Why Innocent Looking Facebook Photos Can Be Dangerous

BeyondTrust, July 16th, 2012

Hacker attacks are far more publicized than insider attacks. In fact, according to the 2011 CyberSecurity Watch Survey conducted by CSO Magazine and Deloitte, 70 percent of insider incidents are handled internally without legal action. This begs the question – how many of those incidents are disclosed to the public? While a majority of U.S. states have enacted security breach notification laws it hasn’t stopped some organizations from covering up insider breaches. And of even more concerning, some businesses have no idea that their intellectual property is being compromised by way of popular social media platforms.

The rapid consumerization of IT coupled with the increasingly popular use of social media platforms to increase brand visibility and socialize CRM is drastically expanding the threat landscape for enterprises. It is becoming apparent that hackers and malicious software developers are targeting social media platforms as channels to commit cybercrimes and pilfer information.

Malicious attackers have a number robust toolkits and clever methods to slip past defenses, including: emails with hidden agendas, USB drives containing malware, insider threats and now the utilization of third party social media sites with posted images, audio and video files to gain access to company networks without detection.

A recent article by Dark Reading highlights how an innocent-looking vacation picture on Facebook could conceivably traffic exfiltrated documents. According to the article, “Security researchers will unveil at Black Hat USA a new method of hiding sensitive information in the encoding of seemingly safe images shared on social media sites to avoid security mechanisms. The method employed by a new tool they developed called SNScat can not only be used to exfiltrate data off networks without detection, but to also run covert botnets through the type of social media network traffic allowed by most businesses today.”

Social media’s infiltration into the enterprise isn’t slowing down and it’s becoming critical that enterprises invest in vulnerability management, mobile device management and privilege access management to keep the pace against the dark side of innovation and malicious attackers.