Axios Codebook

January 06, 2023
๐ TGIF, everyone! Welcome back to Codebook.
- The first week back after the holidays always feels like a long slog (especially if you work on Capitol Hill ๐). But don't worry, at least it's Friday now.
- ๐ฌ Have thoughts, feedback or scoops to share? [email protected]
Today's newsletter is 1,405 words, a 5.5-minute read.
1 big thing: Braving the zero-trust future
Illustration: Shoshana Gordon/Axios
A security practice that few know how to define will take up a lot of the federal government's and the private sector's attention this year: zero-trust architecture.
The big picture: Federal agencies are racing to meet a September 2024 deadline to transition to it โ and companies are looking to the government for guidance on what an esoteric zero-trust framework actually looks like.
How it works: "Zero trust" refers to a combination of security principles that can take several forms. Simply put, the idea focuses on limiting employees' internal access to the documents and files they need for their jobs.
- To do this, organizations audit what classified information is stored online, which employees and third-party digital tools have access to that info, and what additional security layers are needed to keep hackers out.
- One common zero-trust practice is multifactor authentication (MFA), where users input a code to further verify their identity beyond an easy-to-steal password.
Why it matters: Security experts have long held a zero-trust framework as the gold standard for organizations since it would minimize the impact a hacker with a stolen employee password could have.
- Many of the most notable security incidents, including the 2021 Colonial Pipeline ransomware attack, stem from hackers obtaining one stolen password to break in.
Catch up quick: The White House ordered all civilian government agencies last year to establish and implement a zero-trust plan by the end of September 2024 under the administration's zero-trust strategy.
- The plans must include adoption of a "phishing-resistant" form of MFA, maintain inventories of digital assets, and segment individual networks from other agencies.
Details: Cybersecurity consultants and lobbyists tell Axios that most of the zero-trust conversation this year will focus on the White House's ability to aid federal agencies in their mandated transitions.
- This year's appropriations and budgeting cycle is the last opportunity to ensure federal agencies have the funds they need to meet the 2024 deadline.
- In the private sector, companies are eyeing the government's approach for clear standards on what should be included in a zero-trust framework, Matt Gorham, leader of PwC's Cyber & Privacy Innovation Institute, tells Axios.
Between the lines: Federal CISO Chris DeRusha tells Axios his office is helping agencies overcome a handful of hurdles in their transitions, including modernizing their technology so it's capable of supporting things like MFA and finding talent to help assist in the transition.
- "The hurdles here are similar to hurdles we've experienced in decades in modernizing federal IT," DeRusha tells Axios.
- Matt Keller, vice president of federal services at GuidePoint Security, tells Axios that some agencies are "a little bit behind the curve" and still working on documenting their assets โ the first step in determining what zero-trust would look like for their offices.
The intrigue: The private sector has been leading the way in adopting zero-trust ideas โ providing valuable insights that the public sector can learn from.
- 36% of CISOs said in a recent PwC survey that they had already started implementing zero-trust components, while 25% said their organizations would start doing so in the next two years.
Yes, but: Zero trust isn't a total silver bullet for securing a company.
- This framework protects a network only if a hacker gets in through accessing an employee's accounts, which many sophisticated attacks don't need to be successful.
2. LockBit's not-so-great, very busy month
Illustration: Aรฏda Amer/Axios
One of the most prolific ransomware gangs of 2022 is already making headlines in the new year for successfully attacking critical infrastructure around the world.
Driving the news: In the last month, the ransomware gang has claimed responsibility for attacks on hospitals, shipping ports and local government offices.
- LockBit said on New Year's Eve that it was behind an ongoing cyberattack on the Housing Authority of the City of Los Angeles.
- LockBit also claimed responsibility for a Christmas Day ransomware attack on the Port of Lisbon.
- And LockBit ransomware was behind a cyberattack at the Toronto-based Hospital for Sick Children.
Why it matters: LockBit's continued success underscores the pervasive threat ransomware still poses despite years of government and industry investments to fight this type of cyberattack.
The big picture: The recent attacks add to a growing list of high-profile LockBit targets, including the 2021 attack on Accenture.
The intrigue: Part of LockBit's continued dominance in the ransomware underworld stems from its incentives program, according to researchers at Trustwave's SpiderLabs.
- The gang offers higher-than-average payouts to hackers who conduct attacks and operate a first-of-its-kind bug bounty program where hackers can report security vulnerabilities in company networks for a payout.
- LockBit is also constantly purchasing new hacking tools on the dark web to stay ahead of the curve, Trustwave researchers noted.
Between the lines: Trustwave forecasted in a report this week that LockBit would "remain the most active and effective group for the foreseeable future."
Yes, but: Law enforcement agents are already investigating LockBit, and officials have had a strong track record in the last couple of years of spooking and shutting down prolific gangs.
- Prosecutors charged a dual Russian and Canadian national in November with working with LockBit.
- Deputy attorney general Lisa Monaco said at the time the arrest was the result of a more than 2.5-year investigation into LockBit.
3. New hackers using old tricks in Ukraine
Illustration: Sarah Grillo/Axios
A Russian cyber espionage group is suspected of repurposing another malware campaign's old infrastructure to spy on a Ukrainian computer network.
Driving the news: Researchers at Google-owned Mandiant recently discovered an espionage campaign where Turla Team, a Russian government-linked cyber espionage group, is suspected of re-registering domain names used nine years ago in a previously unconnected attack to spread a banking trojan malware via infected USB drives.
- Some of the infected computers were on a Ukrainian network onto which the new hackers later installed additional malware and backdoors.
The big picture: The campaign highlights an evolution in Russian state-sponsored hackers' tactics, allowing them to rely on others' leftovers to remain undetected on victim networks.
- Russian government hackers are known to test out new tricks in Ukraine.
What they're saying: "Now they are taking advantage of another actorโs work by taking over their command and control," John Hultquist, head of threat intelligence at Mandiant, said in a statement.
Details: Mandiant researchers first stumbled upon the campaign in September while investigating a breach on an unnamed Ukrainian computer network.
- Researchers concluded that the hackers re-registered an old domain name in January 2022 and spent a few months combing through infected devices to determine which victims they now had access to.
- From there, the new hackers installed two new malware strains that Turla Team is known to have used in past campaigns onto selected Ukrainian computers.
- In total, Turla is suspected of re-registering three domain names linked to hundreds of device infections.
Between the lines: Mandiant observed the group downloading Turla-connected malware onto only a single network โ the Ukrainian one โ "suggesting a high level of specificity in choosing which victims received a follow-on payload," per the report.
The intrigue: This is the first time Mandiant has spotted Turla targeting Ukrainian organizations since the Russian invasion in February.
- However, Turla has practiced a similar disguise before: In 2019, British intelligence warned that the group was using Iranian hackers' servers to masquerade attacks on dozens of countries.
4. Catch up quick
@ D.C.
๐ President Joe Biden is expected to sign the new national cybersecurity strategy in the coming weeks, according to senior administration officials. (Washington Post)
๐ฒ TikTok has stopped a hiring process for consultants that would help implement a new government security deal amid ongoing opposition from U.S. officials. (Reuters)
๐ฐ European regulators fined Meta more than $400 million for violating its privacy laws through its targeted ad practices. (Axios)
@ Industry
๐ฆ Ex-Twitter security chief and whistleblower Peiter "Mudge" Zatko has joined Rapid7 as an executive-in-residence. (Washington Post)
๐ธ CISOs are preparing to do more with fewer resources and financing this year. (Wall Street Journal)
@ Hackers and hacks
๐ Chinese researchers are claiming they can already use quantum computers to crack the most commonly used encryption scheme. (Financial Times)
๐พ Email hosting service Rackspace has confirmed that the Play ransomware gang was behind November's security incident. (Rackspace)
๐ช Cybercriminals stole $3.7 billion in crypto assets in 2022 during hacks, per a recent report. (CyberScoop)
5. 1 fun thing
I'm currently on a quest to read more cyber nonfiction books โ and naturally I'm now swimming in library holds that are all ready for pickup at the same exact time.
- Nonetheless, I'm still looking for recommendations. Have one? I'd love to hear it.
โ๏ธ See y'all on Tuesday!
Thanks to Peter Allen Clark for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.


