The Coronavirus has prompted thousands of information security professionals to volunteer their skills in upstart collaborative efforts aimed at frustrating cybercriminals who are seeking to exploit the crisis for financial gain. Whether its helping hospitals avoid becoming the next ransomware victim or kneecapping new COVID-19-themed scam websites, these nascent partnerships may well end up saving lives. But can thisunprecedented level of collaboration survive the pandemic?
At least three major industry groups are working to counter the latest cyber threats and scams. Among the largest in terms of contributors is the COVID-19 Cyber Threat Coalition (CTC), which comprises rough 3,000 security professionals who are collecting, vetting and sharing new intelligence about new cyber threats.
Nick Espinosa, a self-described security fanatic, author and public speaker whos handling communications for the CTC, said the group does most of its work remotely via a dedicated Slack channel, where many infosec professionals seem eager to counter the gusto with which the cybercriminal community has sought to profit by exacerbating an already difficult situation.
A nurse or doctor cant do what we do, and we cant do what they do, Espinosa said. Weve seen a massive rise in threats and attacks against healthcare systems, but its worse if someone dies due to a malicious cyberattack when we have the ability to prevent that. A lot of people are involved because theyre emotionally attached to the idea of helping this critical infrastructure stay safe and online.
Using threat intelligence feeds donated by dozens of cybersecurity companies, the CTC is poring over more than 100 million pieces of data about potential threats each day, running those indicators through security products from roughly 70 different vendors. If at least 10 of those flag a specific data point such as a domain name as malicious or bad, it gets added to the CTCs blocklist, which is designed to be used by organizations worldwide for blocking malicious traffic.
For possible threats, meaning between five and nine vendors detect an indicator as bad, our volunteers manually verify that the indicator is malicious before including it in our blocklist, Espinosa said.
Another Slack-based upstart coalition called the COVID-19 CTI Leaguespans more than 40 countries and includes professionals in senior positions at such major companies as Microsoft Corp and Amazon.com Inc.
Mark Rogers, one of several people helping to manage the CTI Leagues efforts, told Reuters the top priority of the group is working to combat hacks against medical facilities and other frontline responders to the pandemic, as well as helping defendcommunication networks and services that have become essential as more people work from home.
The group is also using its web of contacts in internet infrastructure providers to squash garden-variety phishing attacks and another financial crime that is using the fear of COVID-19 or the desire for information on it to trick regular internet users, wrote Reuters Joe Menn.
Ive never seen this volume of phishing, Rogers told Reuters. I am literally seeing phishing messages in every language known to man.
Among the more mature organizations working to counter the threat from COVID-19 scammers is the Cyber Threat Alliance, a industry group founded in 2017 that counts among its members more than two dozen major cybersecurity firms that are all required to regularly share threat intelligence with other members.
One thing were paying attention to in addition to phishing and malware attacks is anything targeting stuff involved in the pandemic response, such as the manufacturers of protective gear, testing kits, or hospitals, CTA President Michael Daniel told KrebsOnSecurity. One of those organizations getting hit with ransomware now would be really bad, and we want to make sure if we see that were alerting and working with law enforcement.
Earlier this month, the international police network INTERPOL issued a warning to law enforcement in nearly 200 member countries, saying it had detected a significant increase in the number of attempted ransomware attacks against key organizations and infrastructure engaged in the virus response.
The alert came after several top ransomware gangs pledged a moratorium on attacking hospitals and other care centers for the near future. Nevertheless, these group have continued to target companies on the periphery of the pandemic response, including virus testing labs, N95 mask production facilities, and companies engaged in vaccine research.
The CTCs Espinoza said it would be a potentially fatal mistake to assume all cybercriminal groups might observe such a cease-fire.
We might have independent criminal groups saying they wont hit hospitals but theyll hit everyone else, but that doesnt prevent them from sending phishing emails and masquerading as the World Health Organization or the Centers for Disease Control, he said. These are people who have no problems locking out little old ladies out of their computers for 800 bucks, and of course there are state-sponsored hackers who love any opportunity to sow discord and disrupt things.
The CTAs Daniel said while its great to see so much voluntary collaboration between the cybersecurity industry, governments and law enforcement, hes been thinking a lot lately about how to sustain these relationships and networks once the urgency of the pandemic subsides.
Formerly special assistant to President Obama and cybersecurity coordinator on the National Security Council, Daniel said he sees preserving and enhancing this information sharing effort post-COVID as one of the biggest policy issues facing the federal government over the next few years.
Information sharing is easy to talk about, and hard to do in practice, Daniel said. I dont use the term public-private partnership because its been bandied about so much over the years that I dont know what it means anymore. Its probably best described as working together on an operation.'
What prevents private companies from working more closely and frequently with governments on operations to target cybercrime organizations and networks? Daniel said on the government side, there are real concerns that working with one or two particularly clueful or effective companies (versus all of them) might give the impression that the government is showing favoritism, or picking winners and losers in the market.
But you have to do that to some extent because the truth is some companies matter in this space, and a lot dont, Daniel said. The government has to accept that, determine what are the objective rules, and establish transparency so that [their efforts] arent seen as some secret club but as part of a normal process.
Daniel said governments in general also need to get more comfortable sharing information about operations targeting specific crime groups in advance of those actions.
The government has to figure out how to let the private sector in on some of the planning and preparation, he said. If you want [the cybersecurity industrys] help against certain targets, you have to tell us who they are ahead of time. But this goes against how governments operate in almost every way.
On the private sector side are issues of how for-profit companies can closely collaborate with the government without being perceived as potentially compromising the privacy and security of their customers, or as simply an agent of the government.
For companies, the question is how do you deal with the liability and other questions that come with that, Daniel said. These are very real impediments, and why I think we need to get past the endless discussions of public-private partnerships and start talking about what we can do to coordinate actions against these groups so we can have a more strategic impact on the adversary.
Tags: COVID-19 Cyber Threat Coalition, Cyber Threat Alliance, Joe Menn, Mark Rogers, Michael Daniel, Nick Espinosa
This entry was posted on Wednesday, April 15th, 2020 at 11:28 amand is filed under The Coming Storm.You can follow any comments to this entry through the RSS 2.0 feed.You can skip to the end and leave a comment. Pinging is currently not allowed.
Excerpt from:
- Coronavirus Scam Alert: Watch Out For These Risky COVID-19 Websites And Emails - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19: Broome County Executive expected to sign executive orders on virus - WBNG-TV [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Houston-based company ready to test COVID-19 'vaccine candidate,' but doesn't have the funds - KHOU.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19 Mesa County Public Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus Disease 2019 (COVID-19) | SCDHEC [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus disease 2019 - Wikipedia [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hackers are jumping on the COVID-19 pandemic to spread malware - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 can last a few days on surfaces, according to new experiment findings - ABC News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Guardian view on the UKs Covid-19 response: confused and hesitant - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The COVID-19 Coronavirus Pandemic Highlights The Importance Of Scientific Expertise - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO Expert: Aggressive Action Against Coronavirus Cuts Down On Spread : Goats and Soda - NPR [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- 2 new cases of COVID-19 at Chicago schools - WGN TV Chicago [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Will Gargling with Salt Water or Vinegar 'Eliminate' the COVID-19 Coronavirus? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Worried about dying from COVID-19? You might be a millennial | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Startups developing tech to combat COVID-19 urged to apply for fast-track EU funding - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Why do dozens of diseases wax and wane with the seasonsand will COVID-19? - Science Magazine [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO, UN Foundation and partners launch first-of-its-kind COVID-19 Solidarity Response Fund - World Health Organization [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: PM to address nation tonight - New Straits Times [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Where every sport lies after mass disruption - RTE.ie [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Facts, myths and hypotheses | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hong Kong Has Largely Survived COVID-19. Can New York and The US Do It Too? - BuzzFeed News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- UPDATE: Case of COVID-19 confirmed in Wilson County - WITN [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Is This Train Car Carrying 'COVID-19'? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus pandemic: facts, updates and what to do about COVID-19 - The Verge [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- DHS: 34 people test positive for COVID-19 in Wisconsin - WBAY [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 by the numbers; plus key resources to help you stay informed - Berkeleyside [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 puzzles that scientists are still trying to answer - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- What's the COVID-19 end game? - The San Diego Union-Tribune [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 coronavirus is not the flu. Its worse. - Vox.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Phones Could Track the Spread of Covid-19. Is It a Good Idea? - WIRED [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- NIH Reports First Known Employee with COVID-19 Infection - National Institutes of Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Newborn tests positive for COVID-19 in London - Livescience.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: Malaysia's pandemic action plan activated for the coronavirus - The Star Online [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- How Bad Will The COVID-19 Coronavirus Epidemic Get In The U.S.? Health Experts Weigh In - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Can People Who Recover from COVID-19 Become Reinfected? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- THE LATEST: 41 test positive for COVID-19 in the state - WFSB [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Twelve new cases of COVID-19 announced in Illinois; bringing total to 105 - KWQC-TV6 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Eagle County outlines shift for COVID-19 testing, Vail Health shifts operations - Vail Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 7th positive COVID-19 case announced in Hawaii, all cases related to travel - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Canada tightens borders over coronavirus will it curb COVID-19s spread? - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- As health care workers prepare for COVID-19, medical students pitch in on the homefront - Minnesota Public Radio News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus First positive case of COVID-19 confirmed in Geauga County Kaylyn Hlavaty 7:58 AM - News 5 Cleveland [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 2nd presumptive case of COVID 19 reported in Bell County - KWTX [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- New confirmed cases of COVID-19 in Wisconsin - WKOW [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hawaii National Guard ready to step in against spread of COVID-19 - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Alberta orders all classes cancelled, daycares closed as COVID-19 cases rise to 56 in the province - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Has Italy Stopped Treating the Elderly in the COVID-19 Pandemic? - Snopes.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus testing: Information on COVID-19 tests according to state health departments - NBCNews.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Working from home because of COVID-19? Here are 10 ways to spend your time - Science Magazine [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Two positive COVID-19 cases announced in Fairbanks, bringing Alaska's confirmed total to 3 - Anchorage Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 8 more positive cases of COVID-19 brings Michigan total to 33 - FOX 2 Detroit [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Who Is Infectious? - Forbes [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- The Guardian view on the latest Covid-19 steps: a recipe for isolation - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Government publishes updated COVID-19 industry guidance - GOV.UK [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- NIH clinical trial of investigational vaccine for COVID-19 begins - National Institutes of Health [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Expanding Colorado's COVID-19 Testing Capacity Proves Frustrating to Polis, Doctors And The Public - Colorado Public Radio [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Microsoft Bing launches interactive COVID-19 map to provide pandemic news - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips: How to slow the spread of COVID-19 with hand-washing, social distance - USA TODAY [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- See Which Countries are Flattening their COVID-19 Curve - Visual Capitalist [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- With launch of COVID-19 data hub, the White House issues a call to action for AI researchers - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19 - Cabinet for Health and Family Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus Disease 2019 (COVID-19) | AustinTexas.gov [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- First COVID-19 case in Waterbury is confirmed - Waterbury Republican American [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 reveals the alarming truth that many children cant wash their hands at school - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Statement on COVID-19 Panel Discussion Notes That Were Attributed to UCSF - UCSF News Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 coronavirus testing in the US has been absurdly sluggish. That puts us at risk. - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Regal is closing all theaters until further notice over COVID-19 fears - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Amazon limiting shipments to certain types of products due to COVID-19 pandemic - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coralville company to produce millions of kits to test for COVID-19 - KCRG [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Number of COVID-19 cases in Erie County rises to 11, new case confirmed in Wyoming County - WIVB.com - News 4 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips and symptoms: What everyone should know about getting the new coronavirus - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Tech giants are getting creative to manage the COVID-19 crisis - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Mental health in the age of coronavirus - UN News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- White House provides an update on COVID-19 testing in the U.S., says theres been a dramatic ramp - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19: How long does the coronavirus last on surfaces? - BBC News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hospital in Boston will be converted into Covid-19 treatment center - STAT [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- 78 cases of COVID-19 confirmed in Tennessee - NewsChannel5.com [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- COVID 19: Tennessee confirmed cases reaches 52, Dept of Health releases age ranges of those infected - Clarksville Now [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Housing associations under pressure to offer Covid-19 rent holidays - The Guardian [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Sacramento woman dead from COVID-19 attended church with others who have virus - KCRA Sacramento [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]