How Darktrace AI Helped Protect the Qatar World Cup 2022 from Cyber Disruption
The 2022 Qatar World Cup introduced the world’s first ‘connected stadium’ concept whereby all eight stadiums were managed by a single unified technology. Discover why Darktrace was selected to help protect this global tournament from cyber-attacks.
Qatar World Cup 2022 was the fifth world cup (football and rugby) I have been closely involved in from the operation and cyber security standpoint. Over the last two decades, I have witnessed a dramatic shift in the cyber landscape.
A few years back, the main challenge was to mitigate technical issues due to failures or human error by increasing the resilience with high-availability and failover design. Today, with the increased complexity of the digital infrastructure underpinning global tournaments, and the sophistication and ferocity of the threat actors (ransomware gangs, hacktivists, APT groups) seeking to disrupt them, it is no surprise that cyber security has been pushed to the top of organizers’ agendas.
This football World Cup represented a challenge like no other. The tournament introduced the world’s first ‘connected stadium’ concept whereby all eight stadiums were managed by a single unified technology from the state-of-the-art Aspire Command Centre in Doha.
The centre – described as the most sophisticated setup ever seen at a sporting event – managed everything, from the lighting and access gates through to communications and IT. This unified integrated technology ecosystem offers the potential to drastically increase efficiency and gave the ability to seamlessly manage multiple matches at once. Each of the eight stadiums has a ‘digital twin’, allowing the cyber security experts to detect and mitigate issues as and when they arise.
The organizer realized the importance of protecting a digital infrastructure of this scale and complexity from attempted cyber-attacks. A football World Cup draws in a global audience – an estimated 3.75 billion were said to have tuned in for the previous final. It is difficult to overstate the financial and reputational impacts of disruption to any game – whether that be to the turnstiles within the stadium or the broadcast of the game – due to a cyber incident. Hacktivists and other cyber-criminals are acutely aware of the global stage a tournament like this provides and so these events become an obvious target for threats such as Distributed-Denial-of-Service (DDoS) and ransomware attacks.
Furthermore, the interconnectivity between IT and OT systems means that the line between cyber security and physical safety is significantly blurred. For example, having your access control and CCTV malfunctioning may lead to overcrowding within parts of stadium and leave fans vulnerable to crushes and physical injuries.
Initially, the World Cup organizer was looking to improve OT visibility. They quickly recognized that Darktrace’s technology could take them a step further than any other solutions on the market. Darktrace AI is uniquely able to monitor and protect their OT and their IT, detect unusual behaviors, and mitigate cyber-threats, and present its findings in a single pane of glass.
The host country recognized that a best-in-class event needed best-in-class technology. The nature of international events means that timing is critical and puts enormous pressure on the organizers and operators. ‘D-Day’ cannot be replayed or postponed, and so if cyber disruption occurs during the event, every minute is crucial. Darktrace was selected not only because of its unified IT and OT coverage, but because of its ability to detect, investigate, and respond at machine speed.
In the end, Darktrace played a crucial role in protecting the tournament across all eight stadiums throughout the World Cup. Supplementing the value of the AI, our team was on the ground, working alongside the cyber security team to assist with investigations. The teamwork and collaboration were second-to-none and the energy in the Command Centre was palpable when Darktrace was able to spot events of interest that would have otherwise gone under the radar.
On game day, every second counts, so pairing people with the right technology is critical. Explainable AI really came into its own during the World Cup, rapidly synthesizing information about disparate events, and generating alerts in seconds about emerging threats. That meant the team had the information they needed at their fingertips in an easily-understand format.
Our AI technology, created in 2013 in our Cambridge AI Research Centre, has disrupted the cyber security industry, and is making a big impact in the real world: from financial services and education through to critical national infrastructure like utilities, energy suppliers, and healthcare. The Qatar World Cup 2022 provided a unique and high-profile challenge. Darktrace didn’t just successfully protect the World Cup against cyber-attackers; it protected the more than 1.4 million people entering the stadiums from physical risk arising from OT attacks.
In all likelihood, you probably watched this year’s World Cup engrossed in the games, without giving much of a thought to cyber security. That’s the funny thing about success in the cyber security world: if all goes well, the average person wouldn’t even know it.
We are incredibly proud to have helped defend the Qatar World Cup 2022. I would like to congratulate the organizer and all security team members involved for delivering a World Cup free from cyber disruption, allowing fans both on site and the billions watching at home to simply enjoy the action on the pitch.
Learn more about how Darktrace helped protect the World Cup: Watch the video.
Sie mögen das und wollen mehr?
Erhalten Sie den neuesten Blog per E-Mail
Vielen Dank! Ihre Anfrage ist eingegangen!
Huch! Beim Absenden des Formulars ist etwas schief gelaufen.
Sie mögen das und wollen mehr?
Stay up to date on the latest industry news and insights.
Vielen Dank! Ihre Anfrage ist eingegangen!
Huch! Beim Absenden des Formulars ist etwas schief gelaufen.
Darktrace Cyber-Analysten sind erstklassige Experten für Threat Intelligence, Threat Hunting und Incident Response. Sie bieten Tausenden von Darktrace Kunden auf der ganzen Welt rund um die Uhr SOC-Support. Einblicke in das SOC-Team wird ausschließlich von diesen Experten verfasst und bietet Analysen von Cyber-Vorfällen und Bedrohungstrends, die auf praktischen Erfahrungen in diesem Bereich basieren.
ÜBER DEN AUTOR
VP, Cyber Intelligence
Karim Benslimane is Darktrace’s VP of Cyber Intelligence, working with clients in the public and private sector to analyse the most sophisticated cyber-threats today, and advising security professionals on the employment of artificial intelligence to strengthen their defensive strategy. Karim is a technical specialist in cyber and counter-terrorism exercises with over two decades of experience defending the sports and event industry from sophisticated threats. He has led major IT and cyber security projects for international arenas and events such as the Football World Cups, Rugby World Cups, World Athletics Championships and over 500 events.
Karim is also Lieutenant-Colonel (RC) at the Command of the Gendarmerie in Cyberspace, also known as ComCyberGend, in charge with steering, leading and coordinating the French Gendarmerie Nationale's efforts to combat cyberthreats in the areas of prevention, monitoring of digital spaces and judicial investigation of cybercriminal organisations.
Quasar Remote Access Tool: When a Legitimate Admin Tool Falls into the Wrong Hands
The threat of interoperability
As the “as-a-Service” market continues to grow, indicators of compromise (IoCs) and malicious infrastructure are often interchanged and shared between multiple malware strains and attackers. This presents organizations and their security teams with a new threat: interoperability.
Interoperable threats not only enable malicious actors to achieve their objectives more easily by leveraging existing infrastructure and tools to launch new attacks, but the lack of clear attribution often complicates identification for security teams and incident responders, making it challenging to mitigate and contain the threat.
One such threat observed across the Darktrace customer base in late 2023 was Quasar, a legitimate remote administration tool that has becoming increasingly popular for opportunistic attackers in recent years. Working in tandem, the anomaly-based detection of Darktrace DETECT™ and the autonomous response capabilities of Darktrace RESPOND™ ensured that affected customers were promptly made aware of any suspicious activity on the attacks were contained at the earliest possible stage.
What is Quasar?
Quasar is an open-source remote administration tool designed for legitimate use; however, it has evolved to become a popular tool used by threat actors due to its wide array of capabilities.
How does Quasar work?
For instance, Quasar can perform keylogging, take screenshots, establish a reverse proxy, and download and upload files on a target device . A report released towards the end of 2023 put Quasar back on threat researchers’ radars as it disclosed the new observation of dynamic-link library (DLL) sideloading being used by malicious versions of this tool to evade detection . DLL sideloading involves configuring legitimate Windows software to run a malicious file rather than the legitimate file it usually calls on as the software loads. The evolving techniques employed by threat actors using Quasar highlights defenders’ need for anomaly-based detections that do not rely on pre-existing knowledge of attacker techniques, and can identify and alert for unusual behavior, even if it is performed by a legitimate application.
Although Quasar has been used by advanced persistent threat (APT) groups for global espionage operations , Darktrace observed the common usage of default configurations for Quasar, which appeared to use shared malicious infrastructure, and occurred alongside other non-compliant activity such as BitTorrent use and cryptocurrency mining.
Between September and October 2023, Darktrace detected multiple cases of malicious Quasar activity across several customers, suggesting probable campaign activity.
Quasar infections can be difficult to detect using traditional network or host-based tools due to the use of stealthy techniques such as DLL side-loading and encrypted SSL connections for command-and control (C2) communication, that traditional security tools may not be able to identify. The wide array of capabilities Quasar possesses also suggests that attacks using this tool may not necessarily be modelled against a linear kill chain. Despite this, the anomaly-based detection of Darktrace DETECT allowed it to identify IoCs related to Quasar at multiple stages of the kill chain.
Quasar Initial Infection
During the initial infection stage of a Quasar compromise observed on the network of one customer, Darktrace detected a device downloading several suspicious DLL and executable (.exe) files from multiple rare external sources using the Xmlst user agent, including the executable ‘Eppzjtedzmk[.]exe’. Analyzing this file using open-source intelligence (OSINT) suggests this is a Quasar payload, potentially indicating this represented the initial infection through DLL sideloading .
Interestingly, the Xmlst user agent used to download the Quasar payload has also been associated with Raccoon Stealer, an information-stealing malware that also acts as a dropper for other malware strains . The co-occurrence of different malware components is increasingly common across the threat landscape as MaaS operating models increases in popularity, allowing attackers to employ cross-functional components from different strains.
Quasar Establishing C2 Communication
During this phase, devices on multiple customer networks were identified making unusual external connections to the IP 193.142.146[.]212, which was not commonly seen in their networks. Darktrace analyzed the meta-properties of these SSL connections without needing to decrypt the content, to alert the usage of an unusual port not typically associated with the SSL protocol, 4782, and the usage of self-signed certificates. Self-signed certificates do not provide any trust value and are commonly used in malware communications and ill-reputed web servers.
Further analysis into these alerts using OSINT indicated that 193.142.146[.]212 is a Quasar C2 server and 4782 is the default port used by Quasar . Expanding on the self-signed certificate within the Darktrace UI (see Figure 3) reveals a certificate subject and issuer of “CN=Quasar Server CA”, which is also the default self-signed certificate compiled by Quasar .
A number of insights can be drawn from analysis of the Quasar C2 endpoints detected by Darktrace across multiple affected networks, suggesting a level of interoperability in the tooling used by different threat actors. In one instance, Darktrace detected a device beaconing to the endpoint ‘bittorrents[.]duckdns[.]org’ using the aforementioned “CN=Quasar Server CA” certificate. DuckDNS is a dynamic DNS service that could be abused by attackers to redirect users from their intended endpoint to malicious infrastructure, and may be shared or reused in multiple different attacks.
The sharing of malicious infrastructure among threat actors is also evident as several OSINT sources have also associated the Quasar IP 193.142.146[.]212, detected in this campaign, with different threat types.
While 193.142.146[.]212:4782 is known to be associated with Quasar, 193.142.146[.]212:8808 and 193.142.146[.]212:6606 have been associated with AsyncRAT , and the same IP on port 8848 has been associated with RedLineStealer . Aside from the relative ease of using already developed tooling, threat actors may prefer to use open-source malware in order to avoid attribution, making the true identity of the threat actor unclear to incident responders .
Quasar Executing Objectives
On multiple customer deployments affected by Quasar, Darktrace detected devices using BitTorrent and performing cryptocurrency mining. While these non-compliant, and potentially malicious, activities are not necessarily specific IoCs for Quasar, they do suggest that affected devices may have had greater attack surfaces than others.
For instance, one affected device was observed initiating connections to 162.19.139[.]184, a known Minergate cryptomining endpoint, and ‘zayprostofyrim[.]zapto[.]org’, a dynamic DNS endpoint linked to the Quasar Botnet by multiple OSINT vendors .
Not only does cryptocurrency mining use a significant amount of processing power, potentially disrupting an organization’s business operations and racking up high energy bills, but the software used for this mining is often written to a poor standard, thus increasing the attack surfaces of devices using them. In this instance, Quasar may have been introduced as a secondary payload from a user or attacker-initiated download of cryptocurrency mining malware.
Similarly, it is not uncommon for malicious actors to attach malware to torrented files and there were a number of examples of Darktrace detect identifying non-compliant activity, like BitTorrent connections, overlapping with connections to external locations associated with Quasar. It is therefore important for organizations to establish and enforce technical and policy controls for acceptable use on corporate devices, particularly when remote working introduces new risks.
In some cases observed by Darktrace, devices affected by Quasar were also being used to perform data exfiltration. Analysis of a period of unusual external connections to the aforementioned Quasar C2 botnet server, ‘zayprostofyrim[.]zapto[.]org’, revealed a small data upload, which may have represented the exfiltration of some data to attacker infrastructure.
Darktrace’s Autonomous Response to Quasar Attacks
On customer networks that had Darktrace RESPOND™ enabled in autonomous response mode, the threat of Quasar was mitigated and contained as soon as it was identified by DETECT. If RESPOND is not configured to respond autonomously, these actions would instead be advisory, pending manual application by the customer’s security team.
For example, following the detection of devices downloading malicious DLL and executable files, Darktrace RESPOND advised the customer to block specific connections to the relevant IP addresses and ports. However, as the device was seen attempting to download further files from other locations, RESPOND also suggested enforced a ‘pattern of life’ on the device, meaning it was only permitted to make connections that were part its normal behavior. By imposing a pattern of life, Darktrace RESPOND ensures that a device cannot perform suspicious behavior, while not disrupting any legitimate business activity.
Had RESPOND been configured to act autonomously, these mitigative actions would have been applied without any input from the customer’s security team and the Quasar compromise would have been contained in the first instance.
In another case, one customer affected by Quasar did have enabled RESPOND to take autonomous action, whilst also integrating it with a firewall. Here, following the detection of a device connecting to a known Quasar IP address, RESPOND initially blocked it from making connections to the IP via the customer’s firewall. However, as the device continued to perform suspicious activity after this, RESPOND escalated its response by blocking all outgoing connections from the device, effectively preventing any C2 activity or downloads.
When faced with a threat like Quasar that utilizes the infrastructure and tools of both legitimate services and other malicious malware variants, it is essential for security teams to move beyond relying on existing knowledge of attack techniques when safeguarding their network. It is no longer enough for organizations to rely on past attacks to defend against the attacks of tomorrow.
Crucially, Darktrace’s unique approach to threat detection focusses on the anomaly, rather than relying on a static list of IoCs or "known bads” based on outdated threat intelligence. In the case of Quasar, alternative or future strains of the malware that utilize different IoCs and TTPs would still be identified by Darktrace as anomalous and immediately alerted.
By learning the ‘normal’ for devices on a customer’s network, Darktrace DETECT can recognize the subtle deviations in a device’s behavior that could indicate an ongoing compromise. Darktrace RESPOND is subsequently able to follow this up with swift and targeted actions to contain the attack and prevent it from escalating further.
Credit to Nicole Wong, Cyber Analyst, Vivek Rajan Cyber Analyst
Darktrace DETECT Model Breaches
Anomalous Connection / Multiple Failed Connections to Rare Endpoint
Anomalous Connection / Anomalous SSL without SNI to New External
Anomalous Connection / Application Protocol on Uncommon Port
Attack Trends: VIP Impersonation Across the Business Hierarchy
What is VIP impersonation?
VIP impersonation involves a threat actor impersonating a trusted, prominent figure at an organization in an attempt to solicit sensitive information from an employee.
VIP impersonation is a high-priority issue for security teams, but it can be difficult to assess the exact risks, and whether those are more critical than other types of compromise. Looking across a range of Darktrace/Email™ customer deployments, this blog explores the patterns of individuals targeted for impersonation and evaluates if these target priorities correspond with security teams' focus on protecting attack pathways to critical assets.
How do security teams stop VIP Impersonation?
Protecting VIP entities within an organization has long been a traditional focus for security teams. The assumption is that VIPs, due to their prominence, possess the greatest access to critical assets, making them prime targets for cyber threats.
Email remains the predominant vector for attacks, with over 90% of breaches originating from malicious emails. However, the dynamics of email-based attacks are shifting, as the widespread use of generative AI is lowering the barrier to entry by allowing adversaries to create hyper-realistic emails with minimal errors.
Given these developments, it's worth asking the question – which entities (VIP/non-VIP) are most targeted by threat actors via email? And, more importantly – which entities (VIP/non-VIP) are more valuable if they are successfully compromised?
There are two types of VIPs:
1. When referring to emails and phishing, VIPs are the users in an organization who are well known publicly.
2. When referring to attack paths, VIPs are users in an organization that are known publicly and have access to highly privileged assets.
Not every prominent user has access to critical assets, and not every user that has access to critical assets is prominent.
Darktrace analysis of VIP impersonation
We analyzed patterns of attack pathways and phishing attempts across 20 customer deployments from a large, randomized pool encompassing a diverse range of organizations.
Understanding Attack Pathways
Our observations revealed that 57% of low-difficulty attack paths originated from VIP entities, while 43% of observed low-difficulty attack paths towards critical assets or entities began through non-VIP users. This means that targeting VIPs is not the only way attackers can reach critical assets, and that non-VIP users must be considered as well.
While the sample size prevents us from establishing statistical significance across all customers, the randomized selection lends credence to the generalizability of these findings to other environments.
On average, 1.35% of total emails sent to these customers exhibited significantly malicious properties associated with phishing or some form of impersonation. Strikingly, nearly half of these malicious emails (49.6%) were directed towards VIPs, while the rest were sent to non-VIPs. This near-equal split is worth noting, as attack paths show that non-VIPs also serve as potential entry points for targeting critical assets.
For example, a recent phishing campaign targeted multiple customers across deployments, with five out of 13 emails specifically aimed at VIP users. Darktrace/Email actioned the malicious emails by double locking the links, holding the messages, and stripping the attachments.
Given that non-VIP users receive nearly half of the phishing or impersonation emails, it underscores the critical importance for security teams to recognize their blind spots in protecting critical assets. Overlooking the potential threat originating from non-VIP entities could lead to severe consequences. For instance, if a non-VIP user falls victim to a phishing attack or gets compromised, their credentials could be exploited to move laterally within the organization, potentially reaching critical assets.
This highlights the necessity for a sophisticated security tool that can identify targeted users, without the need for extensive customization and regardless of VIP status. By deploying a solution capable of promptly responding to email threats – including solicitation, phishing attempts, and impersonation – regardless of the status of the targeted user, security teams can significantly enhance their defense postures.
Darktrace vs Traditional Email Detection Methods
Traditional rules and signatures-based detection mechanisms fall short in identifying the evolving threats we’ve observed, due to their reliance on knowledge of past attacks to categorize emails.
Secure Email Gateway (SEG) or Integrated Cloud Email Security (ICES) tools categorize emails based on previous or known attacks, operating on a known-good or known-bad model. Even if tools use AI to automate this process, the approach is still fundamentally looking to the past and therefore vulnerable to unknown and zero-day threats.
Darktrace uses AI to understand each unique organization and how its email environment interoperates with each user and device on the network. Consequently, it is able to identify the subtle deviations from normal behavior that qualify as suspicious. This approach goes beyond simplistic categorizations, considering factors such as the sender’s history and recipient’s exposure score.
This nuanced analysis enables Darktrace to differentiate between genuine communications and malicious impersonation attempts. It automatically understands who is a VIP, without the need for manual input, and will action more strongly on incoming malicious emails based on a user’s status.
Email does determine who is a VIP, without a need of manual input, and will action more strongly on incoming malicious emails.
Darktrace/Email also feeds into Darktrace’s preventative security tools, giving the interconnected AI engines further context for assessing the high-value targets and pathways to vital internal systems and assets that start via the inbox.
Leveraging AI for Enhanced Protection Across the Enterprise
The efficacy of AI-driven security solutions lies in their ability to make informed decisions and recommendations based on real-time business data. By leveraging this data, AI driven solutions can identify exploitable attack pathways and an organizations most critical assets. Darktrace uniquely uses several forms of AI to equip security teams with the insights needed to make informed decisions about which pathways to secure, reducing human bias around the importance of protecting VIPs.
With the emergence of tools like AutoGPT, identifying potential targets for phishing attacks has become increasingly simplified. However, the real challenge lies in gaining a comprehensive understanding of all possible and low-difficulty attack paths leading to critical assets and identities within the organization.
At the same time, organizations need email tools that can leverage the understanding of users to prevent email threats from succeeding in the first instance. For every email and user, Darktrace/Email takes into consideration changes in behavior from the sender, recipient, content, and language, and many other factors.
Integrating Darktrace/Email with Darktrace’s attack path modeling capabilities enables comprehensive threat contextualization and facilitates a deeper understanding of attack pathways. This holistic approach ensures that all potential vulnerabilities, irrespective of the user's status, are addressed, strengthening the overall security posture.
Contrary to conventional wisdom, our analysis suggests that the distinction between VIPs and non-VIPs in terms of susceptibility to impersonation and low-difficulty attack paths is not as pronounced as presumed. Therefore, security teams must adopt a proactive stance in safeguarding all pathways, rather than solely focusing on VIPs.
Attack path modeling enhances Darktrace/Email's capabilities by providing crucial metrics on potential impact, damage, exposure, and weakness, enabling more targeted and effective threat mitigation strategies. For example, stronger email actions can be enforced for users who are known to have a high potential impact in case of compromise.
In an era where cyber threats continue to evolve in complexity, an adaptive and non-siloed approach to securing inboxes, high-priority individuals, and critical assets is indispensable.