Darktrace AI Prevents Real-time Thread Hijacking Attack

In a notable cybersecurity triumph, Darktrace's artificial intelligence technology successfully detected and thwarted a sophisticated thread hijacking attack aimed at compromising email accounts and stealing data. The incident underscores the growing prevalence of such stealthy cyber intrusions, which exploit the trust within ongoing email conversations to perpetrate data theft.

The cybersecurity landscape has witnessed an increase in thread hijacking attacks, a tactic where attackers infiltrate and manipulate existing email threads. By doing so, they gain the trust of the participants and can surreptitiously redirect communications to achieve nefarious objectives. This form of cyberattack is challenging to detect with conventional security systems, making it particularly dangerous.

The Incident

The recent attack targeted a major company, with the attacker gaining initial access to a user’s email account. Potential methods of entry include phishing, deploying malware, or exploiting weak passwords. Once inside, the attacker monitored ongoing email threads, searching for opportunities to exploit. Upon identifying a vulnerable conversation, they inserted themselves into the thread, making the email appear as a legitimate continuation from a trusted source.

To avoid detection, the attacker created a hidden email rule that diverted messages away from the intended recipient into an archive folder. This tactic ensured that the genuine account holder remained unaware of the malicious activities, as the malicious emails or responses would be sent to a rarely opened folder.

Darktrace’s Intervention

Darktrace’s self-learning AI identified an anomaly related to a suspiciously named mailbox rule, prompting its RESPOND tool to act. On August 8, 2024, the AI detected the creation of a rule labelled with a solitary period (“.”), which deviated from typical naming conventions. Realising the potential threat, the RESPOND tool swiftly disabled the compromised SaaS (Software-as-a-Service) user account for 24 hours to halt any further malicious activities.

In addition, Darktrace issued a Proactive Threat Notification to its Security Operations Centre (SOC) team. This allowed for a detailed investigation of the incident and timely communication with the affected company.

Expert Commentary

A spokesperson from Darktrace highlighted the attackers’ evasion technique, noting its effectiveness in moving malicious emails to obscure folders to avoid quick discovery by the genuine user. “This evasion technique is typically used to move any malicious emails or responses to a rarely opened folder, ensuring that the genuine account holder does not see replies to phishing emails or other malicious messages sent by attackers,” the company stated.

Darktrace’s intervention not only thwarted the immediate threat but demonstrated the critical importance of advanced AI-driven threat detection and response systems. Such tools are indispensable for organisations seeking to defend against increasingly sophisticated cyberattacks.

The incident is a testament to the capabilities of Darktrace’s technology in protecting digital communication channels. It also serves as a crucial reminder of the evolving tactics used by cybercriminals and the need for robust, proactive security measures in safeguarding sensitive information.

Source: Noah Wire Services