Time to Deploy Ransomware Drops 94%

According to IBM, attackers have significantly accelerated the deployment of ransomware in recent years, from an average of over 60 days per attack in 2019 to less than four days per attack in 2021.

company year X-Force Threat Intelligence Index was compiled from billions of data points collected from network and endpoint devices, incident response engagements, vulnerability and exploit databases, and more in 2022.

While ransomware’s share of incidents has fallen from 21% in 2021 to 17% in 2022, attackers are striking faster than ever, with more 94% reduction in average time to deploy software.

“One particularly pernicious way ransomware operators distribute payloads on networks is by compromising domain controllers. It uncovered entities that had misconfigurations in Active Directory that could expose them to privilege escalation and domain-wide takeover,” the report explains.

“In 2022, X-Force also observed more aggressive ransomware attacks against underlying infrastructure such as ESXi and Hyper-V. It emphasizes the importance of properly protecting the visor.”

Extortion was the top goal of threat actors last year as ransomware continues to be prevalent. He was fifth in attacks (21%), second and third more than data theft (19%) and credential harvesting (11%).

IBM said business email compromise (BEC) was another leading cause of extortion-based attacks, frequently characterized by the use of remote access tools, cryptominers, backdoors, downloaders, and web shells. rice field.

Manufacturing companies make up the largest group (30%) of victims of extortion attacks.

Elsewhere, phishing remained the number one initial access vector last year, identified in two-fifths (41%) of incidents, followed by public application exploitation (26%).

As inboxes are compromised, attackers are increasingly using thread hijacking techniques to add legitimacy to spam emails and increase the likelihood of engaging with victims.

IBM has recorded a 100% year-over-year increase in thread hijacking attempts per month in 2022. Emotet, Qakbot, and IcedID campaigns in particular heavily use this tactic.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *