Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/15/2020
05:55 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

More Cyberattacks in the First Half of 2020 Than in All of 2019

The pandemic-related shift to remote work and the growing availability of ransomware-as-a-service were two major drivers, CrowdStrike says.

A study by CrowdStrike of recent threat activity on networks belonging to its customers showed more intrusion attempts in the first six months of this year than in all of 2019.

The security vendor's threat-hunting team blocked some 41,000 potential intrusions just between Jan. 1 and June 30 this year compared with 35,000 for all of last year. Incidents of hands-on-keyboard intrusions in the first six months of 2020 — where a threat actor is actively engaged in malicious activity — was some 154% higher than the number of similar instances that CrowdStrike's researchers observed in 2019.

Related Content:

Cybersecurity Lessons from the Pandemic

Special Report: Computing's New Normal, a Dark Reading Perspective

New on The Edge: Think You're Spending Enough on Security?

Predictably, one of the biggest causes for the increased threat activity was the rapid adoption of remote workforces in response to the COVID-19 pandemic. The switch significantly expanded the attack surface at many organizations, which threat actors were quick to try and exploit. Another driving factor was the growing availability of ransomware-as-a-service (RaaS) offerings and the resulting increase in threat actors and attack activity in the space. There was a notable increase especially in ransomware attacks that also involved the theft of sensitive data and subsequent attempts to extort victims with threats to publicly release the data, says Jennifer Ayers, vice president of CrowdStrike's OverWatch threat-hunting service.

Despite all the attention that cyber espionage and nation-state-backed threat groups have garnered recently, an overwhelming majority of the actual attacks that CrowdStrike blocked in the first six months of this year were financially motivated. In fact, 82% of the hands-on-keyboard attacks that CrowdStrike's threat hunters encountered fell into the e-crime category, compared with 69% in 2019,.

As has been the case for some time, organizations in the financial, technology, and telecommunications sectors were targeted more heavily than organizations in most other sectors. In addition, though, CrowdStrike observed what it called a dramatic increase in intrusion activity involving manufacturing companies. In fact, the manufacturing industry was the second most frequently targeted vertical after the technology sector in the first half of 2020. According to the company, the critical nature of most manufacturing operations and the valuable intellectual property and other data that manufacturing companies hold have made the sector an attractive target for both financially motivated attackers and nation-state threat groups.

Other sectors that experienced increased threat activity included healthcare, food and beverage, and academic institutions.

Once again, China-based adversaries posed a significant threat to organizations in multiple industries. CrowdStrike researchers observed at least six China-based actors targeting organizations in various data theft and cyber-espionage campaigns in the first half of 2020. Telecommunications companies were particularly popular targets for the China-based groups. Organizations in the manufacturing, healthcare, and agricultural sectors were also relatively heavily targeted.

In keeping with a recent trend, attackers used a variety of legitimate administration tools in their attacks. Some of them were native to the host operating system and others were not. The most frequently used tools included Process Hacker, Proc Dump, Advanced IP Scanner, Team Viewer, and Advanced Port Scanner. Attackers also used a variety of legitimate pen-testing tools in their campaigns including Mimikatz, Cobalt Strike, PowerShell Empire, PowerSploit, and Meterpreter.

One noticeable trend was the growing commonality in tactics, techniques, and procedures (TTPs) among e-crime groups and the generally more sophisticated state-backed groups. The overlap in TTPs is especially evident in the initial stages of an intrusion and in the use of legitimate admin tools and so-called living-off-the-land (LOTL) tactics to infiltrate networks, to escalate privileges, to achieve persistence, and to evade defenses, says Ayers. Where the two groups differ the most is in stealth and persistence. While financially motivated groups tend to be louder and more obvious in their malicious activity, the state groups tend to be stealthier and more persistent, she says

"They both present a challenge," Ayers notes. "The key thing from a defender standpoint is about the maturity of the security program," Ayers says. For organizations, the best defense continues to be paying attention to the basics — such as patching on time, implementing multifactor authentication, changing passwords frequently, and shoring up the perimeter to protect against some of the more basic attacks, she says.

According to Ayers, one especially worrisome development for defenders is the lengths to which attackers have going to evade detection. With organizations using more endpoint detection and response tools and other endpoint controls, threat actors have begun innovating ways around them. "We have seen some pretty interesting things in terms of how far they will go, including literally downloading [antivirus] uninstallers" on compromised systems.

CrowdStrike's report listed nearly six-dozen TTPs that its researchers observed attackers using to evade detection. Among them were tactics including registry modification, process injection, the use of signed code, process hollowing, malware that compiled after delivery, file deletion, and hidden users.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3113
PUBLISHED: 2021-01-17
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and ...
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...