Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What’s the Endgame for Enterprise Data Security?
Articles

What’s the Endgame for Enterprise Data Security?

ISBuzz TeamBy ISBuzz TeamOctober 19, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security
security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The highly publicised recent hack of the Hacking Team, the company that provides spyware and surveillance technology to governments and law enforcement agencies, has put the issue of malware detection into the spotlight.

Widely criticised by privacy advocates for providing spyware to governments with poor human rights records, in July the Hacking Team itself became a target when unknown hackers spirited away 400 GB of data. The leaked cache of files included details of client dealings and the working source code of the company’s Remote Control Software (RCS) snooping tool.

This should represent a major red light for enterprise security professionals across the globe. Publication of the RCS source code puts it directly into the hands of professional hackers everywhere, potentially unleashing an explosion of backdoor advanced cyber-threats

Evaluating data from the Hacking Team breach does, however, provide a fascinating glimpse into the world of professional hackers. From the nuts and bolts of attack vectors to the technical infrastructure of the RCS spying tool itself, there are some key learning points enterprise security professionals should take away from the Hacking Team incident.

Anyone can be a victim of cyber attack – even ‘professional hackers’

If your data is valuable to you, chances are it will be of interest to someone else. Witness how the Hacking Team, purportedly a state-of-the-art professional hacking company, itself became the victim of determined and highly motivated hackers.

The way the breach was engineered is still not known. But similar attacks indicate what the likely entry point was: an employee that clicked on something they shouldn’t have; poor practice in relation to passwords; exploitation of a system vulnerability following the failure to apply a patch.

Clearly, securing the enterprise requires determined 24 x 7 real time monitoring and the rigorous application of numerous protocols. However, employees, partners and customers may not be so vigilant or security aware – and that risks opening the door to wider scale enterprise data compromise.

The Hacking Team’s methodology – a lesson for hackers everywhere

Using Hacking Team’s controversial RCS spyware tool, it’s possible to monitor the communications of internet users, download and decipher encrypted files and emails, intercept Skype and other VoIP communications, and even remotely activate microphones and cameras on target computers. All that source code is readily available on the web.

Perhaps the most valuable information to come out of the RCS code leak was the existence of multiple zero-day vulnerabilities in commonly used applications like Adobe Flash player, iOS, and Internet Explorer.

But while vendors like Microsoft and Adobe may have issued patches for leaked vulnerabilities, the Hacking Team’s internal secrets are now out in the open for others to evolve, modify and augment. Detection using traditional anti-virus technology will be pretty challenging from this point forward.

Worryingly, analysis of Facebook and Twitter page structures indicates these were often used to elicit interactions with malicious content. In other words, infections were often engineered by getting targets to click on a link or open an application or file.

It’s easy to be compromised – discovering the breach isn’t

Hacking Team invested significant time and resources to ensure targets remained unaware they had been compromised. The RCS tool contained multiple mechanisms to ensure potential targets were infected specifically – and once only. The infection server checked and evaluated the operating system, browser and visiting IP address parameters in order to determine whether or not to infect a target.

And when it came to covering tracks, the Hacking Team’s malware infrastructure was designed to utilise multiple anonymiser IP addresses acting as ‘collectors’ that fed back to a control server.

In other words, this malware represented an advanced and persistent threat that contained payloads for Android, Blackberry, Apple iOS, Linus, Mac OS X, Symbian as well as Microsoft Windows, Windows Mobile and Windows Phone class of operating systems.

Detecting data espionage – applying the lessons learned

The RedSocks Malware Intelligence Team has already been able to reverse engineer binaries within the leaked Hacking Team code and perform search queries that enable users of our Malware Threat Defender solution to identify if they’ve been a victim of this malware in the past.

What’s more, we’ve also been able to share data in the STiX format (Structured Threat Information Expression) with the wider security community that identifies which global IP addresses were used as ‘collectors’.

But this is a lesson for everyone responsible for the integrity of enterprise data. Malware of this nature is covert and designed to bypass and evade detection by firewalls and anti-virus software. Passing unnoticed into the enterprise utilising vulnerabilities in browsers, apps and operating systems – it awaits instructions to steal data.

Most enterprises will never suspect a thing, unless they are constantly monitoring the network for those little telltale ‘handshakes’ that occur the moment the malware ‘phones home’. And that’s the greatest lesson we can all learn from the Hacking Team hack.[su_box title=”About Ricky Gevers” style=”noise” box_color=”#336588″]Ricky GeversRickey Gevers is a security practitioner, researcher and consultant since 2004 . He has been actively involved in Anti-Malware defense and research since 1999 at both a corporate and international level.Gevers has research interests in malware automation and analysis, application security, secure software design and cybercrime. Education: He holds a bachelor degree in Computer Science and Specialized in Forensics, Incident Response, Reverse Engineering, Pentesting.

Companies he worked with: Internship at NFI -Netherlands Forensic Institute, Digital Investigation, currently employed at RedSocks.

He has contributed to the book: “Komt een vrouw bij de hacker” by Maria Genova. ( “A woman comes to the hacker” ), a book about identity thefts in the practice and he is actively involved in speaking at various security conferences in the Netherlands. His primary effort is to present new research ideas and and design flaws in software. “I sincerely believe in learning and sharing knowledge among security community.”[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}