From XZ to Crowdstrike -Impact and future implications of supply chain attacks

September, 2, 2024

A supply chain attack can potentially impact the global economy and bring it to a crashing halt. What happened with Crowdstrike, XZ Utils project and mitigation strategies for organisations to address supply chain attacks

Globalisation and digitalisation have made many aspects of the world economy heavily reliant on technology such as smartphones and notebooks which in turn are dependent on regular software and security updates from the manufacturers. This intricate network of entities, resources, goods and services forms a supply mesh that enables international trade, travel and commerce as we know it today.

To enable these software updates, a certain level of implicit trust is afforded to a company when it pushes updates to their devices that they are free of malware and error. This implicit level of trust makes supply chain attacks a tempting prospect for threat actors. By gaining access to a manufacturer’s infrastructure, threat actors are able to inject malware into legitimate software updates, making it potentially one of the most effective and dangerous attack vectors possible. This attack vector is not a new idea, with recent attempts like ShadowPad, CCleaner and ShadowHammer in recent years show that a determined attacker can get to the most protected networks. However the recent Crowdstrike incident has demonstrated the significance of the supply chain and the unprecedented scale of an impact if something goes wrong, opening up new questions as to the vulnerability of supply chains and our dependency on them today.

Crowdstrike - The Day The Earth Stood Still

Starting on Friday, 19 July 2024, 04:09 UTC for a span of approximately two to three days, the world economy ground to a halt thanks to a content configuration update released by CrowdStrike, a US-based cybersecurity company that is one of the few companies afforded with kernel privileges to the Windows operating system.

The configuration update for Crowdstrike should have been a routine, a regular update to the protection mechanisms of their Falcon platform, gaining telemetry and detecting possible novel threat techniques for the Windows platform. Unfortunately, this update resulted in a never ending reboot spiral for over 8.5 million Windows machines across the world,” said Vitaly Kamluk, Cybersecurity expert of Global Research & Analysis team (GReAT) at Kaspersky.

According to the media, critical infrastructure like hospitals, banks, airlines and more including critical government infrastructure such as the United States NASA, Federal Trade Commission, National Nuclear Security Administration, 911 call centres for emergencies, government websites in the Philippines and more that had systems running Windows which were protected by Crowdstrike were affected by the erroneous update and unable to do business. At present, this could be considered as the worst outage in history with an unprecedented amount of financial damage.

Affected systems include Windows hosts running sensor version 7.11 and above that were online between Friday, July 19, 2024 04:09 UTC and Friday, July 19, 2024 05:27 UTC and received the update. Mac and Linux hosts were not impacted. Ultimately, this scenario was not instigated by any APTs but an erroneous software update that showed the potential aftermath of a perfectly executed supply chain attack. This however is not the first incident of a supply chain failure as prior incidents have occurred before such as the compromise of Linux XZ library in a sophisticated operation.

Linux XZ - A wolf in sheep’s clothing brought to light

Earlier in 2024, the Linux XZ Utils project, a set of free data compression command-line tools and a library were found to be compromised in a supply-chain nature of attack. The attack was a highly complex and sophisticated backdoor which was masterfully obfuscated and hidden to hook and tamper the logic of OpenSSH, an implementation of Secure Shell (SSH), to enable unauthorised access. SSH is also the name for cryptographic network protocol to securely operate devices including enterprise servers, IoT devices, network routers, network-attached storage devices and more.

At present, tens of millions of home appliances connected to the Internet of Things (IoT), millions of servers, data centres and network equipment are reliant on SSH which can potentially lead to a catastrophe that would dwarf the Crowdstrike incident. Open-source software company Red Hat noted that this incident is tracked in the NIST National Vulnerability Database as case CVE-2024-30942 with a maximum severity score of 10, acknowledging its potential for exploitation by malicious threat actors.

Forensic analysis revealed that the commits were made by a GitHub user with the username JiaT75 also known as ‘Jia Cheong Tan’ who joined the XZ Utils project team and contributed to the XZ project from 2021. The identity of JiaT75 is a matter of speculation as it could be multiple threat actors working off a single account though it was known that the account operated using a Singapore VPN and in the UTC+8 time zone.

Like a wolf in sheep’s clothing, JiaT75 then built trust over time by socialising with other contributors and offering positive contributions to ultimately gain control to maintain the XZ project archive and gain privileges to merge commits. It was discovered that the XZ/libzma build was modified and cloaked with a series of complex obfuscations, becoming a dependency for SSH on some operating systems, essentially allowing unfettered access to infected systems.

This incident was fortunately detected in time and research is ongoing but highlights that social engineering in combination with the nature of open source software remains another viable avenue for a supply chain attack.

Kaspersky experts conducted a comprehensive analysis of the case, which included examining the social engineering tactics involved.

What does the threat landscape bode for an AI-integrated future?

AI is increasingly becoming integrated into society with aspects of AI being used to optimise infrastructure in smart cities, enhance healthcare, education, agriculture and more. As with any technology, AI is not infallible as it is dependent on learning models and training to derive meaningful input and which can be subject to supply chain attacks by injecting malicious input. “Potential avenues of a supply chain attack on AI would be to manipulate the training data and introduce biases and vulnerabilities into the model or modify the AI models with altered versions so that it would produce incorrect outputs,” says Vitaly. He adds that such behaviour could potentially be difficult to detect, allowing malicious activities to go unnoticed for extended periods.

For APTs playing the long game, supply chain attacks can lie quietly waiting for the right target while potentially obfuscating the malware payload, hiding it as a legitimate file and placing extended tools within a trusted company’s infrastructure to facilitate higher level access or ultimately a full system compromise. Far worse is the long term possibility of bugs or flaws being introduced into supply chain attacks focused on AI that would degrade its capabilities and quality over time, making it the equivalent of a time bomb, impacting crucial systems with a wide reach or critical importance.

Readily available large language model (LLM) AIs such as ChatGPT, CoPilot and Gemini can be manipulated to help in creating convincing spear phishing attacks while AI deepfakes can be used to mimic important personnel, which resulted in the loss of US$25 million in Hong Kong when a threat actor mimicked the image of a company’s chief financial officer to disburse the funds.

For nearly two decades, the specialists at Kaspersky's AI Technology Research Center have been at the forefront of applying artificial intelligence to cybersecurity and developing Ethical AI. The team's AI expertise is integrated into various Kaspersky products, improving everything from AI-enhanced threat detection and alert prioritisation to threat intelligence powered by generative AI.

To address this potential threat landscape of supply attacks, organisations have a number of strategies. “In addition to best cybersecurity practices, organisations need to conduct mitigation strategies to manage or minimise the potential impact of a supply chain attack in their infrastructure,” says Vitaly. Among the strategies are rigorous testing before builds go live, thorough tools integrity and strict manufacturing control, model version numbers and model validation to track changes and versions, continuous monitoring for anomalies, digital signatures for builds and regular security audits.

More information about this activity can be found at Kaspersky

Video Story

A Crisis If Economy Does Not Grow – Sujeewa Mudalige & Talal RafiLiberal Handling of Market Will Continue | Duminda HulangamuwaTax exemptions have not served very well for SL - IMF's Peter Breuer ‘At Hydepark’SL tourism to showcase a new era of growth at WTM 2024 in LondonExclusive Interview with Dr. Nandalal Weerasinghe at Ada Derana Hyde ParkThe Nightly Business Report |17th May 2024The Nightly Business Report | 15th May 2024The Nightly Business Report | 13th May 2024The Nightly Business Report | 07 May 2024The Nightly Business Report | 30th April 2024The Nightly Business Report | 29th April 2024The Nightly Business Report | 26th April 2024The Nightly Business Report | 25th April 2024The Nightly Business Report | 22nd April 2024The Nightly Business Report | 19th April 2024The Nightly Business Report | 17th April 2024The Nightly Business Report | 16th April 2024The Nightly Business Report | 15th April 2024RICH MUST PAY MORE TAXES, IMF’S PETER BREUER & SARWAT JAHAN ‘AT HYDEPARK WITH INDEEWARI AMUWATTE’2024 Will Have More Positivity – CBSL Governor Dr. Nandalal Weerasinghe ‘@ HYDEPARKBudget 2024 - Dr. Roshan PereraWhat's happening to tourism ?SALIYA PIERIS & NALAKA GUNAWARDENE ON SL ONLINE SAFETY BILL - 'AT HYDEPARK WITH INDEEWARI AMUWATTE’Ravi Abeysuriya and Deshan Pushparajah join Indeewari Amuwatte 'At HydePark' on Ada Derana 24Former IMF-ICD director Dr. Sharmini Coorey joins Indeewari Amuwatte 'at HYDEPARK' on Ada Derana 24Dr. Priyanga Dunusinghe and Dr. Nadeem Ul Haque join Indeewari Amuwatte At HydeParkHEAD OF SOE RESTRUCTURING UNIT SURESH SHAH JOINS INDEEWARI AMUWATTE 'AT HYDEPARK' ON ADA DERANA 24Sri Lanka: Supporting Recovery and Promoting Stable & Inclusive GrowthCBSL Governor is confident that Sri Lanka will be able to achieve debt sustainability even before the timeframe envisaged through the IMF EFF programmeCSE had a bullish start for the week but later drop in prices capped early gains of the dayForeign Investors resulted a net foreign inflow of LKR 230 millionCSE continued to move upward ahead of monetary policy review meetingCSE records downward trend for second consecutive dayThe current tax policy is a rescue operation - PresidentCSE managed to secure its bull run for 2nd consecutive session in the weekCSE’s ASPI records massive gain - 20.02.2022Sri Lanka Stock Market 13.02.2023Sri Lanka Stock Market 10.02.2023Sri Lanka Stock Market 08.02.2023Sri Lanka Stock Market 03.02.2023Sri Lanka Stock Market 02.02.2023Govt needs to have a policy framework to bring about the necessary change - Ranjit PageSri Lanka Stock Market 26.01.2023Sri Lanka Stock Market 24.01.2023Sri Lanka Stock Market 20.01.2023Sri Lanka Stock Market 18.01.2023Sri Lanka Stock Market 13.01.2023Sri Lanka Stock Market 12.01.2023Alternative solutions for Sri Lanka's economic recovery - Dr. Howard Nicholas, EconomistSri Lanka Stock Market 10. 01. 2023Sri Lanka Stock Market 09.01.2023Sri Lanka Stock Market 04.01.2023Sri Lanka Stock Market 03.01.2023IMF bailout package can be approved by the global lender in January 2023 by which time Sri Lanka would have secured creditor assurances from countries including India and China – CBSL GovernorADA DERANA POST-BUDGET DISCUSSION ON 'RECOVERING FROM CRISIS, REGAINING STABILITY'CSE Chairman says they expect to introduce a host of new financial instruments to the Colombo Bourse by mid-2023Sri Lanka’s Turnaround Strategies and the Role of the International CommunityPresident Ranil addresses Sri Lankan diaspora in UKUSAID ADMINISTRATOR SAMANTHA POWER WITH INDEEWARI AMUWATTE AT HYDEPARK ON ADA DERANA 24PETROLEUM ENGINEER SALIYA WICKRAMASURIYA JOINS INDEEWARI AMUWATTE AT HYDEPARK ON ADA DERANA 24US Ambassador to Sri Lanka Julie Chung Joins Indeewari Amuwatte at Hydepark on Ada Derana 24Press Conference on Current Economic SituationSri Lanka may take weeks to hire debt advisers, Sabry saysExpert Panel of Industrialists Join Indeewari Amuwatte @HydeparkExperts Discuss How to Best Address Sri Lanka’s Economic Situation with Indeewari Amuwatte @HYDEPARK@Hyde Park with Indeewari Amuwatta | Srimathi ShivashankarHow can Sri Lanka reset and revive its economy while finding solutions to address a health crisis?CBSL Governor Ajith Nivard Cabraal Joins Indeewari Amuwatte @HYDEPARKU.S. Ambassador to Sri Lanka Alaina B. Teplitz says that Sri Lanka should choose its partners based on openness, transparency and true investments rather than loans.We're not taking anything away from investors - SEC ChairmanEconomic Freedom of Sri LankaCSE Chairman Dumith Fernando Joins Indeewari Amuwatte @Hydepark on Ada Derana 24Inaugural speech by His Excellency President Gotabaya Rajapaksa at Sri Lanka Economic Summit 2020US SEC. of State Mike Pompeo Joins Indeewari Amuwatte @Hydepark on Ada Derana 24Foreign Secretary Joins Indeewari Amuwatte @HYDEPARK on Ada Derana 24GET REAL - Senior Deputy Governor of the Central Bank of Sri Lanka Dr. Nandalal WeerasingheMAS joins global efforts to contain spread of COVID-19Preventing Disruptions to Economic Activity amidst the Spread of the COVID-19 PandemicDUMITH FERNANDO JOINS INDEEWARI AMUWATTE @HYDEPARK ON ADA DERANA 24FORMER CBSL GOVERNOR AJITH NIVARD CABRAAL JOINS INDEEWARI AMUWATTE @HYDEPARK ON ADA DERANA 24BE BOLD! DR. MARK MOBIUS TELLS SRI LANKASri Lanka urgently needs a nation branding strategy that will help the island nation be a game-changer - Dr. Udaya IndrarathnaLotus Tower officially declared openAgreement signed to develop East container terminal at Colombo PortUpdate from Washington: US Foreign Policy towards China and South Asia and what it means for Sri LankaEaster Day attacks are a blow in the economy at large, not just tourism industryILO Launches Report on the Future of Work in Sri LankaMacroeconomic Impact of the Budget 2019Fiscal Impact of the Budget 2019Harry Jayawardena @ KPMG's post Budget ForumDissecting Budget 2019Sri Lanka Economic Association – Annual Sessions 2018Land reclamation for Port City completedSri Lanka Targeting 3 Million Tourists in 2019Susantha Ratnayake bids farewell to JKH, Balendra junior in as ChairmanThe economy cannot operate isolation - PallewattaDo we have the money to pay our obligations coming due next year? Answer is yes.CBSL Governor Dr. Indrajit Coomaraswamy, addressing 22nd Annual General Meeting of the ACGMr. Ranjit Page addressing the 2nd Annual General Meeting of the Sri Lanka Retailers’ AssociationCentral Bank issues a new series of coinsUS$ 184 million spent to defend Rupee - CBSL GovernorSri Lanka PM Ranil ‘Concerned on rebalancing of the Global Order’ at World Economic Forum on ASEANSri Lanka Economic Summit 2018 - Keynote Address Mr. Arun M Kumar - Chairman and CEO, KPMG IndiaSL at risk of exchange rate crisis - NomuraSumal Perera suggests Dhammika Perera should be the Next Presidential Candidate at Fireside ChatSL's IT/BPM Marks $1.2 Bn in Revenue - EDBContent creators can now monetize via YouTube in Sri Lanka!There are about 20 other reports like of the bond scam - Auditor GeneralA rapid development in coming 18 months - PMEconomic growth cannot be achieved with a small marketSL Rupee should be allowed to float – IMFSri Lanka highly important in terms of business in South Asia - Petri PeltonenSri Lanka blessed with rich natural resources we can only dream about - Harri KämäräinenGovt planning new national economic strategy – Prof. Lalith SamarakoonSri Lanka rupee hits record lowMonetary Board decides to reduce SLFR by 25 bpsEU delegation highlights need for further progress on human rightsTourism Minister requests diplomats to invite countrymen to visit SLSri Lanka statistics office withdraws GDP dataJapan-Sri Lanka Business Forum held under President's patronageEvening with a Corporate Leader : Mr Dhammika PereraThere is scarcity of talent - Kathy Tingate, Director HR, Microsoft Asia PacificGas cylinder prices to be increased?Budget Openness: Sri Lanka Needs Higher StandardsStock Market continues strong start to the year with the second listing of 2018United States GSP program expires on Dec 31President to request Russia to withdraw tea banJAT Holdings could go public in SingaporeLVL Energy Fund announces Rs. 1.2 billion IPO to fund its strategic growth and expansionWe still haven't found all the dead bodies - PMA budget office to be established in parliament by the end of 2018 - Minister EranWe have a serious concern about debt distress – CBSL GovernorPetroleum Minister Arjuna Ranatunga explains cause for fuel shortageAnika Wijesuriya has fled country due to threats - AG's DeptSri Lanka and Finland to ink agreement on digitalizationMorison PLC unveiled to mark new eraDSL Enterprises joins with Little Hearts social welfare projectPM inaugurates largest naval vessel to be produced in SLAG's dept grills PTL legal officers over litigation errorPresident declares open star class hotel in Nuwara EliyaFormer CB Governor questioned on Greek bond investmentsNew Inland Revenue Bill to be tabled on FridayRevelations at treasury bond commission by former EPF SuperintendentBOI should be closed down - Justice MinisterAloysius asked to hand over personal electronic devices to bond commissionSri Lanka Customs launches online payment platform for declarationsSri Lanka’s tallest building gets shaky from the startBeneficiaries of EPF will have to pay taxes - BandulaWe need an export oriented economy - PMRavi Karunanayake on why he switched from finance to foreign affairsSL looking to import fabric to meet new demand due to GSP+ - Felix Fernando18% duty on fish exports to be lifted under GSP+GSP+ is granted to encourage govt. towards reforms - Tung-Lai MargueNew tax revenue proposal to increase government coffers - RaviDHL is committed to enhancing its investments in SLHambantota port deal is a major plus, will benefit country - CB GovernorDerana launches Derana SME Club with IDBWe will bring in new legislation – PMSL’s first A320 touches down at BIAAll securities issued by the government are absolutely safe – CB GovernorSri Lanka spending Rs 35 billion to import milk powder - HarshaGoogle internet balloon plan hits a legal snag - HarinLAUGFS Creates History at HambantotaFinance Minister calls CB Governor a hospital attendant - VIDEOEPF can buy over all companies in Sri Lanka, says Premier – VIDEOHandunnetti questions how Perpetual Treasuries gained heavenly wisdom – VIDEOLondon Stock Exchange Group opens new technology facility in Sri Lanka - VIDEO
The requested content cannot be found
A Crisis If Economy Does Not Grow – Sujeewa Mudalige & Talal Rafi

Stock Market

Exchange Rates