プレスリリース

2023年4月14日 11:42 AM

LockBitの主張に関する声明を更新しました

Mike Beck, Chief Information Security Officer, Darktrace

Darktraceの内部システムに侵入したとする昨日のLockBitによるツイートを受け、徹底的なセキュリティ調査を完了しました。当社のシステムおよび関連する組織のシステムに侵害がなかったことを確認することができました。当社のお客様へのサービスは中断されることなく、通常通り運営が継続されており、これ以上の措置は必要ありません。

プレスリリース

2023年4月13日 9:30 AM

LockBitの主張に関する声明

今朝早く、Darktraceはサイバー犯罪集団 LockBit が Darktrace の内部セキュリティシステムに侵入し、当社のデータにアクセスしたとするツイートを確認しました。当社のセキュリティチームは、当社の内部システムの完全なレビューを実行しましたが、侵害の証拠は一切見当たりませんでした。LockBitによるソーシャルメディアへの投稿はいずれも、当社のデータに一切関連するものではありません。当社は引き続き状況を注意深く注視していきますが、現在の調査に基づき、当社のシステムは引き続き安全であり、すべての顧客データは完全に保護されていると確信しています。


プレスリリース

Technology University Stops Information-Stealing Cyber-Attack with Darktrace AI

University Targeted by ‘PrivateLoader’, a Pay-Per-Install Malware Distribution Service
Cambridge, UK
May 5, 2022

Media coverage

News publication logo

Technology University Stops Information-Stealing Cyber-Attack with Darktrace AI

Read the story
May 5, 2022

Darktrace, a global leader in cyber security AI, today announced that an African technology university stopped a recent cyber-attack using Darktrace AI. The attackers attempted to distribute PrivateLoader malware, a pay-per-install malware service commonly associated with crypto-mining and IP theft.

The public university, which has been established for over 30 years in Africa, awards students with undergraduate and graduate degrees in technology-related subjects. The university holds vast amounts of valuable IP including government-funded research into artificial intelligence, robotics, and sustainable energy solutions, which is a prime target for financially motivated cyber-criminals as well as state-sponsored attackers.

The university was targeted during a trial of Darktrace’s AI in mid-April. The AI technology had formed a unique understanding of the university’s ‘normal’ operations across its digital estate which allowed it to spot the out-of-the-ordinary activity indicative of an attack. In this case, the AI detected a desktop connecting to a rare external endpoint using a mechanism that was not consistent with their technology stack.

The IP address was subsequently tracked by Darktrace’s AI Analyst and found to be related to the pay-per-install malware service, PrivateLoader. The compromised device was then observed performing activity indicative of ‘RedLineStealer’ and ‘MarsStealer’, information-stealing malware which exfiltrate data with the intent of monetizing it through direct use or distribution on darknet sites.

Darktrace AI detected the attack in its earliest stages, and the threat was interrupted before any critical research or student data could be exfiltrated. After the attack was contained, a thorough investigation into the incident was conducted to ensure future cyber resilience for the university.

“PrivateLoader is an emerging malware service which has grown in popularity over the past year. It is unsurprising that attackers would target a university with this attack tool, typically used to distribute information-stealing malware which can harvest the critical data that universities hold for financial or more political purposes,” commented Toby Lewis, Darktrace’s Global Head of Threat Analysis. “By taking a number of subtle indicators from across the organization into consideration, including time of day, duration, data in and out, and peer analysis of similar devices and users, Self-Learning AI is uniquely capable of spotting these threats in their earliest stages – before critical data falls into the wrong hands.”

About Darktrace

Darktrace (DARK.L), a global leader in cyber security AI, delivers world-class technology that protects over 6,800 customers worldwide from advanced threats, including ransomware and cloud and SaaS attacks. Darktrace’s fundamentally different approach applies Self-Learning AI to enable machines to understand the business in order to autonomously defend it. Headquartered in Cambridge, UK, the Group has more than 2,000 employees worldwide. Darktrace was named one of TIME magazine’s ‘Most Influential Companies’ for 2021.

この記事を共有
該当する項目はありません。
メディアコンタクト
該当する項目はありません。