Antigena Email Version 5: The Future of Email Protection
09
Feb 2021
Version 5 of Antigena Email enhances security operations with AI-powered threat detection and intuitive reporting for busy security teams.
Darktrace Version 5 signals a new chapter in AI-powered cyber security, offering a series of innovations across the entire Immune System platform – including AI augmentation and extended coverage across remote environments. This update also includes one-click integrations, on-demand automated investigations, and – the subject of this blog post – critical upgrades to Antigena Email, the world’s first autonomous email security technology.
Antigena Email uses a self-learning approach to stop every type of email threat, without relying on pre-existing lists or reputation checks. The technology autonomously interrogates every email in the context of its evolving understanding of ‘normal’ for the recipient, group, and organization as a whole. The features in Version 5 present several unique benefits to the user, not least in the various ways in which they can save time.
The self-learning AI technology provides a solution free from configuration, policy setting, and ongoing maintenance. The system’s accuracy results in negligible false positives, meaning security teams no longer need to release legitimate emails that legacy security tools have held back.
Furthermore, human security teams are augmented by Narrative – a new feature that automatically generates natural language reports on every email security incident. By surfacing a summary of what happened and why Antigena Email took the actions it did, Version 5 drastically reduces ‘time to meaning’ for overstretched human security teams.
Time to resolve a phishing attack
Email attacks are becoming increasingly targeted, and just one successful attack can give hackers the keys to an organization’s digital kingdom. Investigating the cause of a breach, cleaning up infected devices, and manually compiling incident reports can quickly drain a company’s resources.
Gateway tools tend to be time-consuming for security professionals, who must research malicious emails that were let through and tweak settings to stop them in the future, as well as release ‘false positive’ legitimate business emails that have been stopped for no good reason. Under such constraints, it is no wonder that phishing emails are reaching the inbox with alarming frequency – leading to wide-scale attacks.
While many traditional security tools put immense strain on human analysts, Antigena Email almost entirely removes the human from the equation. The self-learning technology accurately determines malicious from benign by taking a fundamentally different approach to email security. Rather than asking ‘is this email bad’ – Antigena Email uniquely sets to find out: ‘does this email belong’, in the context of ‘normal’ for the sender, the recipient, and the wider organization. It is this contextual understanding of the wider ‘patterns of life’ that enables the technology to catch sophisticated threats on the first encounter.
Time to find and release emails
Security teams too often spend their days ground down by repetitive tasks. For those who rely on legacy tools which present crude information and stop only the most basic threats, important trends are not found unless manually uncovered, and human experts are kept in the weeds.
With Antigena Email, this has now changed. Customers are now able to focus on gaining a holistic understanding of their organization. Such understanding is only possible when teams are not bogged down in details or trapped by an obscure user interface, tweaking complex settings which could inadvertently cause more harm than good.
The technology generates a bespoke dashboard for security teams, accounting for all specific preferences and interests. For example, organizations interested primarily in supply chain attacks on the C-suite can set Antigena Email to surface and chart anomalous emails tagged by Antigena Email as ‘Out of Character’, where specifically the recipient was C-suite.
In this way, IT teams can set the system once to exactly what interests them, and subsequently forget about it until they decide to log in and glance over key figures. When logging in, it is no longer to chase a specific email, and there is nothing to action – Antigena Email has already done it. Instead, IT teams can view the broad picture and use the information available to influence security decisions. They can now ask and fully understand which users are most exposed and why an organization is so at risk.
Time to understand what happened
Security professionals just need the answer. When looking at an email, no one should have to unpack and make sense of raw data. Instead, users should be presented with a recap summary – a Narrative – which is digestible in seconds and which even the most junior team members can easily grasp.
Antigena Email takes each complex case and words it in such a way that even a non-technical employee can understand. It uses advanced machine learning to present key information in plain English, allowing end users to perceive the situation at a glance.
Narrative tells the stories of what happened and why, and how aggressively an email was actioned. What was the sender’s intention? Were they trying to solicit the recipient into a bank transaction? Whatever the circumstances, if an email does not belong, that is the end of the story. There are no ongoing chapters, there is no fallout. Antigena Email neutralizes the email and ends the story before the threat has had the chance to develop.
And if a person wishes to dive deeper, Narrative provides one-click jumping off points that expose the underlying data (see the red text in the image above). But this is a choice. It is no longer business critical to scroll through emails and uncover information manually to stop future threats. As Antigena Email is proactive, the human no longer has to be.
A new era of email security
Antigena Email takes care of all the daily repetitive tasks – stopping the bad, allowing the good – taking the least aggressive action to neutralize any given threat. As a result, security teams are no longer forced to spend their days determining which emails are malicious or dealing with complaints from users who have had legitimate emails blocked.
Now that human experts no longer have to worry about sifting through emails themselves, they can focus on what matters. Antigena Email gives time to security teams to define their email environment, pinpoint the biggest risks, and identify general business trends.
Oops! Something went wrong while submitting the form.
Newsletter
Enjoying the blog?
Sign up to receive the latest news and insights from the Darktrace newsletter – delivered directly to your inbox
Thanks for signing up!
Look out for your first newsletter, coming soon.
Oops! Something went wrong while submitting the form.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
Dan Fein
VP, Product
Based in New York, Dan joined Darktrace’s technical team in 2015, helping customers quickly achieve a complete and granular understanding of Darktrace’s product suite. Dan has a particular focus on Darktrace/Email, ensuring that it is effectively deployed in complex digital environments, and works closely with the development, marketing, sales, and technical teams. Dan holds a Bachelor’s degree in Computer Science from New York University.
Bytesize Security: Insider Threats in Google Workspace
What is an insider threat?
An insider threat is a cyber risk originating from within an organization. These threats can involve actions such as an employee inadvertently clicking on a malicious link (e.g., a phishing email) or an employee with malicious intent conducting data exfiltration for corporate sabotage.
Insiders often exploit their knowledge and access to legitimate corporate tools, presenting a continuous risk to organizations. Defenders must protect their digital estate against threats from both within and outside the organization.
For example, in the summer of 2024, Darktrace / IDENTITY successfully detected a user in a customer environment attempting to steal sensitive data from a trusted Google Workspace service. Despite the use of a legitimate and compliant corporate tool, Darktrace identified anomalies in the user’s behavior that indicated malicious intent.
Attack overview: Insider threat
In June 2024, Darktrace detected unusual activity involving the Software-as-a-Service (SaaS) account of a former employee from a customer organization. This individual, who had recently left the company, was observed downloading a significant amount of data in the form of a “.INDD” file (an Adobe InDesign document typically used to create page layouts [1]) from Google Drive.
While the use of Google Drive and other Google Workspace platforms was not unexpected for this employee, Darktrace identified that the user had logged in from an unfamiliar and suspicious IPv6 address before initiating the download. This anomaly triggered a model alert in Darktrace / IDENTITY, flagging the activity as potentially malicious.
Following this detection, the customer reached out to Darktrace’s Security Operations Center (SOC) team via the Security Operations Support service for assistance in triaging and investigating the incident further. Darktrace’s SOC team conducted an in-depth investigation, enabling the customer to identify the exact moment of the file download, as well as the contents of the stolen documents. The customer later confirmed that the downloaded files contained sensitive corporate data, including customer details and payment information, likely intended for reuse or sharing with a new employer.
In this particular instance, Darktrace’s Autonomous Response capability was not active, allowing the malicious insider to successfully exfiltrate the files. If Autonomous Response had been enabled, Darktrace would have immediately acted upon detecting the login from an unusual (in this case 100% rare) location by logging out and disabling the SaaS user. This would have provided the customer with the necessary time to review the activity and verify whether the user was authorized to access their SaaS environments.
Conclusion
Insider threats pose a significant challenge for traditional security tools as they involve internal users who are expected to access SaaS platforms. These insiders have preexisting knowledge of the environment, sensitive data, and how to make their activities appear normal, as seen in this case with the use of Google Workspace. This familiarity allows them to avoid having to use more easily detectable intrusion methods like phishing campaigns.
Darktrace’s anomaly detection capabilities, which focus on identifying unusual activity rather than relying on specific rules and signatures, enable it to effectively detect deviations from a user’s expected behavior. For instance, an unusual login from a new location, as in this example, can be flagged even if the subsequent malicious activity appears innocuous due to the use of a trusted application like Google Drive.
Credit to Vivek Rajan (Cyber Analyst) and Ryan Traill (Analyst Content Lead)
Appendices
Darktrace Model Detections
SaaS / Resource::Unusual Download Of Externally Shared Google Workspace File
RansomHub Ransomware: investigación de Darktrace sobre la herramienta más nueva en ShadowSyndicate's Arsenal
What is ShadowSyndicate?
ShadowSyndicate, also known as Infra Storm, is a threat actor reportedly active since July 2022, working with various ransomware groups and affiliates of ransomware programs, such as Quantum, Nokoyawa, and ALPHV. This threat actor employs tools like Cobalt Strike, Sliver, IcedID, and Matanbuchus malware in its attacks. ShadowSyndicate utilizes the same SSH fingerprint (1ca4cbac895fc3bd12417b77fc6ed31d) on many of their servers—85 as of September 2023. At least 52 of these servers have been linked to the Cobalt Strike command and control (C2) framework [1].
What is RansomHub?
First observed following the FBI's takedown of ALPHV/BlackCat in December 2023, RansomHub quickly gained notoriety as a Ransomware-as-a-Service (RaaS) operator. RansomHub capitalized on the law enforcement’s disruption of the LockBit group’s operations in February 2024 to market themselves to potential affiliates who had previously relied on LockBit’s encryptors. RansomHub's success can be largely attributed to their aggressive recruitment on underground forums, leading to the absorption of ex-ALPHV and ex-LockBit affiliates. They were one of the most active ransomware operators in 2024, with approximately 500 victims reported since February, according to their Dedicated Leak Site (DLS) [2].
ShadowSyndicate and RansomHub
External researchers have reported that ShadowSyndicate had as many as seven different ransomware families in their arsenal between July 2022, and September 2023. Now, ShadowSyndicate appears to have added RansomHub’s their formidable stockpile, becoming an affiliate of the RaaS provider [1].
Darktrace’s analysis of ShadowSyndicate across its customer base indicates that the group has been leveraging RansomHub ransomware in multiple attacks in September and October 2024. ShadowSyndicate likely shifted to using RansomHub due to the lucrative rates offered by this RaaS provider, with affiliates receiving up to 90% of the ransom—significantly higher than the general market rate of 70-80% [3].
In many instances where encryption was observed, ransom notes with the naming pattern “README_[a-zA-Z0-9]{6}.txt” were written to affected devices. The content of these ransom notes threatened to release stolen confidential data via RansomHub’s DLS unless a ransom was paid. During these attacks, data exfiltration activity to external endpoints using the SSH protocol was observed. The external endpoints to which the data was transferred were found to coincide with servers previously associated with ShadowSyndicate activity.
Darktrace’s coverage of ShadowSyndicate and RansomHub
Darktrace’s Threat Research team identified high-confidence indicators of compromise (IoCs) linked to the ShadowSyndicate group deploying RansomHub. The investigation revealed four separate incidents impacting Darktrace customers across various sectors, including education, manufacturing, and social services. In the investigated cases, multiple stages of the kill chain were observed, starting with initial internal reconnaissance and leading to eventual file encryption and data exfiltration.
Attack Overview
Internal Reconnaissance
The first observed stage of ShadowSyndicate attacks involved devices making multiple internal connection attempts to other internal devices over key ports, suggesting network scanning and enumeration activity. In this initial phase of the attack, the threat actor gathers critical details and information by scanning the network for open ports that might be potentially exploitable. In cases observed by Darktrace affected devices were typically seen attempting to connect to other internal locations over TCP ports including 22, 445 and 3389.
C2 Communication and Data Exfiltration
In most of the RansomHub cases investigated by Darktrace, unusual connections to endpoints associated with Splashtop, a remote desktop access software, were observed briefly before outbound SSH connections were identified.
Following this, Darktrace detected outbound SSH connections to the external IP address 46.161.27[.]151 using WinSCP, an open-source SSH client for Windows used for secure file transfer. The Cybersecurity and Infrastructure Security Agency (CISA) identified this IP address as malicious and associated it with ShadowSyndicate’s C2 infrastructure [4]. During connections to this IP, multiple gigabytes of data were exfiltrated from customer networks via SSH.
Data exfiltration attempts were consistent across investigated cases; however, the method of egress varied from one attack to another, as one would expect with a RaaS strain being employed by different affiliates. In addition to transfers to ShadowSyndicate’s infrastructure, threat actors were also observed transferring data to the cloud storage and file transfer service, MEGA, via HTTP connections using the ‘rclone’ user agent – a command-line program used to manage files on cloud storage. In another case, data exfiltration activity occurred over port 443, utilizing SSL connections.
Lateral Movement
In investigated incidents, lateral movement activity began shortly after C2 communications were established. In one case, Darktrace identified the unusual use of a new administrative credential which was quickly followed up with multiple suspicious executable file writes to other internal devices on the network.
The filenames for this executable followed the regex naming convention “[a-zA-Z]{6}.exe”, with two observed examples being “bWqQUx.exe” and “sdtMfs.exe”.
Additionally, script files such as “Defeat-Defender2.bat”, “Share.bat”, and “def.bat” were also seen written over SMB, suggesting that threat actors were trying to evade network defenses and detection by antivirus software like Microsoft Defender.
File Encryption
Among the three cases where file encryption activity was observed, file names were changed by adding an extension following the regex format “.[a-zA-Z0-9]{6}”. Ransom notes with a similar naming convention, “README_[a-zA-Z0-9]{6}.txt”, were written to each share. While the content of the ransom notes differed slightly in each case, most contained similar text. Clear indicators in the body of the ransom notes pointed to the use of RansomHub ransomware in these attacks. As is increasingly the case, threat actors employed double extortion tactics, threatening to leak confidential data if the ransom was not paid. Like most ransomware, RansomHub included TOR site links for communication between its "customer service team" and the target.
Since Darktrace’s Autonomous Response capability was not enabled during the compromise, the ransomware attack succeeded in its objective. However, Darktrace’s Cyber AI Analyst provided comprehensive coverage of the kill chain, enabling the customer to quickly identify affected devices and initiate remediation.
In lieu of Autonomous Response being active on the networks, Darktrace was able to suggest a variety of manual response actions intended to contain the compromise and prevent further malicious activity. Had Autonomous Response been enabled at the time of the attack, these actions would have been quickly applied without any human interaction, potentially halting the ransomware attack earlier in the kill chain.
Conclusion
The Darktrace Threat Research team has noted a surge in attacks by the ShadowSyndicate group using RansomHub’s RaaS of late. RaaS has become increasingly popular across the threat landscape due to its ease of access to malware and script execution. As more individual threat actors adopt RaaS, security teams are struggling to defend against the increasing number of opportunistic attacks.
For customers subscribed to Darktrace’s Security Operations Center (SOC) services, the Analyst team promptly investigated detections of the aforementioned unusual and anomalous activities in the initial infection phases. Multiple alerts were raised via Darktrace’s Managed Threat Detection to warn customers of active ransomware incidents. By emphasizing anomaly-based detection and response, Darktrace can effectively identify devices affected by ransomware and take action against emerging activity, minimizing disruption and impact on customer networks.
Credit to Kwa Qing Hong (Senior Cyber Analyst and Deputy Analyst Team Lead, Singapore) and Signe Zahark (Principal Cyber Analyst, Japan)