Site navigation

Cyber Threat Actors are ‘Living Off The Land,’ says NCSC

Michael Edgar

,

NCSC warning
“In this new dangerous and volatile world where the frontline is increasingly online, we must protect and future proof our systems,” said deputy Prime Minister Oliver Dowden.

The National Cyber Security Centre (NCSC) has issued a warning about state-sponsored cyber-attackers hiding on critical infrastructure networks.

The warning comes in collaboration with partners from the US, Australia, Canada, and New Zealand, and sheds light on how threat actors have been exploiting built-in tools and processes within computer systems, a tactic known as ‘living off the land’, to gain persistent access while evading detection.

In response, the NCSC is urging critical infrastructure operators in the UK to implement recommended actions like implementing logging and aggregate logs in out-of-band centralised locations, use automation to continually review all logs against a baseline of network activity, and more listed in the full release

Another advisory specifically identifies China state-sponsored and Russia state-sponsored actors as among those observed utilising ‘living off the land’ techniques to infiltrate compromised critical infrastructure networks. Furthermore, it highlights the activities of China state-sponsored actor Volt Typhoon, which has been employing similar tactics to compromise critical infrastructure systems in the US.

“Earlier this week, I announced an independent review to look at cybersecurity as an enabler to build trust, resilience and unleash growth across the UK economy,” continued Dowden.

By driving up the resilience of our critical infrastructure across the UK we will defend ourselves from cyber-attackers that would do us harm.”

The new advisory and joint guidance serve as updates to previous warnings issued in May of last year, highlighting China state-sponsored activity observed against critical infrastructure networks in the US that could potentially impact networks worldwide.


Recommended reading


“It is vital that operators of UK critical infrastructure heed this warning about cyber-attackers using sophisticated techniques to hide on victims’ systems,” said Paul Chichester, NCSC director of operations.

“Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services.”

“Organisations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data