found within various legitimate Android applications. On a different front, the second most recorded threat in H2 2023 is malicious JavaScript code detected as JS/Agent, which continues to be injected into compromised websites.

On the other hand, the increasing value of bitcoin has not been accompanied by a corresponding increase in cryptocurrency threats, diverging from past trends. However, cryptostealers have seen a notable increase, caused by the rise of the malware-as-a-service infostealer Lumma Stealer, which targets cryptocurrency wallets.

For more information, check out the ESET Threat Report H2 2023 on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Don´t let cybercriminals steal your Christmas joy

Roman Cuprik

A new smartphone may sound like the perfect Christmas present until there is malware hidden in the device or the person´s identity gets stolen.

Smartphones have become an inseparable part of our lives, allowing us to communicate, make transactions, play games, or read news on the go. These devices became so prevalent that average screen time for users around the world reached 3 hours and 46 minutes in 2023, according to the Independent. Given this number, it is no surprise that 22% of people in the US have asked for a mobile phone as a Christmas present in 2022, according to Statista’s Global Consumer Survey.

 

The joy of finding a new smartphone under the tree is undeniable. However, there are a few things you should keep in mind before you start using it.

  1. Update software – keeping your software up to date is a crucial step in security as new updates fix bugs and vulnerabilities.
  2. Review app permissions – check and manage app permissions to restrict access to sensitive information and only grant necessary permission for each app.
  3. Review and customize privacy settings – go through the settings and customize them according to your preferences (or even better, security experts’ recommendations).
  4. Use a reliable security solution – using a reputable security software is key to making sure your device stays healthy longer, so you can continue enjoying your gift for as long as possible.

There are other Christmas temptations than just sweets

With its holidays and festivities, the end of the year is often a period when cybercriminal activity surges. The most common threats around the holidays include online shopping scams, delivery phishing scams or even gift card scams and identity theft and much much more.

Sometimes scammers even create fake online stores offering Christmas sell-offs with the intent to steal your money and data. Most likely, they want to trick you into downloading malware or get hold of your personal data.

For example, in late 2022, the holidays celebrated in December led to increased phishing activity impersonating unspecified online shops. Moreover, when mobile game developers rolled out new releases before Christmas, attackers exploited the hype by uploading their modified malicious versions to third-party app stores, according to ESET Threat Report T3 2022.

In turn, ESET researchers observed a significant increase in Android adware detections by 57% in the last few months of 2022, having been driven by a staggering 163% increase in adware and a growth of 83% in HiddenApps detections.

These are just the campaigns that ESET researchers detected at the end of 2022. Your brand-new smartphone can also fall victim to a ransomware attack, it´s vulnerabilities can be exploited and don’t forget the “old-fashioned” physical theft. 

How to bring the Christmas joy back?

To protect your smartphone, stay vigilant when browsing the web or the app store and install a high-quality cybersecurity solution that protects against most of these threats. 

ESET Mobile Security (EMS) Premium for Android deals with all of the situations we outlined earlier. Besides Antivirus Scan and Adware Detector, which are part of the free version, ESET Mobile Security Premium also includes features that turn this solution into a complex, multilayered protection capable of deflecting a wide scope of attacks.

The long list of features includes Payment Protection, Anti-Phishing, Call Filter, Anti-Theft and much more. On top of that, the latest version, EMS 9, brings a new, redesigned, and simplified installation wizard.

All these juicy features now come with a generous price drop, making it a gift that keeps giving. From December 23rd to January 6th , the premium version of ESET Mobile Security will be 50% off. There is no need for a promotional code; the discount will automatically be added to your checkout! It couldn’t be easier.

Boost your smartphones security for a more connected and hassle-free holiday. Stay safe, not just during Christmas, but all year round. The gift of a smartphone is one that can keep on giving or taking. May your holiday season be filled with joy and your digital experiences be not only festive, but also secure.

Wishing you a merry Christmas and a digitally protected New Year! 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.