The Next Attacks Will Not Break In. They Will Subvert What You Already Trust.

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005. This is about attacks aimed at the tools a business trusts to run on their own.

Malware has always chased the value, not the target

Malware’s history is a series of moves toward wherever the value actually sits. It started with simple malicious email attachments a user had to execute themselves, moved deeper into the operating system, then spread across other applications entirely. Ransomware marked a further shift: once attackers realized there was real money in the data itself, the focus moved from controlling systems to controlling what those systems hold.

None of the earlier vectors went away. Email is still one of the most common ways in, the list of operating-system infiltration methods keeps growing, and supply-chain attacks as a way around perimeter security keep increasing. The next stage builds on all of it rather than replacing any of it.

Why subverting automation is the more efficient attack

The value is in the data. So what if an attacker did not need to break through a firewall, subvert multi-factor authentication, or trick a person into doing anything that looks overtly malicious? What if they could instead commandeer tools that are already deployed, already trusted, and already running – and quietly mislead them about what they are supposed to be doing? It is social engineering aimed at software rather than people: hidden behind the scenes, unnoticed and unwatched.

There are only a few hundred automation tools in wide deployment across the corporate landscape. None of them is perfect, and every single one of them operates on externally supplied data – the exact property that makes it possible to feed one something it should never have trusted.

The concrete action, not just the warning

This is not a call to stop automating. It is a call to assess the attack surface of the automation toolchains a business already runs, the same way it would assess the attack surface of any other system that touches sensitive data. That assessment is worth doing now, while there is still time to build the practices and controls this class of attack will require, rather than after it has already found a way in.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.