Masquerading / Renaming / Trusted-Path Abuse
Malicious file/process/account е именуван или поставен така, че да прилича на legitimate component.
Какво е
Malicious file/process/account е именуван или поставен така, че да прилича на legitimate component.
Как работи
Attacker разчита на visual/operator assumptions, trusted directories, familiar names или copied icons/metadata.
Как да се предотврати
Code signing/application control, full-path/process telemetry, hash/reputation checks, protected system paths и analyst procedures, които не приемат filename-а за доказателство.
Как атаките се комбинират в реална кампания
Една от най-важните идеи в целия справочник е, че реалният инцидент не идва с етикет „днес ще бъде само phishing“. Нападателите комбинират техники според това кое работи. Следващите вериги са защитни модели, не инструкции за нападение: целта е да се види къде defender-ът може да прекъсне процеса.
Сценарий A: Ransomware intrusion
- Initial access: exploitation на Internet-facing VPN/firewall/application, stolen credentials, phishing или third-party access.
- Establish foothold: remote-access tool, web shell, valid account или malware loader.
- Credential access: infostealer, credential dumping, token/session theft.
- Privilege escalation: local/domain/cloud IAM escalation.
- Discovery и lateral movement: identity systems, file servers, virtualization, backup infrastructure.
- Data collection/exfiltration: staging и upload към attacker-controlled или abused cloud service.
- Recovery inhibition: delete snapshots/backups, stop protection/recovery services.
- Impact: mass encryption, service shutdown и/или data extortion.
Къде се прекъсва веригата: fast edge patching; phishing-resistant MFA; EDR; segmentation; PAM; network/service account controls; mass-download/exfil alerts; separate immutable backup plane; rapid host/account isolation. Mandiant отчита data theft в 77% от анализираните 2025 ransomware intrusions, което показва защо backup alone не решава extortion риска.
Сценарий B: Business Email Compromise и payment fraud
- Spear phishing/AiTM, password spraying или infostealer краде identity/session.
- Attacker чете mailbox и изучава suppliers, invoices, executives и payment timing.
- Създава forwarding/inbox rule или използва real thread.
- Изпраща request за промяна на bank account/beneficiary или „спешно“ плащане.
- Finance team изпълнява легитимна transaction към грешен получател.
Къде се прекъсва: FIDO/passkeys; sign-in/session anomaly detection; alerts за forwarding/OAuth rules; DMARC; independent callback за banking changes; dual approval и beneficiary-change controls. В този сценарий antivirus може изобщо да няма какво да „хване“.
Сценарий C: Help-desk vishing към SSO takeover
- Attacker събира employee data от OSINT/breach data.
- Обажда се на help desk и се представя за служителя.
- Опитва password/MFA reset или enrollment на нов factor.
- Влиза през SSO и достига SaaS applications.
- Създава OAuth/app/token persistence или краде/експортира cloud data.
Къде се прекъсва: strong help-desk identity proofing; no caller-ID trust; manager/device-backed verification; restrictions върху MFA re-enrollment; phishing-resistant authentication; conditional access; OAuth/app governance и bulk-export detection. Google/Mandiant наблюдава подобни voice-driven SaaS campaigns през 2025-2026.
Сценарий D: AiTM phishing и session-token theft
- Жертвата отваря lookalike login URL.
- Phishing proxy relay-ва реалния authentication flow.
- Password и обикновен MFA се приемат от истинския IdP.
- Proxy прихваща authenticated session token/cookie.
- Attacker reuse-ва session, докато token-ът е валиден, и достига mail/SaaS data.
Къде се прекъсва: origin-bound FIDO/WebAuthn/passkeys; managed-device requirements; token/session risk evaluation; device-bound token technologies където се поддържат; rapid revoke при phishing report; browser/endpoint protection.
Сценарий E: SIM swap към account takeover
- Attacker събира personal/account data.
- Social engineering или compromised carrier process прехвърля номера към attacker-controlled SIM/eSIM.
- Жертвата губи cellular service.
- Attacker получава SMS/voice recovery codes за services, които използват phone number като security factor.
- Password/recovery changes lock-ват истинския user и позволяват fraud.
Къде се прекъсва: carrier PIN/port lock; alerts за SIM/eSIM changes; no SMS като единствен strong factor; FIDO/passkeys/security keys; strong recovery process и rapid carrier/account response.
Сценарий F: Software supply-chain compromise
- Maintainer, repo, CI/CD runner, signing key, package namespace или vendor е compromised.
- Malicious code/artifact влиза в trusted build/release path.
- Customers автоматично install/update-ват trusted software.
- Malicious component получава foothold с application privileges.
- Следват credential access, cloud movement, exfiltration или downstream attacks.
Къде се прекъсва: phishing-resistant maintainer auth; branch/release protection; hermetic builds; SBOM; artifact signatures; provenance/attestation; dependency controls; isolated runners; behavior monitoring и customer-side least privilege.
Сценарий G: Public-facing web exploit към cloud compromise
- Internet-facing application има known/zero-day RCE или SSRF.
- App process е compromised.
- SSRF/process достига cloud metadata или local secret.
- Temporary workload credential се използва към cloud APIs.
- Overprivileged IAM позволява discovery, storage access или privilege escalation.
- Data се exfiltrate-ва или се създава persistence.
Къде се прекъсва: rapid edge patching/WAF compensating controls; process sandboxing; metadata hardening; workload identity с минимални rights; egress controls; IAM graph review; cloud audit/anomaly detection.
Сценарий H: Insider data theft
- Employee/contractor има legitimate access до sensitive repository.
- Извършва unusually large search/download или събира data с нормални tools.
- Upload-ва към personal cloud, personal email или removable media.
- Опитва да delete-не local evidence или просто напуска организацията.
Къде се прекъсва: need-to-know access; periodic recertification; DLP/device control; sanctioned SaaS tenant restrictions; mass-download anomaly alerts; immutable audit logs; timely offboarding и humane insider-risk process.
Сценарий I: Prompt injection към AI-agent action
- Agent чете untrusted webpage/document/email чрез retrieval/browser tool.
- Content съдържа indirect prompt injection.
- Model интерпретира част от data като instruction.
- Agent избира tool с прекомерни permissions.
- Без deterministic policy/approval се прави external или destructive action.
Къде се прекъсва: retrieved content да е untrusted data; tool least privilege; read-only default; external policy enforcement; action schemas/validation; human approval за high-impact операции; immutable audit trail.
Сценарий J: DDoS като част от по-голям incident
- Attacker изпраща volumetric/protocol/L7 traffic или заплашва с RDDoS.
- Operations екипът се фокусира върху availability кризата.
- Паралелно може да протича credential fraud, data theft или extortion negotiation.
- Ако origin/DNS/control plane не е изолиран, mitigation pressure създава secondary failures.
Къде се прекъсва: always-on upstream DDoS protection; Anycast/CDN; protected origin; resilient DNS; rate/bot controls; separate incident workstreams и проверка за concurrent identity/data events.
Източници и стандарти
Източниците по-долу са подбрани с приоритет към NIST, CISA, MITRE ATT&CK, OWASP, ENISA, FTC и актуални primary threat-intelligence публикации от Google/Mandiant, Microsoft, Verizon и други утвърдени организации. Vendor sources са използвани главно за текущо наблюдавани техники и практически разновидности, а не като единствена нормативна основа.
- ** MITRE ATT&CK, Enterprise Tactics.** https://attack.mitre.org/tactics/enterprise/
- ** MITRE ATT&CK, Phishing (T1566).** https://attack.mitre.org/techniques/T1566/
- ** OWASP Top 10:2025.** https://owasp.org/Top10/2025/0x00_2025-Introduction/
- ** NIST Cybersecurity Framework (CSF) 2.0.** https://www.nist.gov/cyberframework
- ** Verizon, 2026 Data Breach Investigations Report (DBIR).** https://www.verizon.com/business/resources/reports/dbir/
- ** NIST SP 800-63B-4, Authentication and Authenticator Management, July 2025.** https://csrc.nist.gov/pubs/sp/800/63/b/4/final
- ** CISA, Implementing Phishing-Resistant MFA.** https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- ** CISA, Phishing Infographic / counter-phishing controls.** https://www.cisa.gov/sites/default/files/2023-02/phishing-infographic-508c_0.pdf
- ** NIST SP 800-161 Rev.1 Update 1, Cybersecurity Supply Chain Risk Management Practices.** https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- ** Proofpoint, What Is Smishing?** https://www.proofpoint.com/us/threat-reference/smishing
- ** U.S. FTC, SIM Swap Scams: How to Protect Yourself.** https://consumer.ftc.gov/comment/58875
- ** Google Threat Intelligence Group, Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft.** https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft
- ** Google/Mandiant, M-Trends 2026.** https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- ** Proofpoint, What Is Quishing (QR Phishing)?** https://www.proofpoint.com/us/threat-reference/quishing
- ** Microsoft Security, Practices for Preventing Credential Theft.** https://www.microsoft.com/en-us/security/blog/2023/12/04/protecting-credentials-against-social-engineering-cyberattack-series/
- ** Microsoft Entra ID, Protect Against Consent Phishing.** https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/protect-against-consent-phishing
- ** Microsoft Security, Multi-stage phishing campaign leads to AiTM token compromise, May 2026.** https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
- ** Microsoft Incident Response, Preventing Cloud Identity Compromise.** https://www.microsoft.com/en-us/security/blog/2023/12/05/microsoft-incident-response-lessons-on-preventing-cloud-identity-compromise/
- ** Proofpoint, Around the World in 90 Days: State-Sponsored Actors Try ClickFix, April 2025.** https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix
- ** NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment, July 2025.** https://csrc.nist.gov/pubs/sp/800/63/A/4/final
- ** NIST SP 800-83 Rev.1, Guide to Malware Incident Prevention and Handling.** https://www.nist.gov/publications/guide-malware-incident-prevention-and-handling-desktops-and-laptops
- ** NIST IR 8374 Rev.1, Ransomware Risk Management: CSF 2.0 Community Profile, June 2026.** https://csrc.nist.gov/pubs/ir/8374/r1/final
- ** Google Threat Intelligence Group, Ransomware Under Pressure: TTPs in a Shifting Threat Landscape, March 2026.** https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape
- ** CISA, #StopRansomware Guide.** https://www.cisa.gov/stopransomware/ransomware-guide
- ** Google/Mandiant, Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition.** https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks/
- ** ENISA, Threat Landscape.** https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape
- ** MITRE ATT&CK, Brute Force (T1110).** https://attack.mitre.org/techniques/T1110/
- ** MITRE ATT&CK, Password Spraying (T1110.003).** https://attack.mitre.org/techniques/T1110/003/
- ** MITRE ATT&CK, Credential Stuffing (T1110.004).** https://attack.mitre.org/techniques/T1110/004/
- ** MITRE ATT&CK, OS Credential Dumping (T1003).** https://attack.mitre.org/techniques/T1003/
- ** MITRE ATT&CK, Credential Access Tactic (TA0006).** https://attack.mitre.org/tactics/TA0006/
- ** OWASP API Security Project / API Security Top 10:2023.** https://owasp.org/www-project-api-security/
- ** MITRE ATT&CK, Adversary-in-the-Middle (T1557).** https://attack.mitre.org/techniques/T1557/
- ** Cloudflare Learning Center, DNS Cache Poisoning / DNS Spoofing.** https://www.cloudflare.com/learning/dns/dns-cache-poisoning/
- ** Cloudflare Learning Center, Domain Hijacking.** https://www.cloudflare.com/learning/dns/what-is-domain-hijacking/
- ** Cloudflare Learning Center, BGP Hijacking.** https://www.cloudflare.com/learning/security/glossary/bgp-hijacking/
- ** MITRE ATT&CK, Exfiltration Over Web Service (T1567).** https://attack.mitre.org/techniques/T1567/
- ** ENISA, Threat Landscape and contemporary threat-technique coverage.** https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape
- ** Cloudflare Learning Center, What Is a DDoS Attack?** https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/
- ** Cloudflare Learning Center, How to Prevent DDoS Attacks.** https://www.cloudflare.com/learning/ddos/how-to-prevent-ddos-attacks/
- ** OWASP Mobile Top 10.** https://owasp.org/www-project-mobile-top-10/
- ** Google Cloud, Cloud Threat Horizons Report H1 2026.** https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
- ** MITRE ATT&CK, Inhibit System Recovery (T1490).** https://attack.mitre.org/techniques/T1490/
- ** OWASP Kubernetes Top Ten.** https://owasp.org/www-project-kubernetes-top-ten/
- ** NIST SP 800-161 Rev.1 Update 1, Cybersecurity Supply Chain Risk Management.** https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- ** ENISA, Threat Landscape for Supply Chain Attacks.** https://www.enisa.europa.eu/publications/threat-landscape-for-supply-chain-attacks
- ** CISA, Insider Threat Mitigation Resources and Tools.** https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/resources-and-tools
- ** NIST, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, 2025.** https://www.nist.gov/publications/adversarial-machine-learning-taxonomy-and-terminology-attacks-and-mitigations-0
- ** OWASP GenAI Security Project, Top 10 for LLM and GenAI.** https://genai.owasp.org/initiatives/top-10-for-llm-and-genai/
- ** Verizon, 2026 Data Breach Investigations Report, including GenAI-related attack observations.** https://www.verizon.com/business/resources/reports/dbir/
Допълнителни основни reference frameworks
Следните ресурси са полезни за operationalizing на защитата, макар да не са цитирани при всяко отделно определение:
- MITRE ATT&CK Enterprise Matrix: https://attack.mitre.org/matrices/enterprise/
- CISA Cybersecurity Performance Goals (CPGs): https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
- CISA Known Exploited Vulnerabilities (KEV) Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NIST National Vulnerability Database (NVD): https://nvd.nist.gov/
- OWASP Cheat Sheet Series: https://cheatsheetseries.owasp.org/
- OWASP Web Security Testing Guide: https://owasp.org/www-project-web-security-testing-guide/
- OWASP ASVS: https://owasp.org/www-project-application-security-verification-standard/
- CIS Critical Security Controls: https://www.cisecurity.org/controls
- FIRST CVSS: https://www.first.org/cvss/
Заключение
Най-полезният начин да се мисли за кибератаките не е като списък от 385 независими чудовища, а като повтарящи се attack primitives:
- измама на човек или процес;
- кражба/злоупотреба с identity;
- exploitation на software или configuration;
- придобиване на execution/persistence;
- повишаване на privileges;
- movement между trust zones;
- collection/exfiltration;
- disruption, manipulation, encryption или destruction.
Организация, която контролира identity, privileges, software exposure, segmentation, data access, egress, recovery и telemetry, прекъсва много различни атаки с едни и същи фундаментални safeguards. Това е по-надеждно от закупуването на отделен „AI-powered next-generation“ продукт за всяка нова дума, която marketing отделът е открил тази седмица.
Най-ефективни защити
Подредени по приоритет — P0 е мястото, от което се започва.
Кой предлага защита в България
Услугите от директорията, които намаляват този риск — с броя компании, които ги предлагат.
Източници
- MITRE ATT&CK, Enterprise Tactics.
- MITRE ATT&CK, Phishing (T1566).
- OWASP Top 10:2025.
- NIST Cybersecurity Framework (CSF) 2.0.
- Verizon, 2026 Data Breach Investigations Report (DBIR).
- NIST SP 800-63B-4, Authentication and Authenticator Management, July 2025.
- CISA, Implementing Phishing-Resistant MFA.
- CISA, Phishing Infographic / counter-phishing controls.
- NIST SP 800-161 Rev.1 Update 1, Cybersecurity Supply Chain Risk Management Practices.
- Proofpoint, What Is Smishing?
- U.S. FTC, SIM Swap Scams: How to Protect Yourself.
- Google Threat Intelligence Group, Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft.
- Google/Mandiant, M-Trends 2026.
- Proofpoint, What Is Quishing (QR Phishing)?
- Microsoft Security, Practices for Preventing Credential Theft.
- Microsoft Entra ID, Protect Against Consent Phishing.
- Microsoft Security, Multi-stage phishing campaign leads to AiTM token compromise, May 2026.
- Microsoft Incident Response, Preventing Cloud Identity Compromise.
- Proofpoint, Around the World in 90 Days: State-Sponsored Actors Try ClickFix, April 2025.
- NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment, July 2025.
- NIST SP 800-83 Rev.1, Guide to Malware Incident Prevention and Handling.
- NIST IR 8374 Rev.1, Ransomware Risk Management: CSF 2.0 Community Profile, June 2026.
- Google Threat Intelligence Group, Ransomware Under Pressure: TTPs in a Shifting Threat Landscape, March 2026.
- CISA, #StopRansomware Guide.
- Google/Mandiant, Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition.
- ENISA, Threat Landscape.
- MITRE ATT&CK, Brute Force (T1110).
- MITRE ATT&CK, Password Spraying (T1110.003).
- MITRE ATT&CK, Credential Stuffing (T1110.004).
- MITRE ATT&CK, OS Credential Dumping (T1003).
- MITRE ATT&CK, Credential Access Tactic (TA0006).
- OWASP API Security Project / API Security Top 10:2023.
- MITRE ATT&CK, Adversary-in-the-Middle (T1557).
- Cloudflare Learning Center, DNS Cache Poisoning / DNS Spoofing.
- Cloudflare Learning Center, Domain Hijacking.
- Cloudflare Learning Center, BGP Hijacking.
- MITRE ATT&CK, Exfiltration Over Web Service (T1567).
- ENISA, Threat Landscape and contemporary threat-technique coverage.
- Cloudflare Learning Center, What Is a DDoS Attack?
- Cloudflare Learning Center, How to Prevent DDoS Attacks.
- OWASP Mobile Top 10.
- Google Cloud, Cloud Threat Horizons Report H1 2026.
- MITRE ATT&CK, Inhibit System Recovery (T1490).
- OWASP Kubernetes Top Ten.
- NIST SP 800-161 Rev.1 Update 1, Cybersecurity Supply Chain Risk Management.
- ENISA, Threat Landscape for Supply Chain Attacks.
- CISA, Insider Threat Mitigation Resources and Tools.
- NIST, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, 2025.
- OWASP GenAI Security Project, Top 10 for LLM and GenAI.
- Verizon, 2026 Data Breach Investigations Report, including GenAI-related attack observations.