❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

CISA promotes a fresh way to deter cyberattackers: Lie to them

16 September 2026 at 16:22

For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered.

The Wednesday guidance, β€œUsing Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters and penetration testers about how decoys can be a cheap, effective way to disrupt attackers, said Chris Butera, acting executive director of the cybersecurity division.

β€˜We’ve been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who’s already gained access to networks,” Butera told CyberScoop at Google Cloud’s Cyber Defense Summit 26.

It’s especially complementary for zero-trust (maintaining that no user or device is trustworthy by default) and assume-compromise (assuming that hackers have already gotten into a network) approaches, Butera said.

While the guidance is β€œreally relevant for everyone,” it’s something that can be especially useful in critical infrastructure sectors that don’t have the most personnel or money, he said.

β€œThis could be something to prioritize as a lower cost solution,” Butera said. β€œYou can create your own honey tokens yourself.”

The 22-page guidance includes decoy principles and goals, definitions of the different kinds of decoys and how to use them and scenarios for deployment.

Honeytokens, for instance, are β€œData elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity.”

β€œCyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” Butera said in a news release. β€œWith this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.” 

The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.

This phishing kit looks more like BEC-as-a-service

1 July 2026 at 06:00

Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged β€œbusiness email compromise-as-a-service” platform.

Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks β€” by 1,380% early this year compared to the same period last year β€” with an assist from artificial intelligence integration.

ARToken is notable, though, for the capabilities that go beyond what’s been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.

β€œThese features indicate the platform is more mature than a simple device code phishing kit β€” it is a complete BEC operations environment,” wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.

Kelley told CyberScoop that β€œwe’ve seen some offerings that touch on this capability, but this definitely seems more fleshed out and polished than previous instances.”

ARToken is also notable for its evasive capabilities, with a seven-layer anti-analysis system, the post states.

The research provides further details on what ARToken’s actual phishing lures look like in practice. They are targeted, rather than scattershot and opportunistic, as one lure the firm examined shows.

β€œThe messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life sciences company β€” abusing a real vendor relationship rather than inventing a sender,” Kelley wrote. β€œThe lure theme is an outstanding-invoice inquiry (β€˜the following invoices appear to still be outstanding… advise when this will be processed’), the kind of message accounts-payable staff are conditioned to act on.”

Kelley told CyberScoop that Cisco Talos doesn’t yet have a full sense of the breadth of the activity, nor who is making use of the capability.

β€œWe’ve seen the public sector targeted but it’s unlikely to be the only one,” he said.

The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop.

ICS Hard Knocks: Mitigations to Scenarios Found in ICS/OT Backdoors & Breaches

By: BHIS
5 December 2024 at 10:00

This blog will be referencing the ICS/OT Backdoors & Breaches expansion deck created by BHIS and Dragos. We will be reviewing the ICS-focused Initial Compromise cards that are used to simulate a cyber incident and suggest potential mitigations to what is presented.

The post ICS Hard Knocks: Mitigations to Scenarios Found in ICS/OT Backdoors & Breaches appeared first on Black Hills Information Security, Inc..

AWS: Assuming Access Key Compromise

By: BHIS
6 August 2018 at 10:42

Jordan Drysdale//* In this blog, we are assuming that we have obtained an access key, a secret key and maybe a .pem key from a network user who left these […]

The post AWS: Assuming Access Key Compromise appeared first on Black Hills Information Security, Inc..

❌
❌