Technology University Stops Information-Stealing Cyber-Attack With Darktrace AI

University Targeted by ‘PrivateLoader’, A Pay-Per-Install Malware Distribution Service

Darktrace, a global leader in cyber security AI, today announced that an African technology university stopped a recent cyber-attack using Darktrace AI. The attackers attempted to distribute PrivateLoader malware, a pay-per-install malware service commonly associated with cryptomining and IP theft.

Marketing Technology News: How Advertisers Can Take Their ID Destiny Into Their Own Hands

The public university, which has been established for over 30 years in Africa, awards students with undergraduate and graduate degrees in technology-related subjects. The university holds vast amounts of valuable IP including government-funded research into artificial intelligence, robotics, and sustainable energy solutions, which is a prime target for financially motivated cyber-criminals as well as state-sponsored attackers.

The university was targeted during a trial of Darktrace’s AI in mid-April. The AI technology had formed a unique understanding of the university’s ‘normal’ operations across its digital estate which allowed it to spot the out-of-the-ordinary activity indicative of an attack. In this case, the AI detected a desktop connecting to a rare external endpoint using a mechanism that was not consistent with their technology stack.

The IP address was subsequently tracked by Darktrace’s AI Analyst and found to be related to the pay-per-install malware service, PrivateLoader. The compromised device was then observed performing activity indicative of ‘RedLineStealer’ and ‘MarsStealer’, information-stealing malware which exfiltrate data with the intent of monetizing it through direct use or distribution on darknet sites.

Marketing Technology News: MarTech Interview with Angeley Mullins, CMO & CGO at Latana

Darktrace AI detected the attack in its earliest stages, and the threat was interrupted before any critical research or student data could be exfiltrated. After the attack was contained, a thorough investigation into the incident was conducted to ensure future cyber resilience for the university.

“PrivateLoader is an emerging malware service which has grown in popularity over the past year. It is unsurprising that attackers would target a university with this attack tool, typically used to distribute information-stealing malware which can harvest the critical data that universities hold for financial or more political purposes,” commented Toby Lewis, Darktrace’s Global Head of Threat Analysis. “By taking a number of subtle indicators from across the organization into consideration, including time of day, duration, data in and out, and peer analysis of similar devices and users, Self-Learning AI is uniquely capable of spotting these threats in their earliest stages – before critical data falls into the wrong hands.”

Marketing Technology News: MarTech Interview with Kyle Lacy, SVP of Marketing at Seismic

Picture of PRNewswire

PRNewswire

PR Newswire, a Cision company, is the premier global provider of multimedia platforms and distribution that marketers, corporate communicators, sustainability officers, public affairs and investor relations officers leverage to engage key audiences. Having pioneered the commercial news distribution industry over 60 years ago, PR Newswire today provides end-to- end solutions to produce, optimize and target content -- and then distribute and measure results. Combining the world's largest multi-channel, multi-cultural content distribution and optimization network with comprehensive workflow tools and platforms, PR Newswire powers the stories of organizations around the world. PR Newswire serves tens of thousands of clients from offices in the Americas, Europe, Middle East, Africa and Asia-Pacific regions.

You Might Also Like