What we do
At McAfee Labs Advanced Threat Research (ATR), our goal is to identify and illuminate a broad spectrum of threats in today's complex and constantly evolving landscape. Our best-of-breed research team leverages a wide range of unique skills to address this challenge. ATR researchers are responsible for leading-edge research in nearly every vertical of threat, including those targeting specific industries such as banking, retail, medical, automotive, industrial controls, and more. We have experts in vulnerability and threat research who find and report critical vulnerabilities in the world's most ubiquitous hardware and software and who leverage a global network of endpoints to track malware campaigns as well as the nation-states and malicious actors behind them. These findings are fed back into the solutions that ultimately power McAfee’s products.
McAfee Unveils New Advanced Threat Research Lab
The new Advanced Threat Research Lab provides our researchers access to state-of-the-art hardware and equipment targeting the discovery, exploitation, and responsible disclosure of critical vulnerabilities. The lab also showcases working demos of current or recently completed research projects, such as attacks against medical devices, automobiles, internet of things (IoT) devices, industrial control systems, and more.Watch Now
This edition highlights the significant investigative research and trends in threats statistics and observations in the threat landscape gathered by the McAfee Advanced Threat Research and McAfee Labs teams in Q1 2019.Read Report >
McAfee ATR recently investigated a major building controller, discovering a critical, zero-day vulnerability which, if exploited, could allow malicious actors complete control of the operating system.Read Blog >
McAfee ATR recently investigated the Avaya 9600 series IP desk phone, uncovering a remote code execution (RCE) vulnerability which, if exploited, would allow an attacker to take over normal operation of the phone, enable the internal microphone, and export audio over the network.Read Blog >
McAfee ATR explains the technical details on how this new ransomware family works.Read Blog >
McAfee ATR shares actionable insights to secure Remote Desktop Protocol (RDP).Read Blog >
McAfee ATR aids the Dutch National High-Tech Crime Unit (NHTCU) to arrest an individual suspected of building and selling a criminal toolkit named the Rubella Macro Builder.Read Blog >
The ATR team continually conducts leading-edge research into the threats that impact a variety of industries. Below are a few of the key areas we are currently focused on. They will be updated as new research is released.
Autonomous and connected vehicles demonstrate a nascent but rapidly growing target for threat actors. Vehicle-to-X (V2X) communication—with vehicles connecting to each other, surrounding infrastructure, pedestrians, the cloud, and personal devices—provides many new capabilities and new security responsibilities. ATR investigates the attack surfaces in autonomous vehicles as well as the machine learning algorithms and physical-to-digital attacks related to them.
Multiple threats and attacks over the past few years have proven that industrial control systems are a growing target for malicious actors with numerous potentially dangerous outcomes. ATR is currently investigating multiple areas of SCADA and ICS implementations, including human machine interface (HMI) software, programmable logic controllers (PLCs), and network protocols common to this vertical, such as MODBUS, ICCP, DNP3, and others.
The digital transformation in the healthcare industry is truly unlike any other industry. The rapid advancement and innovation—from medical devices and surgical advances to patient management and care—brings new opportunities that can help improve lives, but potential security issues can literally have life and death implications. Our research explores medical devices, networks, protocols, and security practices within the industry to help healthcare organizations continue to innovate securely.
In this internet of things (IoT) world where just about everything is talking to something, the secure transmission of data is critical. If basic encryption and authentication are not used, protocols such as wireless networking, Bluetooth, baseband, broadband, and radio can be sniffed, reverse engineered, and potentially compromised. Our research looks at radio frequency, including near-field-communications (NFC and RFID), and wireless transmissions to determine potential impacts to network and proximity devices.
Enterprise software has long been a rich target for malicious actors due to the attractive return on investment for discovering vulnerabilities. When a single flaw in Windows, for example, can affect millions of users, it will quickly be leveraged in exploit kits, phishing attempts, watering hole attacks, and much more. By discovering and disclosing these critical vulnerabilities in the world’s most popular software, the Advanced Threat Research team continuously reduces the overall attack surface for one of the most attractive targets for cybercriminals.
With the ever-expanding market for smart homes and home-automation devices, consumer electronics are a growing target for threat actors. Many of these products have little to no security, yet we allow them in our homes or even businesses without thinking twice. The Advanced Threat Research team searches for vulnerabilities in these devices to identify threats and guide manufacturers toward more secure products, reducing the potential for attackers to gain access to home or business networks. Our efforts focus on researching upcoming “smart” products as well as devices that are already deployed in these environments.