Darktrace Defends McLaren Racing From Supply Chain Attacks
15
Nov 2021
15
Nov 2021
McLaren Racing chose Darktrace's self-learning AI to fight off supply chain attacks. Learn how Darktrace safeguards their organization with elite cybersecurity.
McLaren Racing has a track record of forming valuable and innovative partnerships. Without these partnerships and the web of organisations that make up our supply chain, it’s unlikely we could be where we are today.
Figure 1: The origins of the different components of McLaren’s 2021 car
Each component of the McLaren Formula 1 car – engine, tyres, brakes, suspension – has a long and complicated backstory, from the R&D labs where it was conceived, to the factory floor on which it was manufactured, to transport and logistics getting it to where it needs to be.
Looking at the entire organisation, the situation is even more complex. IT hardware and software, telemetry, and data analysis tools, each represent a critical component to McLaren Racing’s ecosystem. Without it, we couldn’t function at the top of our game.
But from a security perspective, each of these represent a potential chink in the team’s defensive armour, against a backdrop of a cyber-threat landscape which becomes more hostile every year. As we’ve seen this year from the likes of the SolarWinds hack and the Kaseya software exploit, attackers are waking up to the fact that the supply chain represents a significant opportunity.
A single supplier may represent a point of entry into thousands of organisations. For cyber-criminals, this means one successful compromise can result in more access, more data, and ultimately greater profit.
McLaren Racing is all too aware of recent shifts in the cyber security landscape. A successful cyber-attack on our organisation could have implications on race-day performance, as well as our wider reputation. Last year, we brought in a new line of defence with Darktrace’s Self-Learning AI technology, that learns our business from the ground up, and interrupts subtle and fast-moving cyber-threats wherever they emerge – including from our supply chain.
Threat find: Attacking through the inbox
In this attack, 12 employees were targeted in a systematic phishing attack, receiving an email from a long-established team supplier, notifying them that a voicemail had been left for them.
Figure 2: An extract of the phishing email coaxing the recipient to click
The link to play the voicemail led to a legitimate-looking voicemail service site.
When following the link to access the message, the site requested Office 365 credentials to authenticate the user, designed to harvest the McLaren Racing credentials that could be used to access our environment.
Figure 3: The fake login page
Of the 12 recipients, several key people within our team were targeted, including technical directors and purchase ledgers. The attackers behind this phishing campaign no doubt hand-picked these individuals both due to their authorization powers and the likelihood their accounts had access to sensitive data.
Had these accounts been compromised, the attackers would have had access to some of the highest sensitivity of intellectual property, finance information and executive level strategy within racing.
Darktrace’s email security technology, Antigena Email, assessed the content of these emails as they were delivered, and identified several unusual indicators of attack. While it recognised that the account was one familiar to McLaren, it compared this attack with previous emails sent from the supplier and recognised several risk indicators. Darktrace Antigena autonomously took the decision to hold the email from being delivered to users’ mailboxes.
Legitimate communication between our team and the supplier was still flowing uninterrupted, as Darktrace Antigena was assessing each email’s indicators for risk. The following day, the supplier’s account manager in our team received an email from the supplier in question, informing them that one of their accounts had been compromised and was used to send phishing emails to some of their customers. This confirmed that Antigena Email had correctly identified the email as malicious.
Traditional email security tools rely on historical attack data to determine friend from foe, but this is only effective in cases where an email domain or a malicious URL has been previously encountered. In this case, traditional filtering allowed the email through. Only by having Darktrace’s understanding of ‘self’ and Autonomous Response was McLaren able to avoid exposure to risk on this occasion.
This is reflective of a wider pattern noticed by the security team. Darktrace determines that around 40% of emails going through Antigena Email would have been detected by our other security tools, suggesting that Darktrace is detecting an extra 60% of malicious emails and taking action to ensure we are protected 24/7.
This was just one example of an attempted attack on McLaren through the inbox. On another occasion, Antigena Email identified an email that was attempting to impersonate a sponsor. The email in question was requesting that a senior McLaren Racing figure reset their password and contained a suspicious link that led to a credential harvester. Again, Antigena took action on the emails at time of delivery, and our internal cyber team never had to respond to what could have been a serious incident. It’s through Darktrace taking autonomous action like this on a daily basis that we are able to focus our time on higher-value, strategic work, driving success for the wider team.
Why the supply chain demands a new approach to security
In today’s digitised world, it is impossible to operate as a fluid, dynamic organisation without interacting with suppliers and partners at every digital layer: from email, to file sharing services and technology partners delivered through the cloud. As McLaren grows and works with leading global organisations to improve its performance, its supply chain ecosystem will only get broader.
Attackers are targeting suppliers because they represent a single key that opens potentially dozens or even hundreds of locks, and email is just one avenue of attack. By partnering with Darktrace, McLaren experiences the value of self-learning protection on a daily basis, across its email systems, cloud services, and corporate network.
Whether it’s email or some other form of communication from a supplier, you cannot assume you know who’s on the other side of the keyboard. This is what so many existing security defences do – with static rules and signatures unable to truly tell friend from foe and reveal account takeovers and compromised systems. Modern organisations need a solution that is able to identify potentially malicious activity from suppliers by analysing a broad range of indicators and revealing subtle deviations that indicate threat, and this is where Self-Learning AI shines.
Like this and want more?
Receive the latest blog in your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
NEWSLETTER
Like this and want more?
Stay up to date on the latest industry news and insights.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
AUTHOR
ABOUT ThE AUTHOR
Ed Green
Head of Commercial Technology, McLaren Racing
Ed Green works in the Architecture practice within the Information Technology function at McLaren Technology Group, as well as being responsible for the successful integration of their Technology Partners into the McLaren ecosystem. Ed joined McLaren in March 2018 after spending 5 years working for Block Solutions, a specialist network consultancy. In previous roles, he led the Consultancy division at a UK Solution Integrator operating across the public, enterprise, and commercial sectors. Ed has driven innovative engagements with organisations such as Harrods, intu, The Francis Crick Institute, and Barts Health NHS Trust. He has also spent seven years on the council at Great Ormond Street Hospital representing the views of patients at a Board level, and he continues his work at the Hospital School as a Governor and supports the school with STEM initiatives.
Darktrace has been named as Microsoft UK Partner of the Year for 2024! The Microsoft Partner Awards recognize winners for their commitment to customers, impact of solutions, and exemplary use of Microsoft technologies.
Whilst the award was granted based on our innovations combining Darktrace/Email and Microsoft Defender for Office 365, our shared values go beyond technology. Darktrace stood out for the integration of our products to deliver exceptional security value to customers, as well as our investment in partnerships, marketplace and go to market. Microsoft was also impressed with our strong commitment to diversity and inclusion and our broader contribution to both the UK economy and the UK tech sector.
Microsoft Defender for Office 365 + Darktrace/Email leave attackers nowhere to hide
The email threat landscape is constantly evolving. Attacks are becoming more sophisticated, more targeted and increasing in multi-stage payload attacks. Across the Darktrace customer base in 2023 alone, we have seen a 135% increase in ‘novel social engineering attacks’, corresponding with the rise of ChatGPT, 45% of phishing emails were identified as spear phishing attempts and a 59% increase in multi-stage payload attacks.
Legacy defenses were built to address a high volume of unsophisticated attacks, but generative AI has shifted the threats towards lower quantity yet very sophisticated, high impact targeted attacks. Microsoft Defender for Office 365’s rapid innovation has outpaced the Secure Email Gateway’s rule and signature based historical data approach. Customers no longer need email gateways which duplicate workflows and add expense native to their Defender for O365 solution.
Point email solutions overlap with Microsoft in 3 key areas: detection approach, workflows, capabilities
Detection - Microsoft receives trillions threat signals daily, giving customers the broadest scope of the attack landscape. Darktrace combined with Microsoft unites business and attack centric approaches
Workflows – any Microsoft configurations are reflected automatically in Darktrace/Email. Users can keep daily workflow in Microsoft, while a traditional SEG requires duplicated workflows
Capabilities – Microsoft handles foundational elements like archiving/encryption/signature matching while Darktrace handles advanced threat security
Darktrace/Email is built to elevate, not duplicate, Microsoft email security – removing the burden of operating legacy point solutions and blocking 25% more threats. Robust account takeover protections to stop the 38% of sophisticated threats other tools miss. Customers can seamlessly correlate activity and insights across Microsoft email, DMARC and Teams to stop threats on average 13 days earlier.
Azure Marketplace
Microsoft Azure customers can access Darktrace in the Azure Marketplace to take advantage of the scalability, reliability, and agility of Azure to drive rapid IT operations and security integrations across the enterprise. Customers can leverage their Microsoft Azure Consumption Commitments (MACC), making procurement simple. As UK Partner of the Year winner, customers know they have a trusted partner with Darktrace and a proven solution to work seamlessly with Azure.
Following up on our Conversation: Detecting & Containing a LinkedIn Phishing Attack with Darktrace
25
Jun 2024
Note: Real organization, domain and user names have been modified and replaced with fictitious names to maintain anonymity.
Social media cyber-attacks
Social media is a known breeding ground for cyber criminals to easily connect with a near limitless number of people and leverage the wealth of personal information shared on these platforms to defraud the general public. Analysis suggests even the most tech savvy ‘digital natives’ are vulnerable to impersonation scams over social media, as criminals weaponize brands and trends, using the promise of greater returns to induce sensitive information sharing or fraudulent payments [1].
LinkedIn phishing
As the usage of a particular social media platform increases, cyber criminals will find ways to exploit the increasing user base, and this trend has been observed with the rise in LinkedIn scams in recent years [2]. LinkedIn is the dominant professional networking site, with a forecasted 84.1million users by 2027 [3]. This platform is data-driven, so users are encouraged to share information publicly, including personal life updates, to boost visibility and increase job prospects [4] [5]. While this helps legitimate recruiters to gain a good understanding of the user, an attacker could also leverage the same personal content to increase the sophistication and success of their social engineering attempts.
Darktrace detection of LinkedIn phishing
Darktrace detected a Software-as-a-Service (SaaS) compromise affecting a construction company, where the attack vector originated from LinkedIn (outside the monitoring of corporate security tools), but then pivoted to corporate email where a credential harvesting payload was delivered, providing the attacker with credentials to access a corporate file storage platform.
Because LinkedIn accounts are typically linked to an individual’s personal email and are most commonly accessed via the mobile application [6] on personal devices that are not monitored by security teams, it can represent an effective initial access point for attackers looking to establish an initial relationship with their target. Moreover, user behaviors to ignore unsolicited emails from new or unknown contacts are less frequently carried over to platforms like LinkedIn, where interactions with ‘weak ties’ as opposed to ‘strong ties’ are a better predictor of job mobility [7]. Had this attack been allowed to continue, the threat actor could have leveraged access to further information from the compromised business cloud account to compromise other high value accounts, exfiltrate sensitive data, or defraud the organization.
LinkedIn phishing attack details
Reconnaissance
The initial reconnaissance and social engineering occurred on LinkedIn and was thus outside the purview of corporate security tools, Darktrace included.
However, the email domain “hausconstruction[.]com” used by the attacker in subsequent communications appears to be a spoofed domain impersonating a legitimate construction company “haus[.]com”, suggesting the attacker may have also impersonated an employee of this construction company on LinkedIn. In addition to spoofing the domain, the attacker seemingly went further to register “hausconstruction.com” on a commercial web hosting platform. This is a technique used frequently not just to increase apparent legitimacy, but also to bypass traditional security tools since newly registered domains will have no prior threat intelligence, making them more likely to evade signature and rules-based detections [8]. In this instance, open-source intelligence (OSINT) sources report that the domain was created several months earlier, suggesting this may have been part of a targeted attack on construction companies.
Initial Intrusion
It was likely that during the correspondence over LinkedIn, the target user was solicited into following up over email regarding a prospective construction project, using their corporate email account. In a probable attempt to establish a precedent of bi-directional correspondence so that subsequent malicious emails would not be flagged by traditional security tools, the attacker did not initially include suspicious links, attachments or use solicitous or inducive language within their initial emails.
To accomplish the next stage of their attack, the attacker shared a link, hidden behind the inducing text “VIEW ALL FILES”, to a malicious file using the Hightail cloud storage service. This is also a common method employed by attackers to evade detection, as this method of file sharing does not involve attachments that can be scanned by traditional security tools, and legitimate cloud storage services are less likely to be blocked.
OSINT analysis on the malicious link link shows the file hosted on Hightail was a HTML file with the associated message “Following up on our LinkedIn conversation”. Further analysis suggests the file contained obfuscated Javascript that, once opened, would automatically redirect the user to a malicious domain impersonating a legitimate Microsoft login page for credential harvesting purposes.
Although there was prior email correspondence with the attacker, this email was not automatically deemed safe by Darktrace and was further analyzed for unusual properties and unusual communications for the recipient and the recipient’s peer group.
Darktrace determined that:
It was unusual for this file storage solution to be referenced in communications to the user and the wider network
Textual properties of the email body suggested a high level of inducement from the sender, with a high level of focus on the phishing link.
The full link contained suspicious properties suggesting it is high risk.
Based on these anomalies, Darktrace initially moved the phishing email to the junk folder and locked the link, preventing the user from directly accessing the malicious file hosted on Hightail. However, the customer’s security team released the email, likely upon end-user request, allowing the target user to access the file and ultimately enter their credentials into that credential harvesting domain.
Lateral Movement
Correspondence between the attacker and target continued for two days after the credential harvesting payload was delivered. Five days later, Darktrace detected an unusual login using multi-factor authentication (MFA) from a rare external IP and ASN that coincided with Darktrace/Email logs showing access to the credential harvesting link.
This attempt to bypass MFA, known as an Office365 Shell WCSS attack, was likely achieved by inducing the target to enter their credentials and legitimate MFA token into the fake Microsoft login page. This was then relayed to Microsoft by the attacker and used to obtain a legitimate session. The attacker then reused the legitimate token to log into Exchange Online from a different IP and registered the compromised device for MFA.
The IP addresses used by the attacker appear to be part of anonymization infrastructure, but are not associated with any known indicators of compromise (IoCs) that signature-based detections would identify [9] [10].
In addition to logins being observed within half an hour of each other from multiple geographically impossible locations (San Francisco and Phoenix), the unexpected usage of Chrome browser, compared to Edge browser previously used, provided Darktrace with further evidence that this activity was unlikely to originate from the legitimate user. Although the user was a salesperson who frequently travelled for their role, Darktrace’s Self-Learning AI understood that the multiple logins from these locations was highly unusual at the user and group level, and coupled with the subsequent unexpected account modification, was a likely indicator of account compromise.
Accomplish mission
Although the email had been manually released by the security team, allowing the attack to propagate, additional layers of defense were triggered as Darktrace's Autonomous Response initiated “Disable User” actions upon detection of the multiple unusual logins and the unauthorized registration of security information.
However, the customer had configured Autonomous Response to require human confirmation, therefore no actions were taken until the security team manually approved them over two hours later. In that time, access to mail items and other SharePoint files from the unusual IP address was detected, suggesting a potential loss of confidentiality to business data.
However, it appears that the attacker was able to maintain access to the compromised account, as login and mail access events from 199.231.85[.]153 continued to be observed until the afternoon of the next day.
Conclusion
This incident demonstrates the necessity of AI to security teams, with Darktrace’s ActiveAI Security Platform detecting a sophisticated phishing attack where human judgement fell short and initiated a real-time response when security teams could not physically respond as fast.
Security teams are very familiar with social engineering and impersonation attempts, but these attacks remain highly prevalent due to the widespread adoption of technologies that enable these techniques to be deployed with great sophistication and ease. In particular, the popularity of information-rich platforms like LinkedIn that are geared towards connecting with unknown people make it an attractive initial access point for malicious attackers.
In the second half of 2023 alone, over 200 thousand fake profiles were reported by members on LinkedIn [11]. Fake profiles can be highly sophisticated, use professional images, contain compelling descriptions, reference legitimate company listings and present believable credentials.
It is unrealistic to expect end users to defend themselves against such sophisticated impersonation attempts. Moreover, it is extremely difficult for human defenders to recognize every fraudulent interaction amidst a sea of fake profiles. Instead, defenders should leverage AI, which can conduct autonomous investigations without human biases and limitations. AI-driven security can ensure successful detection of fraudulent or malicious activity by learning what real users and devices look like and identifying deviations from their learned behaviors that may indicate an emerging threat.
Appendices
Darktrace Model Detections
DETECT/ Apps
SaaS / Compromise / SaaS Anomaly Following Anomalous Login
SaaS / Compromise / Unusual Login and Account Update