Cyber recovery forensics kit configured to send return malware
Data protection including malware response operations are disclosed. When a production system is attacked, the malware is allowed to run in a forensic environment in order to learn its operational characteristics. Once learned, a return malware can be placed in the data. The return malware is transmitted to a malware host system by the malware itself and executed.
1 . A method comprising:
detecting malware in a production system;
performing a backup of the production system by a forensic engine;
recovering the backup to a forensic infrastructure as a recovered system, wherein real data of the production system is replaced with dummy data that appears real to the malware, including matching structure, naming, file types, or metadata of the original production data in the recovered system;
operating the recovered system in a live manner that emulates normal production behaviors, including user interactions, scheduled tasks, or authentication activity, thereby deceiving the malware while the malware is operating the recovered system, wherein the malware executes unmodified in the recovered system and operates naturally without operator replacement or suppression, learning operational characteristics of the malware;
placing return malware into the recovered system or the production system responsive to the learned operational characteristics of the malware, including determining, while the malware operates on the recovered system containing the dummy data, whether the malware attempts to access, modify, or transmit the dummy data, and tailoring placement of the return malware based on an observed behavior of the malware, wherein the return malware is configured to be identified by the malware as data of the recovered system and transmitted to a malware host system by the malware; and
executing the return malware in the malware host system, wherein the return malware, upon execution in the malware host system, is configured to covertly transmit a beacon or forensic telemetry indicating its execution and search the malware host system for cryptographic keys or other security credentials.
2 . The method of claim 1 , wherein the malware views the return malware as the data of the recovered system or of the production system and wherein the forensic engine is configured to emulate communications of the malware to the malware host system.
3 . The method of claim 1 , wherein the malware views the return malware as the data of the recovered system or of the production system and wherein the forensic engine is configured to emulate communications of the malware to the malware host system.
4 . The method of claim 1 , wherein the return malware operates differently from the malware.
5 . The method of claim 1 , wherein the return malware is configured to mitigate or reverse damage caused by the malware.
6 . The method of claim 1 , wherein the dummy data is prepared in advance, further comprising allowing the recovered system to operate in a live and connected manner on the dummy data.
7 . The method of claim 6 , wherein the recovered system is configured to operate like the production system.
8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:
detecting malware in a production system;
performing a backup of the production system by a forensic engine;
recovering the backup to a forensic infrastructure as a recovered system, wherein real data of the production system is replaced with dummy data that appears realto the malware, including matching structure, naming, file types, or metadata of the original production data in the recovered system;
operating the recovered system in a live manner that emulates normal production behaviors, including user interactions, scheduled tasks, or authentication activity, thereby deceiving the malware while the malware is operating the recovered system to learn operational characteristics of the malware, wherein the malware executes unmodified in the recovered system and operates naturally without operator replacement or suppression;
placing return malware into the recovered system or the production system responsive to the learned operational characteristics of the malware, including determining, while the malware operates on the recovered system containing the dummy data, whether the malware attempts to access, modify, or transmit the dummy data, and tailoring placement of the return malware based on an observed behavior of the malware, wherein the return malware is configured to be identified by the malware as data of the recovered system and transmitted to a malware host system by the malware; and
executing the return malware in the malware host system, wherein the return malware, upon execution in the malware host system, is configured to covertly transmit a beacon or forensic telemetry indicating its execution and search the malware host system for cryptographic keys or other security credentials.
9 . The non-transitory storage medium of claim 8 , wherein the malware views the return malware as data of the recovered system or of the production system.
10 . The non-transitory storage medium of claim 8 , wherein the operational characteristics include functions performed by the malware, timing of the functions, communications performed by the malware, data affected by the malware, evasion functions, or combination thereof.
11 . The non-transitory storage medium of claim 8 , wherein the forensic engine is configured to emulate communications of the malware to the malware host system.
12 . The non-transitory storage medium of claim 8 , wherein the return malware operates differently from the malware.
13 . The non-transitory storage medium of claim 8 , wherein the return malware is configured to mitigate or reverse damage caused by the malware.
14 . The non-transitory storage medium of claim 8 , further comprising allowing the recovered system to operate in a live and connected manner.
15 . The non-transitory storage medium of claim 14 , wherein the recovered system is configured to operate like the production system.
16 . A method comprising:
learning operational characteristics of multiple malware by allowing each malware to operate unmodified in a corresponding recovered system within a forensic infrastructure, wherein data of a production system is replaced with dummy data that appears real to the malware, including matching structure, naming, file types, or metadata of the original production data in each of the recovered system, wherein each recovered system emulates normal production system behavior, including simulating user interactions, scheduled processes, and authentication activity, to deceive the malware while the malware operates;
placing a return malware in a production system responsive to the learned operational characteristics of the multiple malware, including determining, while the malware operates on its corresponding recovered system containing the dummy data, whether the malware attempts to access, modify, or transmit the dummy data, and tailoring placement of the return malware based on an observed behavior of the malware, the return malware being configured such that, in an event of an attack by malware on the production system, the malware will identify the return malware as ordinary data of the production system and transmit the return malware to a malware host system; and
executing the return malware at the malware host system, wherein the return malware, upon execution on the malware host system, covertly communicates a beacon or forensic telemetry back to a designated receiver and searches for and exfiltrates cryptographic keys or other confidential data.
17 . The method of claim 16 , wherein the return malware is transmitted to the malware host system by the malware prior to detecting the malware at the production system.
18 . The method of claim 16 , further comprising altering the return malware and/or a manner in which the return malware is placed as additional operational characteristics become available.
19 . The method of claim 16 , further comprising detecting the malware and generating a snapshot of the malware, wherein the snapshot is recovered and run to learn the operational characteristics of the malware.