A Perfect Storm For Cybercrime

Calling the past few years uncertain is a slight understatement. From the COVID-19 pandemic, through to record inflation, the exhaustive energy crisis, and the devastating war in Ukraine - so many drastic events have had a significant impact on global behaviour and livelihood.

Every time the world stops to give people a moment to catch their breath, it seems another crisis comes along to disrupt things even further. This has led some global experts to even go as far to describe the world as in a state of “permacrisis”.

The effect these events have bleed through into all facets of life, but from a cybersecurity aspect, the fallout can be even more significant. The ambient uncertainty arising from the unknown plays a huge part in the funding and resourcing behind security operations (SecOps) teams – especially when board members don’t fully understand why having robust cybersecurity tools is so important to protecting business interests.

Furthermore, we’ve also seen threat actors play into the geopolitical instability, utilising sophisticated spear-phishing techniques to target individuals in critical sectors. In some cases, these have been backed by foreign governments in an effort to further destabilise regional economies – we’ve seen this recently with China’s activity in Taiwan. The question arises as to how businesses can better protect themselves from this malicious activity.

New Threats Rising To The Surface

As the tools supporting cybersecurity teams grow more sophisticated, so do the tools utilised by threat actors in their initiatives. Recent research from Trellix found that growing attack surfaces comprise 34% of the challenges faced by CISOs in protecting their organisations. But how does the threat landscape take shape – from ransomware to email, network, and endpoint vulnerabilities?

It’s difficult to pinpoint the exact vectors that threat actors utilise in compromising victim systems. Over the past year, we’ve seen a significant increase in the exploitation of Living off the Land Binaries (LotLBins), with threat actors gaining access to IT infrastructure through existing, benign system tools.

With this, we’ve also seen a proliferation in the use of first and third party bespoke and open-source tools such as Ghidra. Unpredictability on the part of malicious groups is an increasingly leaned on tactic, but it reinforces the importance of security being at the forefront of business decisions. 

According to CISOs across the globe, employee error, such as accidently downloading compromised files or clicking malicious URLs, directly led to 45% of breaches in 2022. Having a top-down, security minded culture is essential to ensuring all business units are informed about security procedure.

Since the start of the conflict between Ukraine and Russia, we’ve also seen increase in niche strategies employed by groups, such as hacktivism – the use of hacking skills to promote political or societal change. Whilst hacktivism isn’t a new trend, groups like Anonymous have existed for some time now, these world events have initiated a “call-to-action” so to speak, against perceived societal injustices.

Collaboration Is The Key Ingredient To Protection

The uncertain political and economic environment has triggered a paradigm shift in attitudes between nations and organisations. The state of permacrisis has been a catalyst for important partnerships between the public and private sectors. We’ve seen an increased coalition of data between large cybersecurity industry players like Microsoft, Cisco, Google and Trellix, leveraging intelligence with the Ukrainian government and NATO throughout 2022.

Increased activity between the Five Eyes alliance (Australia, Canada, New Zealand, the United Kingdom, and the United States), as well as the EU has helped in limiting the scale of state-backed cyberattacks.

The UK government has also recently announced it is strengthening its ties with Japan and Israel to enhance tech and security collaboration between the countries and reduce cyber risk. Whilst advanced persistent threat (APT) groups still remain active, partnerships like these have enabled companies and governments to be better prepared in the face of emerging threats.

Tracking major APT groups is an ongoing process. It requires the participation of government bodies and businesses to keep atop of the evolving threat landscape and minimise threats. Sharing intelligence with the NCSC and CISA, for instance, is an essential step in mitigating the impact of security breaches. To this end, the formation of groups like the NCSC’s Industry 100 scheme and the CISA’s Joint Cyber Defence Collaborative (JCDC) are facilitating a collaborative and fluid intelligence highway across public and private sectors.

Ever Looming State-backed Threats

In May, the APT Group known as Volt Typhoon mounted a massive cyberattack aimed at crippling US critical infrastructure. Whilst they deny involvement, evidence that China was involved in backing the group in their activities demonstrates the building tensions between the East and West. This coincides with our own findings within the recent Trellix CyberThreat Report, with China being the most prevalent threat actor country, contributing to 79% of state backed activity worldwide in Q1 2023.

The exploitation of LotLBins allowed Volt Typhoon to remain hidden amongst in-built systems on compromised computers. This enabled them to remain undetected whilst moving laterally through systems, expanding their threat surface. Often organisations will not even know there is a breach until it is far too late - investing in resources that enhance existing incident detection and response capabilities is crucial.

Cybersecurity is a shared problem. Robust, real-time sharing of threat data is key to protecting citizens and organisations from attack.

The mentality needs to be that “the enemy of my enemy is my friend” when it comes to true security collaboration to keep cybercriminals at bay.

Centralising Security Operations

There is pressure on SecOps in making do with the tools that are already in place. Much like spinning plates, too many siloed solutions can inadvertently take control away from security professionals and reduce overall security visibility.

Having a centralised system that covers email detections, endpoint, network protection and control over data migration offers greater protection.

This allows core vulnerabilities to be prioritised, whilst additional tools like AI and machine learning can be introduced for more automated detection and response. Agility and flexibility are key, as threat actors are always learning, adapting, and evolving their attack techniques. When faced with this challenge, agile cybersecurity defence based on frontline intelligence becomes crucial when defending against attacks across both public and private sectors.

Fabien Rech is Senior VP & GM EMEA of Trellix

You Might Also Read: 

Overcoming The Obstacles Caused By The Great Resignation:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

 


Cyber Security Intelligence: Captured Organised & Accessible


 

« A Million British Medical Patient Records Hacked
Sweden Issues An Order 'Stop Using Google Analytics' »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Dark Reading

Dark Reading

Dark Reading is the most trusted online community for security professionals.

Eversheds Sutherland

Eversheds Sutherland

Eversheds Sutherland is a global multinational law practice offering a full range of commercial and IT law services including Privacy, Data Protection and Cyersecurity.

Cognizant

Cognizant

Cognizant offer services and solutions for IT Infrastructure Security, Enterprise Mobility and Internet of Things.

OPSWAT

OPSWAT

OPSWAT is a software company that provides solutions to secure and manage IT infrastructure.

Horangi

Horangi

Horangi provides security products and services that enable the rapid delivery of Incident Response and threat detection for our customers who lack the scale, expertise, or time to do it themselves.

PBOSecure

PBOSecure

PBOSecure is a dynamic and progressive IT consultancy company specializing in IT and Industrial Control System (ICS) security.

Zuratrust

Zuratrust

Zuratrust provide protection for all kinds of email related cyber attacks.

Risk Strategies

Risk Strategies

Risk Strategies is a leading specialty risk management consultancy and insurance broker offering smarter, practical approaches to risk mitigation including Cyber Liability insurance.

Security & Intelligence Division (SID) - Singapore

Security & Intelligence Division (SID) - Singapore

Security & Intelligence Division (SID) protects Singapore from external threats and safeguards its interests in areas related to terrorism, cyber security, other transnational threats, and geopolitics

eaziSecurity

eaziSecurity

eaziSecurity has built an eco-system of technology and services that bring enterprise scale security solutions to the SME marketplace.

Tentacle

Tentacle

Tentacle has developed a configurable data management tool that helps organizations to improve their information security programs and overall security posture.

Visory

Visory

Great businesses depend on great technology. We make sure our clients go to market with enterprise-level technology and world-class security for their data and infrastructure.

Web3fied

Web3fied

Web3fied is a seed stage company building the future of decentralized digital identity and credentials management.

Obrela Security Industries

Obrela Security Industries

Obrela provides security analytics and risk management services to identify, analyze, predict and prevent highly sophisticated security threats in real time.

Ontinue

Ontinue

Ontinue ION is an MXDR service that provides Nonstop SecOps through five key capabilities that enable your organization to respond to attacks and continuously reduce risk.

CeTu

CeTu

CeTu - Data Orchestration for the Modern SOC. Strengthen security and optimize costs with the world's first AI-native platform for scaling and future-proofing your data stack.