Zscaler Uses Integrated Platform to Combat Ransomware

Transcription

Welcome to Zcast everyone. I'm Zeus Kerravala from ZK Research and I'm here for another one of my thought leadership Zcasts. Today I'm joined by Deepen Desai, the CISO and VP of Security Research at Zscaler. Deepen, obviously given your title, we're going to be talking cyber. Before we get into this though, I do want to give a quick shout out to Eweek. Eweek is my media partner and all Zcasts are done in conjunction with the Eweek speaks program.

So Deepen, before we start, want to you just give us a little bio about yourself, what you do, what Zscaler does and you know, what your role there is. Hey, thank you. Thank you Zeus for having me here. So hey everyone, my name is Deepen Desai. I'm the CISO and head of security research here at Zscaler. My primary role is to make sure our platforms and services are secure and then I also have a group of world-class researchers, which is ThreatLabz, responsible for tracking threat landscape and ensuring protection for our customers against newer threats.

Yeah, so Zscaler offers world's largest security cloud that we call Zscaler Zero Trust Exchange. This is an integrated platform of services that protects users and workloads using identity and context to securely broker user devices. It could be workloads over any network from any location. With Zscaler's zero trust implementation, you secure the users, applications and data rather than the network. Yeah, I've actually been following Zscaler since really since it was founded and I think it's been pretty interesting to see the impact guys have had on the industry because I think what Zscaler's done for security, what I think, you know, AWS and companies like that did for general computing, and It's much more agile and much more scalable than it's ever been.

So, that that's been interesting to see. Now, um you did talk about uh the ThreatLabz team that you have. Uh can you describe the group? You know, what what's its main responsibility? Um you know, how's it structured? What it does? And then what are some of the trends that uh it's seeing right now? Yeah, so ThreatLabz team, for those of you that don't know, it's it's basically the security research arm of Zscaler, uh which includes over 100 security experts located in seven different countries across the globe.

And the main job uh is to track the evolving threat landscape. And as I mentioned, protect thousands of organizations around the world that goes through Zscaler Zero Trust Exchange. Now, the way we have it uh structured is we have practically aligned ThreatLabz team uh across four critical stages of the attack chain. And the goal here is to have the right expertise in place for breaking that attack at multiple levels. So, let me uh double-click on uh those four groups, right?

So, the first group that we have is focused on the initial delivery vector, uh where the attackers are trying to gain entry into your environment. So, this team proactively tracks phishing campaigns, drive-by attacks, um you know, uh any kind of compromise or malicious sites where that attack starts, right? And they use Zscaler cloud as well as other intel sources um uh for the purpose of making sure we're able to keep up with uh that uh delivery vector phase.

The second group uh is responsible for vulnerability exploit coverage. Now, we all agree that patching is important, uh but there is always a gap between a patch becoming available and getting applied to the systems. And that's uh usually the window of opportunity for the attackers. So, this group in Threat Labs reduces and that window by adding detections to give time to the organizations that are going through zero trust exchange to apply those patches.

Um to give you an example, we we are we're part of Microsoft Active Protection Program. There is a MAP Validate Tier, which is one of the highest tier. Uh and that allows Threat Labs team to gain access to Microsoft Adobe vulnerability detection guidance almost 5 weeks in advance of Patch Tuesdays. So, this program basically allows us to ensure vulnerability exploit coverage for Microsoft Adobe vulnerabilities on the day they release security updates and making sure that all our customers are protected.

Now, the third group is responsible for malware coverage. So, if you think of the attack chain, you know, they start with that initial delivery hook. They will use some sort of weaponized payload where a vulnerability exploit is being used to compromise that endpoint. Then, there is usually a malware involved where the again the goal is based on the objective of the adversary. They're trying to steal information or it could be a ransomware. So, this third group of Threat Labs is focused on that malware tracking stage and they're they're tracking both crime ware as well as more targeted malware families.

Uh we leverage AI ML models as well as you know, world-class automation to process large volume of malware payloads, extracting configurations from these payloads automatically and then adding coverage across the cloud. So, one of the stat that I'll share that So, when I when I talk to this group, it's just fascinating, right? The number of unique payloads that Zscaler sees in our cloud sandbox is half a million every day. These are net new payloads.

Uh if I'm sure most of you guys listening to this have heard about VirusTotal, right? That sees close to 2 million new unique payloads every day coming from all kinds of uh users that are subscribed to it. So, there's no way you could manually, you know, go about adding coverage. So, this team has developed lot of good automation using clustering technique, AI/ML model. I mentioned config extractors where we're able to pull the CNC configuration from these payloads automatically and then add the coverage to Zscaler uh zero trust exchange.

The final group is focused on the command and control stage, right? And the goal over here is to track the attacker controlled infrastructure, uh ensuring coverage for that command and control activity. Uh so, what happens when a machine gets infected, it will try to communicate with the attacker's uh server, which is a CNC server, using a predefined protocol, right? In which it will send command, uh receive response, update itself. So, again, this team has uh reversed many of those uh malware family CNC activity protocol, added coverage for it, and they've also developed a cool automation where we are able to emulate that activity um given giving us access to lot of real-time intelligence that again gets added to the product for blocking.

Now, uh the final point I'll make over here, which which really gives ThreatLabz an edge, is uh the team has access to the massive insights from Zscaler zero trust exchange. So, on uh on any given day, uh we're we're securing over 240 billion transactions. That results in 7 billion policy violations and security blocks. And that that represents like trillions of signals that the team is able to derive in order to study what's going on on the you know, newer campaigns, targeted attacks, and that intelligence is further used to kind of improve the efficacy of our platform.

Yeah, I know a lot of businesses used to try and do this type of research themselves, but as you mentioned before, just the volume of data has gotten so high that you really can't do it manually anymore. In fact, I think because of that, I've been a long time believer that, you know, tools like Sims and things have to be completely rebuilt cuz they just, you know, they they they can't keep up. Now, you you talked about some of the interesting trends, you know, from threat labs.

The other side of security, of course, is the monetization of the breaches, which leads to ransomware, right? So, ransomware is a huge topic in cyber today. What's threat labs telling you about ransomware? You know, what's why is it as successful as it's been? You know, what you know, why is it working and how can what can companies do? Yeah, so yes, I I I I'll I'll talk about the overall trends that we're seeing and then we'll jump into the ransomware.

Right? Over the past 2 years, we have we have seen a dramatic shift in the way the organizations operate due to pandemic. Early on, it was more remote workforce. Now, we are into a phase where there is this hybrid work environment. You know, the employees could be remote, could be in the office. The applications and workloads are mostly shifted to public and private cloud infrastructure. And you brought that up, too, because one of the interesting aspects of remote work is prior to the pandemic there's people like you and I that work remotely.

We're pretty sophisticated technically. You you kind of understood how to troubleshoot things. Now we're sending you know contact center agents, inside sales people, marketing people like have never worked remotely before and they don't have the same level of kind of security acumen as people that were professional road warriors. So I'm glad you brought that up because that's been a big change. So sorry to interrupt you though but I thought that was worth noting.

That that no you you you hit the point right on the nail, right? That is the reason what we started seeing since 2020 itself and that trend has continued. You know cybercriminals were keeping a close eye on this shift in the way organizations are operating, right? And and early on many of the organizations were left vulnerable because they were not able to support you know large remote workers. Whether it's because of the lack of infrastructure that was present.

Most of them were prepared to support 10 to 20% of the remote workforce, not not 100%. Right? Their VPNs couldn't scale. Then we are in this hybrid work environment where the employees may be in the home environment for some time and then in the office environment. How how can they reduce the risk? So what we saw in terms of security trends is there are three major buckets where many of these attacks were being planted by cybercriminals. The number one was as you mentioned targeting those remote employees.

Not all of them have the security acumen to spot some of those spear fishing emails or or you know drive by download links. So those remote employees are more susceptible and they're being hit by fairly targeted fishing attacks and drive by attacks. And the goal over here is just to gain that initial entry into the victim environment. The second group of attacks I mean this is part of the three bucket trend that I'm talking about is where as organizations started supporting these hybrid work environment or large remote workforce, they also had to move lot of their internal applications and workloads to public cloud infrastructure, right?

And that's where it's not as easy, right? There were lot of configuration mistakes and and threat actors were continuously looking out for that, right? So as simple as an open S3 bucket to exposed SMB services or any of the vulnerable services that were left out because of a misconfiguration, the threat actor would go after it, gain entry into the environment and steal information in many of the cases. And then the third category of attacks is where they're basically targeting your exposed assets.

And think of remote VPN servers and VPN concentrators that has to be exposed to the internet because you're trying to support your remote workforce. Exchange server, we saw log 4j vulnerability exploit, right? So any server that had that vulnerable library again was a massively being hit. We saw more than a dozen nation-state threat actors targeting these exposed assets like VPN server, right? So that's there was another big uh bucket where we saw the threat landscape evolve and again the goal over here is to gain access to the victim's environment.

Now this trend has been seen, like I mentioned, both for crime ware, which are more financially motivated adversary, as well as more targeted attacks where generally espionage or or or even hacktivism could be the goal, right? So, we saw both nation-state threat actors as well as crime ware actors launching attacks in these three buckets. Now, you asked about ransomware. All right, so yes, ransomware continues to be one of the more prevalent threat.

Um and despite a lot of law enforcement and government crackdown, we continue to see more and more ransomware attacks even now. Um and and the reason is, I mean, if you if you look at it, what has changed over the last 3 years even on the ransomware TTP side, like tools, tactics, procedures that the gangs are using. Um They've They've noticed, like if you think of 2017, there were WannaCry, NotPetya, Bad Rabbit, large global-scale ransomware attacks where they were targeting mass mass number of organizations, encrypting data, and demanding ransom.

Um The new thing that happened back then was they weaponized the payload to move laterally using exploits like EternalBlue. Next few years, all the organizations become became prudent in terms of backup hygiene. So, even if they get hit by some attack like that, they're able to recover from it and it's business as usual, filling in the obviously the security holes that was used to get in. 2019 onwards, we started seeing advent of double extortion attacks.

So, where they started they will get inside the environment, they will they will hit one of the endpoint, they will then move laterally within the environment. They will identify all high value assets that are sitting in their environment. Right? There's this internal recon stage where they will identify your code base server, server that may have financial details. They will even try to find out whether you have a cyber insurance policy. What is how much money do you have as part of your balance sheet.

Right? What what level of coverage do you have? And then that is what they will use to demand ransom from you as well. The high value assets that they've identified, they will steal data from all of those assets before encrypting your entire network. Right? So now even if you're able to recover from your backups, they will threaten to leak that stolen data, which is what why the term double extortion. Um and and and and that's where many of the organizations are forced to pay that.

So, the team actually has been tracking many of these ransomware gangs and we just published our annual report. The 2022 ransomware report by Threat Labs. And there were many of the I can quickly go over the key findings. Yeah, I can I did see that report. I thought it was a really good report. In fact, I'll include a link to the report in the description of the YouTube video here. So, but I was really surprised at some of the findings in there. So, if you could go through some of those, that would be great.

Yeah. So, ransomware attacks we have seen an increase by 80% year-over-year and one of the reasons for the increase was also increase in ransomware as a service model. Yeah. If you look at top ransomware families, eight out of top 11 ransomware families are leveraging ransomware as a service model, which essentially makes it very easy for you know relatively non-technical guy as well to to kind of rent this infrastructure and launch attacks. I mean anyone can launch a ransomware attack now.

Right? It's pretty easy to do. And Bitcoin gives you a perfect payment mechanism as well. Exactly. We also saw certain industry verticals being targeted more than the others. So nearly one in five ransomware attacks targeted manufacturing industry vertical making it most targeted industry in last 2 years. Healthcare as well as you know as as we start getting back to normal the restaurant and food services industries also saw significant spike in ransomware attacks when you compare it to last year.

One of the one of the trends that we saw I mentioned about how ransomware families continue to evolve their TTPs. I wouldn't call that we could call this a TTP as well as where as the law enforcement and and government agencies are cracking down and you know blocking certain ransomware groups. They will come back with a new name. All right, so you've seen more than five different families rebranding themselves. So it's almost identical code base just new name new infrastructure.

All right, that way you know the victims are still able to pay that ransom and and you know gain access to their data. The other trend that we notice is supply chain ransomware attacks. They are basically increasing the damage that is inflicted by these attacks as well as it also is shifting the the focus on the end party that you're relying on. Um Um so, the example that I can give you is uh and we mentioned this in the report as well as where um a a third party that uh a large organization depends on.

So, the large organization parent organization is very good in terms of their security posture, but a third party that has sensitive data about the parent organization for business purposes uh is being targeted by a ransomware group. They managed to exfiltrate data from that third party, and now they're going after the parent organization for for paying ransom. Right? So, the these type of uh um end party attacks uh we we will continue to see more and more um where uh you know, the these guys are just trying to make money by targeting the entire supply chain.

And then um geopolitical conflicts uh Russia-Ukraine war uh we saw a few ransomware attacks uh around the start of that uh conflict. Um it's fairly common to see many other geopolitical regional activity also being used by these threat actors when they launch uh some of these ransomware attacks. Yeah, now I did see uh some of the ransomware data that indicated a large percentage of companies simply pay the ransomware. Uh but as you pointed out, right, there's been a rise in this double extortion.

So, some a lot of times when you pay the ransomware it doesn't actually solve anything. So, um what are you seeing companies doing to try to protect themselves from ransomware? You know, what are they doing right or what are they doing wrong? Right. So, look, if you if you simplify the attack chain, uh the way I look at it is, you know, their their their first goal is to identify the victims, right? So, they're trying to find you your assets that are exposed to the internet.

Uh the goal is to hit that first endpoint. So, first stage is they will try to discover you, your your assets that are exposed. Second stage is where they will attempt to compromise one of your asset or one of your endpoints. It could be one of your server or even public cloud infrastructure that I mentioned. The third stage is where they will attempt to move laterally within your environment. This is one of the most important stage because the difference between a single machine being infected versus your entire environment going down, it's huge, right?

And I'll double-click on how organizations can safeguard at this stage as well. And then finally thereafter your data, right? As I mentioned before, encrypting your data, they're also stealing it. So, the way to look at it when you are trying to come up with your security security architecture, the first goal is to eliminate your external attack surface. Right? Reduce your attack surface. If they can't see you, they can't target you. So, Zscaler Zero Trust Exchange using zero trust architecture significantly reduces your external attack surface.

There's no external VPN server concentrators that the threat actors can attack in this case. The second stage is preventing that compromise. The reason many of the organizations struggled initially and some of them are still in their journey towards this digital transformation is ability to enforce consistent security policies, no matter where your users are. Right? Shouldn't matter whether your user is working in a home environment which is considered relatively insecure or they are within the office.

You should have ability to apply consistent security policy with full SSL inspection. Otherwise, it's a blind spot. When the user is in the office, you have a world-class castle and moat security architecture, but when the user goes out, you're now relying on the fact that they're VPNing in for security. So, having that consistent pane of glass, enforcing inline security engines, and with technologies like sandboxing, browser isolation, the goal is to make it extremely difficult for the threat actor even to hit that first endpoint or the first workload or server application with a attack.

Uh so that that's one point. The other point where I see some of the organization struggle is many of them that I speak with may have like 10 best-of-breed products, right? But they're not talking to each other that well. So, the team is actually doing hand-holding. And in many of the cases, like especially ransomware attack, once a payload goes through, you you really I mean, if 10 minutes later your engine comes back and say, "Hey, this thing was bad.

Take action." It may already be too late, right? Cuz the speed at which these guys are able to encrypt files and and you know, exfiltrate data is is amazing. So, need to have inline security engines that are working together in disrupting these type of modern attacks. And the human Yeah, you mentioned a couple of like sandboxing things that are which fall in the broader category of deception technology. I know this is an area that Zscaler's recently gotten into.

So, can you talk about that and then kind of double-click on the value of the deception technology? Exactly. And that was actually the third stage, right? Once once they hit your asset, initial asset, the goal for the threat actor is to move laterally within your environment, right? And uh when you when you think about it, you should ask the question, what is my blast radius if one of the user endpoint is infected by a malware, right? Um can the attacker reach to my crown jewel application?

Can they move laterally within the environment to other endpoints, right? So, that is something that you should have a clear picture. And the way you reduce that blast radius is by implementing user-to-app and app-to-app microsegmentation. And then that's where Zscaler Zero Trust Exchange, uh Zscaler Private Access piece of it, uh really helps our um uh customers to achieve that secure remote access from your user to the application without actually bringing user on the same network as the application.

So, that's one. The second one is uh as you mentioned uh deception, right? So, we made an acquisition last year, and we're very far along in our integration journey where where what we've done is we're uh we're integrating deception as yet another uh engine that will help uh reduce that blast radius as well as uh uh block um that insider threat activity or the compromised user activity at the time the attack is happening rather than alerting after uh it has happened.

So, um a quick overview of that is we have we have endpoint deception where we're using the same agent to perform deception on the endpoint. Uh think of uh secrets being planted at uh tactical places where threat actors or authorities uh malware families are known to look for uh you know, sensitive information. Then we have application deception using the same Zscaler Private Access model, we now have decoy farm that is projecting as as real application to your your end user.

So, if there is hands-on keyboard activity or the lateral propagation attempt, it may very well end up in a decoy farm and you're able to take action as soon as that happens. So, if if user's use ends up trying to access say RDP port of a legitimate application on one fine day, we'll redirect him to a decoy farm and and cut off all access to internal critical applications. So, stopping the attack at that time, alerting the SOC team who's then able to remediate whatever the infection may be on the endpoint.

Yeah, that's right. So, that's that's an interesting way to I guess protect yourself against ransomware without actually buying I guess these way to think of ransomware and the threat actors into you know, going after what they think is my corporate environment, but it isn't, right? So, that's you know, it's been used to some degree in other elements, but now you're trying to apply that the difficulty that is ransomware which is getting even harder.

Exactly. I mean, if you think of it, deception has been there for some time as well, but the point I made as an yet another point product, managing it is not always easy. So, our goal is to make it one-click option integrated with your existing deployment and then it's an entire platform that's helping you out. Yeah, that's that is an interesting trend I've seen too cuz I was talking with a CISO recently that that I guess a light bulb had gone off in his head where he said that you know, now he's starting to realize that best of breed everywhere doesn't lead to best-in-class threat protection.

In fact, it leads to sub-optimal. And now that security's moving to the cloud, the ability for a company like yourself to aggregate all that data, do some analytics on it, and then be able to find the insights in that, you know, you're going to get better insights than a company trying to pull data from 10 different systems or 20 different systems or sometimes 100 different systems, right? And then try and do the analytics themselves. So. Exactly.

Exactly. And And like I mentioned, you need to have that full visibility, and that's where the platform approach has really helped us. So, by the way, as you say, mentioned about external attack surface, prevent compromise, prevent lateral movement, and then we also solve the final piece of the puzzle, which is where when those ransomware operators are trying to steal your data, we are able to perform inline DLP with full SSL inspection. And And again, the goal over here is to apply that consistent data loss prevention inspection for all data that leaves your endpoint as well as your server assets or your workloads that are running in the public cloud.

The goal is to make sure you're preventing that data exfiltration attempt as well, whether it's those ransomware operators or nation-state threat actors. All right. The last question, Brett, since you do work with for one of the companies in the industry's biggest security providers and yourself, I consider a thought leader, what are some cybersecurity predictions you can give us for the remainder of this year and going into next year? Yeah. Yeah, I I always get asked about that.

So, I'll I'll name a few. Uh one of the prime ones, and and this is on top of my mind as well, right? Is um supply chain attacks. We will see more and more attackers go after supply chain attacks. The supply chain vector used to be associated with nation-state threat actors back in the day. But over the last couple years, we've seen that change. Even the crime where gangs are leveraging that. Uh they haven't used it uh efficiently, but we we anticipate that to change over the coming years.

Um the other piece that we see is the whole as a service model that I spoke about on ransomware side. Uh we also saw similar trend leading to a spike in fishing campaigns. Um fishing as a service model, right? So these as a service threat model will continue to proliferate. More and more gangs will uh take advantage of it and it will basically allow even a non um expert to conduct large-scale attacks. Um we will uh see threat groups leveraging the rebranding phenomena.

Uh right? The trend that we're seeing on the ransomware side. Uh it it will happen in other categories as well. And the goal is to get around the government and regional crackdowns. And then finally insider threats. I mean uh the Lapsus playbook that we saw uh targeting Octa. Um all organizations should seriously have a look at how they will detect and respond to a similar playbook. Right? Um and that's where having those table top exercises, um having a response plan in place uh will be very important.

But uh the prediction over here is growth in the insider threat use case as well. Where some of these gangs will will adopt uh Lapsus playbook to target some of the large organizations. Yeah. Um all right. Well Deepen, so you know, insider threats are probably a good way to end this. Um that was a fascinating discussion on ransomware, on protection, deception technology. So thank you for your time. Uh on behalf of Deepen, I'm Zis Karavale from ZK Research and thanks for watching.

Don't forget to click to subscribe. I'll also include the link to Zscaler and some of his reports I mentioned uh down below. Uh So, on behalf of Deepen thanks for you know, thanks for watching and see you next time on Zcast.

This transcript was generated automatically from the video's captions and may contain errors.

Written By
Zeus Kerravala
Zeus Kerravala
Published: Aug 15, 2022
Updated: Sep 25, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In a recent ZKast, I discussed the evolution of ransomware and other cyberthreats with Deepen Desai, Chief Information Security Officer and VP of Security Research at Zscaler. Desai also explained how Zscaler’s security research arm, ThreatLabz, uses insights from the Zero Trust Exchange to understand emerging threats and improve its platform.

Zeus Kerravala

Zeus Kerravala is an eWEEK regular contributor and the founder and principal analyst with ZK Research. He spent 10 years at Yankee Group and prior to that held a number of corporate IT positions. Kerravala is considered one of the top 10 IT analysts in the world by Apollo Research, which evaluated 3,960 technology analysts and their individual press coverage metrics.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.