PR Newswire
04 Oct 2022, 20 GMT+10
Analysis of the cyber threat landscape from the Secureworks Counter Threat Unit highlights key shifts in the tools and behaviors of adversaries across the world
ATLANTA, Oct. 4, 2022 /PRNewswire/ -- Secureworks (NASDAQ:SCWX), published its annual State of the Threat Report today, revealing that the exploitation in remote services has become the primary initial access vector (IAV) in ransomware attacks over the past year, accounting for 52% of ransomware incidents analyzed by Secureworks over the period (overtaking credentials-based attacks from 2021). Alongside this, there has also been a 150% rise in the use of infostealers, making them a key precursor to ransomware. Both these factors keep ransomware the primary threat for organizations, who must fight to stay abreast of the demands of new vulnerability prioritization and patching.
The 2022 State of the Threat Report from Secureworks provides an overview of how the global cybersecurity threat landscape has evolved over the last 12 months, with a focus on the Secureworks Counter Threat Unit's (CTU) first hand observations of threat actor tooling and behaviors.
"We conduct thousands of incident response engagements every year. While ransomware remains the most prominent threat to businesses, we are tracking notable shifts in threat actor behaviors and their approach to campaigns. It's too simple to claim that ransomware as a service is slowing. Our research clearly shows a rise in Infostealers use and an evolution of tools and adversaries. The threat is changing, but it is not going away," states Barry Hensley, chief threat intelligence officer, Secureworks. "It's critical for organizations to stay ahead of the adversary with solutions that effectively prioritize risk, based on the most up-to-date intelligence. When businesses understand the nature of the threat, they can better focus resources and move quickly to optimize response."
Highlights from the Report Include:
The Onward March of Ransomware
Ransomware continues to remain the primary threat facing organizations accounting for more than a quarter of all attacks. Despite a series of high-profile law enforcement interventions and public leaks, and a small slow down over the summer months, ransomware operators have maintained high levels of activity.
The median detection window in 2022 is four and a half days, compared to five days in 2021. The mean dwell time in 2021 was 22 days but so far in 2022 is down at 11 days. Companies effectively have one working week to respond to and mitigate damage.
The number of victims listed on public "Name and Shame" sites continues to remain high with no year-over-year reduction. Despite some monthly fluctuations, the number of victims named in the first six months of 2022 is slightly higher at 1,307 than the 1,170 named in the first six months of 2021.
This year's Biggest Offenders based on Secureworks' incident response engagements are GOLD MYSTIC, GOLD BLAZER, GOLD MATADOR and GOLD HAWTHORNE. Notably, all of these groups are tied to Russia.
In some instances, the adversaries are making use of the fear surrounding ransomware to undertake lower tech crimes. Hack and leak operations where data is stolen and a ransom is demanded but no ransomware is deployed continued into 2022, with GOLD TOMAHAWK and GOLD RAINFOREST among the top culprits.
Vulnerabilities in Remote Services become the Biggest Issue
The 2022 State of the Threat Report from Secureworks also highlights that exploitation of vulnerabilities in internet-facing systems has become the most common initial access vector (IAV) observed. This is a change from 2021, when the dominant IAV was the use of stolen or guessed credentials.
As new vulnerabilities are discovered, developers of widely available offensive security tools used by threat actors are quick to incorporate new vulnerabilities into their tools, often meaning that even less sophisticated threat actors are able to exploit new vulnerabilities before security teams can patch.
The Rise of Infostealers
CTU researchers have seen an increase in the sale of network access sourced from credentials acquired by information stealers. In a single day in June 2022, CTU researchers observed over 2.2 million credentials obtained by Infostealers available for sale on just one underground marketplace; last year this figure on the same market with respect to the same stealers was 878,429. That's an increase year on year of over 150%.
The three main stealer markets include: Genesis Market, Russian Market and 2easy. There is a plethora of stealers for sale on underground forums but some of the major ones include Redline, Vidar, Raccoon, Taurus, and AZORult.
Infostealers provide the means to quickly and easily obtain credentials that can be used for initial access, making them a major enabler of ransomware operations. Innovative distribution methods for Infostealers have included cloned websites and trojanized installers for messaging apps such as Signal.
A Change in the Loader Landscape
Between July 2021 and June 2022, two big names in the loader landscape disappeared (Trickbot and IceID) and two returned (Emotet and Quakbot). This indicates that groups are moving away from the complex, fully featured botnets that evolved from the early banking trojans towards more lightweight loaders that are easier to develop and maintain - a trend that has only increased with the use of post-exploitation tools such as Cobalt Strike.
Understanding the Nation-state Threat
The Secureworks CTU has tracked several significant activities which can be attributed to nation-state sponsored threat groups, including their motivations, behaviors and tactics
State of the Threat 2022
The Secureworks CTU 2022 State of the Threat Report can be read in full here: https://www.secureworks.com/resources/rp-state-of-the-threat-2022
About Secureworks
Secureworks (NASDAQ: SCWX) is a global cybersecurity leader that protects customer progress with Secureworks Taegis, a cloud-native security analytics platform built on 20+ years of real-world threat intelligence and research, improving customers' ability to detect advanced threats, streamline and collaborate on investigations, and automate the right actions.
Connect with Secureworks via Twitter, LinkedIn and Facebook and
Read the Secureworks Blog
SOURCE Secureworks, Inc.
Get a daily dose of Sydney Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Sydney Sun.
More InformationCAMP HILL, Pennsylvania: This week, the Wall Street Journal (WSJ) reported that Rite Aid could shut down some 400 to ...
WASHINGTON D.C.: U.S. Transportation Secretary Pete Buttigieg has criticized the air traffic control staffing shortages in New York as "unacceptable" ...
BURBANK, California: A note by Needham media analyst Laura Martin released this week revealed that CEO Bob Iger told investors ...
TOKYO, Japan: This week, Toshiba revealed that a tender offer worth US$14 billion from Japan Industrial Partners (JIP) was a ...
HANOI, Vietnam: While the European Union (EU) is set to impose tariffs on its Chinese rivals, Vietnamese electric vehicle (EV) ...
BEIJING, China: In a country where weddings are traditionally grand and expensive events, China's wedding industry, estimated at some US$500 ...
Washington, D.C.: This week, the U.S. Court of Appeals for the Federal Circuit suspended 96-year-old Judge Pauline Newman from hearing ...
NEW YORK: On Tuesday, former U.S. Congressman Stephen Buyer was sentenced to 22 months in prison for trading on inside ...
NEW YORK: This week, the Virginia-based Students for Fair Admissions, founded by affirmative action opponent Edward Blum, sued the U.S. ...
LONDON, U.K.: Jet engine maker CFM International said this week that thousands of engine components may have been sold with ...
BATAM, Indonesia: Due to mounting geopolitical tensions and protests against China's activities in the South China Sea, ASEAN member nations ...
FREMONT, California: This week, brain-chip startup Neuralink, owned by billionaire Tesla CEO Elon Musk, said an independent review board granted ...