Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/15/2020
05:55 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

More Cyberattacks in the First Half of 2020 Than in All of 2019

The pandemic-related shift to remote work and the growing availability of ransomware-as-a-service were two major drivers, CrowdStrike says.

A study by CrowdStrike of recent threat activity on networks belonging to its customers showed more intrusion attempts in the first six months of this year than in all of 2019.

The security vendor's threat-hunting team blocked some 41,000 potential intrusions just between Jan. 1 and June 30 this year compared with 35,000 for all of last year. Incidents of hands-on-keyboard intrusions in the first six months of 2020 — where a threat actor is actively engaged in malicious activity — was some 154% higher than the number of similar instances that CrowdStrike's researchers observed in 2019.

Related Content:

Cybersecurity Lessons from the Pandemic

Special Report: Computing's New Normal, a Dark Reading Perspective

New on The Edge: Think You're Spending Enough on Security?

Predictably, one of the biggest causes for the increased threat activity was the rapid adoption of remote workforces in response to the COVID-19 pandemic. The switch significantly expanded the attack surface at many organizations, which threat actors were quick to try and exploit. Another driving factor was the growing availability of ransomware-as-a-service (RaaS) offerings and the resulting increase in threat actors and attack activity in the space. There was a notable increase especially in ransomware attacks that also involved the theft of sensitive data and subsequent attempts to extort victims with threats to publicly release the data, says Jennifer Ayers, vice president of CrowdStrike's OverWatch threat-hunting service.

Despite all the attention that cyber espionage and nation-state-backed threat groups have garnered recently, an overwhelming majority of the actual attacks that CrowdStrike blocked in the first six months of this year were financially motivated. In fact, 82% of the hands-on-keyboard attacks that CrowdStrike's threat hunters encountered fell into the e-crime category, compared with 69% in 2019,.

As has been the case for some time, organizations in the financial, technology, and telecommunications sectors were targeted more heavily than organizations in most other sectors. In addition, though, CrowdStrike observed what it called a dramatic increase in intrusion activity involving manufacturing companies. In fact, the manufacturing industry was the second most frequently targeted vertical after the technology sector in the first half of 2020. According to the company, the critical nature of most manufacturing operations and the valuable intellectual property and other data that manufacturing companies hold have made the sector an attractive target for both financially motivated attackers and nation-state threat groups.

Other sectors that experienced increased threat activity included healthcare, food and beverage, and academic institutions.

Once again, China-based adversaries posed a significant threat to organizations in multiple industries. CrowdStrike researchers observed at least six China-based actors targeting organizations in various data theft and cyber-espionage campaigns in the first half of 2020. Telecommunications companies were particularly popular targets for the China-based groups. Organizations in the manufacturing, healthcare, and agricultural sectors were also relatively heavily targeted.

In keeping with a recent trend, attackers used a variety of legitimate administration tools in their attacks. Some of them were native to the host operating system and others were not. The most frequently used tools included Process Hacker, Proc Dump, Advanced IP Scanner, Team Viewer, and Advanced Port Scanner. Attackers also used a variety of legitimate pen-testing tools in their campaigns including Mimikatz, Cobalt Strike, PowerShell Empire, PowerSploit, and Meterpreter.

One noticeable trend was the growing commonality in tactics, techniques, and procedures (TTPs) among e-crime groups and the generally more sophisticated state-backed groups. The overlap in TTPs is especially evident in the initial stages of an intrusion and in the use of legitimate admin tools and so-called living-off-the-land (LOTL) tactics to infiltrate networks, to escalate privileges, to achieve persistence, and to evade defenses, says Ayers. Where the two groups differ the most is in stealth and persistence. While financially motivated groups tend to be louder and more obvious in their malicious activity, the state groups tend to be stealthier and more persistent, she says

"They both present a challenge," Ayers notes. "The key thing from a defender standpoint is about the maturity of the security program," Ayers says. For organizations, the best defense continues to be paying attention to the basics — such as patching on time, implementing multifactor authentication, changing passwords frequently, and shoring up the perimeter to protect against some of the more basic attacks, she says.

According to Ayers, one especially worrisome development for defenders is the lengths to which attackers have going to evade detection. With organizations using more endpoint detection and response tools and other endpoint controls, threat actors have begun innovating ways around them. "We have seen some pretty interesting things in terms of how far they will go, including literally downloading [antivirus] uninstallers" on compromised systems.

CrowdStrike's report listed nearly six-dozen TTPs that its researchers observed attackers using to evade detection. Among them were tactics including registry modification, process injection, the use of signed code, process hollowing, malware that compiled after delivery, file deletion, and hidden users.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Naton Rich
50%
50%
Naton Rich,
User Rank: Apprentice
9/16/2020 | 11:40:06 AM
I know the solution
there will be fewer cyber attacks if you use p2p platforms for communication, like the utopia ecosystem and many others. These systems don't have servers that can be hacked
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
US Counterintelligence Director & Fmr. Europol Leader Talk Election Security
Kelly Sheridan, Staff Editor, Dark Reading,  10/16/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26895
PUBLISHED: 2020-10-21
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver,...
CVE-2020-26896
PUBLISHED: 2020-10-21
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collis...
CVE-2020-5790
PUBLISHED: 2020-10-20
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
CVE-2020-5791
PUBLISHED: 2020-10-20
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
CVE-2020-5792
PUBLISHED: 2020-10-20
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.