https://therecord.media/cisa-red-team-large-critical-infrastructure-organization/ [matomo] [ ] [go] [The-Record] * Leadership * Cybercrime * Nation-state * Government * People * Technology * About * Contact * Click Here Podcast * [ ] [go] Subscribe to The Record [ ] [go] CISA red-teamed a 'large critical infrastructure organization' and didn't get caught Image: Department of Defense / Lisa Ferdinando / Flickr Joe Warminsky February 28, 2023 CISA red-teamed a 'large critical infrastructure organization' and didn't get caught Briefs Government Industry Technology * * * * * Joe Warminsky February 28, 2023 * Briefs * Government * Industry * Technology * * * * * CISA red-teamed a 'large critical infrastructure organization' and didn't get caught Hackers working for the federal government only had moderate success in attacking a "large critical infrastructure organization" last year, but were able to get in and get out without being detected, the Cybersecurity and Security Infrastructure Agency (CISA) said Tuesday. CISA had the organization's permission for the stealthy three-month "red team assessment" in 2022 to get a full view of the network's weaknesses. Certain personnel at the target organization had "some high-level details of the engagement," the agency said. "Despite having a mature cyber posture, the organization did not detect the red team's activity throughout the assessment, including when the team attempted to trigger a security response," CISA said in a report intended to advise critical infrastructure companies about security measures. It's the first time the agency has published an advisory on one of its red team assessments, a spokesperson told The Record. "Our recommendations provided to the assessed organizations are applicable to help other entities assess and improve their cybersecurity," the spokesperson said. "We encourage all organizations to read this latest advisory and implement the recommendations therein." The hackers had some early success, the agency said, but eventually came up against the organization's core security measures. "The team gained persistent access to the organization's network, moved laterally across the organization's multiple geographically separated sites, and eventually gained access to systems adjacent to the organization's sensitive business systems (SBSs)," CISA said. That's where they were stymied: In one case, multi-factor authentication (MFA) blocked attempts to infiltrate an SBS, CISA said. MFA usually involves a second form of identifying a user -- such as a physical key or a code-generating app -- beyond a username password. In trying to access another SBS, the team simply ran out of time, the agency said. The CISA Red Team has the legal authority, upon request, to "provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and provide operational and timely technical assistance to Federal and non-Federal entities with respect to cybersecurity risks," the agency said. The report details all of the team's tactics, techniques and procedures. The hackers began with spearphishing specific employees, ultimately compromising two workstations. They used that access to gather more information about the network. Afterward, the red team did more successful spearphishing -- this time of employees with administrative access. The tools included Cobalt Strike, commercially available software that is intended for penetration testing on networks but is also repurposed by malicious hackers. The CISA report does not identify the target organization's area of critical infrastructure. The agency lists 16 sectors under that umbrella, including manufacturing, energy, financial services, healthcare, transportation and water systems. Protecting those industries has been a centerpiece of the government's cybersecurity strategy in recent years, with President Joe Biden signing legislation in March 2022 requiring critical infrastructure organizations to report cyber incidents within 72 hours. * * * * * Tags * CISA * Critical Infrastructure * hacking * red team Joe Warminsky is the news editor for Recorded Future News. He has more than 25 years experience as an editor and writer in the Washington, D.C., area. Most recently he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call. Previous article Next article DISH tells SEC that ransomware attack caused outages; personal info may have been stolen LastPass says attacker hacked employee's home computer to access corporate vault Briefs * Chick-fil-A: 71,000 customers had financial information stolen during cyberattack March 3, 2023 * Online travel giant says it was not compromised through recently-discovered vulnerability March 3, 2023 * Poland blames Russian hackers for cyberattack on tax service website March 2, 2023 * Tennessee State, Southeastern Louisiana universities hit with cyberattacks March 2, 2023 * Secret Service, ICE carried out illegal stingray surveillance, government watchdog says March 2, 2023 * Canadian book giant says employee data was stolen during ransomware attack March 1, 2023 * Washington state public bus system confirms ransomware attack March 1, 2023 * Streaming service Plex unaware 'of any unpatched vulnerabilities' following LastPass report March 1, 2023 Ransomware tracker: the latest figures [January 2023] [2021_1209-Victim-Data-Released-on-Ransomware-Extortion-Sites-1-1024x607] Ransomware tracker: the latest figures [January 2023] 2022 Adversary Infrastructure Report [2022_adver] 2022 Adversary Infrastructure Report Season of Giving, Season of Taking: Heightened Fraud During Holiday Shopping [season_for] Season of Giving, Season of Taking: Heightened Fraud During Holiday Shopping H1 2022: Malware and Vulnerability Trends Report [h1_2022_ma] H1 2022: Malware and Vulnerability Trends Report Russian Information Operations Aim to Divide the Western Coalition on Ukraine [Russian_In] Insikt Group: Russian Information Operations Vulnerability Spotlight: Dirty Pipe [vulnerabil] Insikt Group: Dirty Pipe Glossary Threat Intelligence Threat Intelligence Feeds Threat Intelligence Platform Payment Fraud Intelligence [The-Record] * * * * * * Privacy Policy (c) Copyright 2023 | The Record from Recorded Future News