Find out how cyberattacks are carried out against companies

ciberataques a empresas

Table of Contents

Cyberattacks on Businesses

In this post, we’ll show you some of the cyberattack methods used by organized groups to break into company systems to steal information—among other things—and then demand a ransom.

Some of these methods have been identified by the Threat Hunting team at BlackArrow, an organization that provides offensive and defensive services through Tarlogic Security.

This division is a leader in cybersecurity in Europe. It has offices in Santiago de Compostela and Madrid and has recruited about a hundred experts in this field.

Hace unas semanas, un equipo de cazadores de esta división, presentó un informe recapitulando los vectores principales de intrusión que se han detectado en empresas durante el 2022.

Essentially, they conducted an investigation focused on identifying potential cyberattack threats to businesses.

BlackArrow experts identified three methods used by cybercriminals to gain access to organizations' systems and carry out cyberattacks.
These techniques, once hidden, have become a trend in 2022. They infiltrate systems through ISO and LNK files and also target the supply chain. Here’s how it works.

Cyberattacks on businesses via ISO files

Hacker utilizando el virus informático para el ataque cibernético

Este es uno de los métodos observados durante la investigación. Los cibercriminales envían archivos ISO a través de Google Drive.
Estos en apariencia son legítimos, pero en realidad son el inicio de ciberataque a una empresa.

Se dirige particularmente, a lograr el control de los sistemas lo que resulta crítico, sobre todo, si el sistema tiene capas defensivas vulnerables.
El ciberataque a una empresa por este método se ejecuta así:

Cualquier empleado recibe el archivo ISO, en su correo electrónico, compartido desde Google Drive. Cuando el documento se ejecuta automáticamente se monta e inicia toda una serie de métodos dirigidos a la ejecución de códigos maliciosos.
Estos pueden pasar a otros ordenadores de la empresa a través del equipo de ese empleado. Si lo logra, el ciberataque a esa empresa puede dejar daños críticos.

LNK Files: Another Method of Cyberattacks on Businesses

These are shortcuts that Windows uses to point to an original executable file.
With this method, as with the previous one, cybercriminals use LNK files that appear legitimate but execute malicious code. The goal is to advance the intrusion sequence.

In this case, the code is executed as follows:
An employee may receive the LNK file via email, or from a storage device or USB drive. When the employee opens the link, the malicious activity created by the cyberattacker is executed.

Attack via the supply chain

This method of cyberattack targeting a specific company has gained popularity in 2022. It is an intrusion vector known as a supply chain attack.

This means that the attack’s objectives include compromising suppliers and using them as a gateway to compromise customers.
In this case, the attackers’ goal is to target the larger organization by weakening the smallest link in the chain. In many cases, suppliers are more vulnerable to cyberattacks, so attackers see a clear path to the systems of larger companies.
All of this research has led BlackArrow experts to share some critical security tips to help today’s businesses prevent cyberattacks.

Soldados de las Fuerzas Especiales de Ciberseguridad totalmente armados
It is not enough to address vulnerabilities; we must also address potential threats.

Organizations are advised to invest in threat hunting services to protect their systems from attackers.
They also recommend strengthening cybersecurity by placing greater emphasis on how attackers operate.