The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign

RSA Conference 2024 · Track Session

Overview

In an insightful presentation at RSAC 2024, Eward Driehuis and Jacqueline Nijzink delivered a compelling argument that fraud, particularly mobile-based fraud, serves as a crucial canary in the coalmine for broader, more sophisticated cybersecurity threats. Their talk, "The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign," highlighted the escalating impact of financial fraud on victims, often leading to severe psychological distress, including depression and suicidal thoughts, as evidenced by research in the Netherlands showing 70% of victims experience such outcomes. This human cost underscores the urgent need for a more robust and integrated approach to fraud prevention.

Watch on YouTube

Visual summary for The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign
Visual summary for The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign

Key moments

  1. 0:00 Introduction to talk and speakers
  2. 0:40 Modern fraud examples: pig butchering and Anatsa malware
  3. 2:00 Profound human impact of fraud on victims
  4. 2:50 Mobile channels: the new frontier for cyber threats
  5. 3:40 Exponential growth and evolving capabilities of mobile malware
  6. 4:30 Overview of the evolving mobile malware ecosystem
  7. 5:20 Deep dive into the prolific Anatsa mobile malware

The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign

Speakers: Eward Driehuis, Vice President of Fraud Engineering, ThreatFabric; Jacqueline Nijzink, Agent of Change (formerly Global Head of Fraud Prevention and Detection, ABN AMRO)

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=5XnRxpgFcKg

Overview

In an insightful presentation at RSAC 2024, Eward Driehuis and Jacqueline Nijzink delivered a compelling argument that fraud, particularly mobile-based fraud, serves as a crucial canary in the coalmine for broader, more sophisticated cybersecurity threats. Their talk, "The Canary in the Coalmine of Cybersecurity: Fraud as a Warning Sign," highlighted the escalating impact of financial fraud on victims, often leading to severe psychological distress, including depression and suicidal thoughts, as evidenced by research in the Netherlands showing 70% of victims experience such outcomes. This human cost underscores the urgent need for a more robust and integrated approach to fraud prevention.

The core message of the session was that the innovations observed in the realm of financial fraud, especially through mobile malware, often foreshadow the emergence of advanced persistent threats (APTs), ransomware campaigns, and even nation-state-sponsored cyber warfare and industrial sabotage. Just as banking fraud on web channels preceded the rise of threats like CryptoLocker and NotPetya, the current surge in mobile fraud indicates a dangerous evolution in the threat landscape. Driehuis and Nijzink, drawing on their extensive experience from ThreatFabric and ABN AMRO, urged the cybersecurity community to recognize and act upon these early warnings, emphasizing that fraud is not merely a financial nuisance but a critical indicator of future, more devastating attacks.

This article delves into the specifics of their findings, exploring the technical intricacies of modern mobile malware, the evolving tactics of fraudsters, and the strategic implications for defenders. It underscores the necessity for a unified "cyber fraud fusion" approach, improved threat intelligence sharing, and a standardized vocabulary to combat these interconnected threats effectively.

Background

▶ Watch: Introduction to talk and speakers (0:00)

The landscape of cybercrime has historically mirrored the evolution of user engagement with digital platforms. Two decades ago, as banks transitioned to web-based digital channels, criminals followed suit, developing desktop malware primarily for fraud. This established a pattern: where users go, criminals follow, adapting their methods to exploit new technologies and platforms. Today, the pervasive adoption of mobile devices for banking and daily activities has created a new frontier for cybercriminals, leading to an exponential growth in mobile-centric threats.

The problem extends beyond mere financial loss. The speakers highlighted the devastating personal impact of fraud, citing independent research in the Netherlands revealing that 70% of fraud victims experience depression or suicidal thoughts. This profound human cost emphasizes that fraud is not just an economic issue but a critical public health and safety concern. The traditional distinction between "scams" (often social engineering-driven) and "malware" (technology-driven) is increasingly blurring, with modern attacks often leveraging both. For instance, while pig butchering scams rely heavily on social engineering and romance fraud tactics, victims like Liz Nolan have lost significant savings, such as 20,000 pounds, due to sophisticated mobile malware like Anatsa. This convergence necessitates a holistic understanding of the attack kill chain, integrating insights from both social engineering and technical perspectives. The global nature of this problem is evident, with the US rapidly climbing to become the second most targeted country for mobile malware, underscoring its widespread reach and impact.

Key Findings

▶ Watch: Profound human impact of fraud on victims (2:00)

The speakers presented several critical findings that illustrate the escalating threat of mobile fraud and its broader implications:

  1. Exponential Growth and Evolving Capabilities of Mobile Malware: There has been an exponential growth in unique, identifiable mobile malware families. More significantly, the capabilities of these families are rapidly advancing. A few years ago, device takeover was rare; now, it's a feature in almost a third or even over a third of mobile malware. This indicates a shift towards more intrusive and impactful attacks.
  1. A Driving Ecosystem of Cybercrime: The proliferation of malware is supported by a sophisticated ecosystem, including specialized hosting services and a focus on profit. While many malware families exist, consolidation is occurring, with a few major players dominating. Notable examples include Hydra (active since 2018 and evolved into a powerful device takeover Trojan), Cerberus, and Anatsa. Anatsa, though "less noisy" in terms of observable samples, is described as one of the most prolific and professional groups, suggesting a higher level of operational security and targeting precision. These groups target a vast number of countries and numerous financial institutions, using configuration files embedded in the malware to identify their targets.
  1. Primary Objectives: Data Theft and Device Takeover: Mobile malware primarily focuses on two objectives:
  • Stealing data: Often achieved through spyware capabilities.
  • Enforcing device takeover: This is the most crucial objective, typically accomplished using remote access tooling and keylogging.
  1. Common Infection Vectors: Criminals employ cunning methods to distribute mobile malware:
  • Benign Apps with Delayed Malicious Updates: The most common vector involves creating seemingly benign apps (e.g., file managers, PDF readers, phone cleaners) that perform as advertised and are initially placed in official app stores. After gaining a significant install base (sometimes 100,000-200,000 users), a subsequent update transforms the app into a malicious backdoor to a criminal Command and Control (C2) server.
  • Leveraging Updates for Popular Apps: Another popular method involves tricking users into downloading fake updates for widely used applications like Chrome. While Android is the primary platform, iOS is also targeted, with new vectors emerging.

Technical Deep Dive

▶ Watch: Mobile channels: the new frontier for cyber threats (2:50)

The technical sophistication of modern mobile malware is a significant concern, with attackers developing novel methods to bypass security measures and exploit platform vulnerabilities.

  1. Android 13+ Security Bypass: Attackers have developed a security bypass for Android 13 and above. This bypass allows them to open a side channel through which malicious updates or modules can be downloaded and loaded onto the device. This technique is particularly insidious as it enables attackers to initially deploy a benign application to app stores, only to later inject malicious functionality, making early detection extremely difficult.
  1. Multi-Factor Authentication (MFA) and Biometric Bypass: Despite the widespread adoption of MFA and biometrics, attackers have found effective bypass mechanisms. Their primary method involves exploiting accessibility permissions on Android devices. These permissions, designed to assist users with disabilities by allowing apps to read screen content and perform clicks, are weaponized. When a user reaches a biometric authentication screen, the malware leverages accessibility permissions to force a bypass to the fallback mechanism (e.g., PIN code). The user is prompted to enter their PIN, which the malware then steals using the same accessibility permissions, effectively bypassing the biometric security. This highlights a critical vulnerability in how fallback mechanisms are handled and protected.
  1. Evolving iOS Threats: While historically more secure, iOS is not immune. Attackers are misusing webclips to create fake applications that mimic legitimate banking apps and other financial services. More significantly, upcoming regulations, particularly in the European Union, are pressuring Apple to open its ecosystem to third-party app stores. The speakers warned that while little activity is currently observed, this regulatory change is expected to introduce a wave of new attack vectors on iOS devices, potentially leading to a significant increase in malicious app distribution outside the controlled App Store environment.
  1. APT-like Activity: LightSpy 2: A particularly worrisome development is the emergence of APT-like organizations leveraging mobile malware. The speakers discussed LightSpy 2, a sophisticated threat deployed as a fake Telegram app. Initially, it functions as advertised, but its modular design allows for the loading of additional malicious modules. One such module is designed to mimic WeChat, the "Chinese everything app" (encompassing dating, banking, Uber, etc.). This module can download all of a user's payment data directly from the WeChat backend, suggesting a focus on building comprehensive user profiles. Furthermore, LightSpy 2 possesses the capability to open the microphone and listen in on conversations, transforming infected devices into surveillance tools. While ThreatFabric could not independently verify the initial attribution of LightSpy to APT41 by other companies, they confirmed that the group behind LightSpy 2 is "definitely better funded and better structured" due to the advanced nature of their creations. The deployment mechanism for such sophisticated tools is unclear, as samples are not found in app stores, but potential methods like DNS poisoning were hinted at, suggesting capabilities often associated with state-sponsored actors who have "full control of all the firewalls in a given country." This indicates a dangerous convergence of financial crime innovation with nation-state capabilities.

Demo / Proof of Concept

▶ Watch: Overview of the evolving mobile malware ecosystem (4:30)

The speakers did not perform a live demonstration or proof of concept during the talk. Instead, they meticulously described and illustrated the technical mechanisms and attack flows used by various mobile malware families and social engineering scams. Their presentation used detailed examples, such as the Anatsa malware attack on Miss Liz Nolan and the functionality of LightSpy 2, to convey the operational specifics of these threats. While no real-time hack was shown, the technical deep dive provided a clear understanding of how these attacks are executed, serving as an illustrative "proof of concept" through narrative and explanation.

Defensive Implications

▶ Watch: Deep dive into the prolific Anatsa mobile malware (5:20)

The insights shared by Driehuis and Nijzink carry profound implications for cybersecurity defenders, urging a paradigm shift in how fraud is perceived and combated. The central message, that fraud is a canary in the coalmine, means that organizations must recognize mobile fraud as an early warning signal for more severe, impending cyber threats. Historically, innovations in banking fraud have branched out to ransomware (e.g., CryptoLocker), geopolitical sabotage (e.g., NotPetya), and industrial espionage. The current surge in mobile fraud, particularly with APT-like groups leveraging tools like LightSpy 2, suggests a similar trajectory towards more destructive and strategic attacks.

Defenders must adopt a proactive stance, starting with enhanced visibility into mobile threats. Organizations with consumer-facing mobile channels are advised to implement strategic and tactical monitoring to understand the evolving threat landscape. This visibility is paramount for any effective detection system.

The speakers introduced the concept of fraud practitioners needing to be "DJs," capable of blending high-tech and low-tech detection methods. While social engineering scams (detecting "bananas," as the analogy went) might seem low-tech, their detection often requires highly sophisticated, technology-driven approaches. Conversely, purely technical attacks require robust threat intelligence. This necessitates a cyber fraud fusion strategy, breaking down the traditional silos between cybersecurity and fraud prevention teams. Threat intelligence (TI) must be seamlessly integrated into anti-fraud detection chains, and insights from the fraud front lines regarding APT-like activities need to be communicated back to the broader cybersecurity teams.

Regulatory changes are also a critical factor. The potential for reimbursement laws on scams, as seen in other parts of the world and being discussed in the EU (potentially involving Telcos and Big Tech), could significantly shift liability towards financial institutions. Organizations must perform thorough risk assessments to understand the business and operational impact of such regulations. Furthermore, independent research indicates that customers now prioritize safety over convenience, even if it means increased friction in their banking journey. Banks that effectively detect and prevent fraud see a 40% increase in their Net Promoter Score (NPS), and even communicating about fraud awareness boosts NPS by 20%. This highlights that robust fraud prevention is not just a cost center but a significant driver of customer trust and brand reputation.

Finally, a crucial call to action is the development of a common vocabulary and a standardized fraud kill chain taxonomy, akin to MITRE ATT&CK for technical cyberattacks. The lack of a universal language for describing and categorizing fraud incidents hinders effective information sharing, which is vital for combating a global problem. Collaboration must extend beyond internal organizational boundaries to include governmental bodies, legal departments, public sectors, Telcos, and banks, fostering a networked approach to cybersecurity that is essential for collective defense.

Key Takeaways

  • Mobile Malware as a Leading Indicator: The innovations in mobile fraud and malware are critical early warning signs for broader, more sophisticated cyber threats, including APTs, ransomware, and state-sponsored espionage/sabotage.
  • Advanced Attack Sophistication: Mobile malware is rapidly evolving, with capabilities like Android 13+ security bypasses, MFA/biometric evasion via accessibility permissions, and the exploitation of iOS webclips, indicating a persistent and creative adversary.
  • The Rise of APT-like Activity: The emergence of highly funded and structured groups deploying advanced modular malware like LightSpy 2, capable of deep data exfiltration and surveillance, signifies a dangerous convergence of financial crime and nation-state-level capabilities.
  • Necessity for Cyber Fraud Fusion: Organizations must break down silos between cybersecurity and fraud teams, integrating threat intelligence and adopting a "DJ" approach that blends high-tech and low-tech detection strategies to effectively combat hybrid social engineering and malware attacks.
  • Critical Need for Visibility and Common Language: Enhanced visibility into mobile threats is non-negotiable for effective detection. Furthermore, developing a common vocabulary and a standardized fraud kill chain taxonomy is essential for improved threat intelligence sharing and cross-organizational collaboration.
  • Customer Trust and Regulatory Impact: Prioritizing customer safety over convenience in fraud prevention significantly boosts brand reputation and Net Promoter Scores. Organizations must also proactively assess the impact of evolving regulations, such as reimbursement laws, on their operations and liability.

About the Speaker(s)

Eward Driehuis is the Vice President of Fraud Engineering at ThreatFabric. With nearly 30 years of experience in cybersecurity and fraud strategies, Eward brings a wealth of knowledge and expertise to the table. His role at ThreatFabric involves leveraging advanced technology to combat financial fraud, making him a key figure in understanding the technical intricacies of mobile malware and its impact on the financial sector.

Jacqueline Nijzink is an "agent of change" with a distinguished career in fraud and operations, particularly within the financial industry. She previously served as the Global Head of Fraud Prevention and Detection at ABN AMRO, one of Europe's largest banks. Jacqueline has also played a significant role in the broader anti-fraud community, having run the International Program Committee for the EFG Fraud Group at RSA for over five years. Her background provides invaluable insight into the operational challenges and strategic imperatives of combating fraud from a banking perspective.

All talks from RSA Conference 2024