ESET Hosts 22nd International AVAR Cybersecurity Conference Spotlighting Operation Ghost APT Campaigns
What Happened — ESET organized the 22nd Annual International AVAR Cybersecurity Conference in Osaka, Japan (Nov 6‑9, 2019). The event featured 50+ expert speakers and covered topics such as financially‑targeted malware, election security, cryptocurrency threats, and the newly uncovered “Operation Ghost” campaign attributed to the Dukes APT group.
Why It Matters for Trust & Control Assurance
- Emerging APT techniques highlighted at the conference illustrate the need for continuous threat‑intelligence integration into control‑assurance programs.
- Mapping the tactics of groups like Dukes to control objectives (e.g., monitoring, incident response, and supply‑chain oversight) provides defensible evidence for audits across multiple frameworks.
- The conference’s focus on DNS security, cryptocurrency attacks, and election‑related malware underscores the importance of maintaining up‑to‑date control evidence for high‑risk vectors.
Who Is Affected – Technology vendors, financial services, government agencies, and any organization that relies on DNS, cryptocurrency services, or election‑related infrastructure.
Recommended Actions
- Incorporate the latest APT tactics (e.g., Operation Ghost) into your threat‑modeling and risk‑assessment processes.
- Map those tactics to relevant control objectives (monitoring, incident response, supply‑chain oversight) and collect continuous evidence to demonstrate readiness.
- Leverage a control‑mapping platform to maintain an up‑to‑date audit trail that satisfies multiple frameworks simultaneously.
Source: ESET press release
Technical Notes – Operation Ghost is attributed to the Dukes APT group, known for high‑value espionage campaigns. Topics discussed included financially‑targeted malware, election‑security threats, and cryptocurrency‑related attacks. No specific CVEs were disclosed. Source: same as above