Ensuring Business Continuity Through Expert Incident Response and Threat Intelligence
Arcova identified and contained a cyberattack, allowing client business operations to continue uninterrupted. Deficiencies in the client's alerting and response processes were corrected, dramatically improving response time and effectiveness.
Project Information
Client: Global Industrial Company
Services: Incident Response
Areas of Expertise: Threat Intelligence, Incident Response, APT Response
Sector: Manufacturing
Challenge
Arcova's client, a global industrial company, suffered a cyberattack from a Russian state-sponsored Advanced Persistent Threat (APT) with tradecraft similar to the Threat Actor known as COZYBEAR. The attack involved unusual login events and sophisticated phishing servers, indicating a high level of threat actor sophistication. The client had no preexisting Incident Response plans, requiring real-time development and implementation of strategies.
Solution
Arcova's Cyber Fusion Center Analyst identified and contained the cyberattack by investigating closed alerts and engaging the Threat Intelligence team. The team discovered the attacker's infrastructure, including servers hosted by Russian FSB affiliates and tools popular among threat actors. The Incident Response team initiated a bridge call with representatives from the client's security leadership, architecture, IAM, finance, and legal teams, as well as major service and cloud providers, to manage the incident. They scoped, isolated, remediated, and restored normal business operations before the start of business the next morning. The team also corrected deficiencies in the client's alerting and response processes, dramatically improving response time and effectiveness.
Impact
The client was able to continue normal business operations without interruption despite the compromise by a sophisticated threat actor. The collaboration with Microsoft security and other major third-party cloud service providers not only contained and remediated the attack but also tore down a significant portion of the attacker infrastructure. The Threat Intelligence team captured key Indicators of Attack and Indicators of Compromise (IOAs/IOCs) and added them to the threat intelligence feed provided to all clients.
Key Results
Dramatic improvement in response time and effectiveness.
Uninterrupted business operations despite the cyberattack.
Significant portion of attacker infrastructure dismantled.
Key IOAs/IOCs captured and added to threat intelligence feed.
