In response to the past year of growing cyber security threats, CrowdStrike has released its 2021 Global Threat Report. The report provides vital lessons and recommendations for how security teams can operate in today’s environment in which constantly evolving threats make visibility and speed increasingly important.
Findings in the report suggest that supply chain attacks, ransomware, data extortion and nation-state threats are more abundant than ever. To counter the rapid growth in eCrime, in this year’s annual report, CrowdStrike introduced a new eCrime Index (ECX). The index demonstrates the strength, volume and sophistication of the market and is updated weekly in real-time to help businesses maintain an advantage over their adversaries.
CrowdStrike’s report covers real-world scenarios and observed tactics in which several key trends stood out. By having an understanding of these trends, businesses can not only become both better informed but can become better placed to meet the challenges that they represent.
1. COVID-19 Themes and Healthcare Sector Became a Target
COVID-19 has had a significant impact on every business and every industry, so it stands to reason that it has impacted the cyber landscape. Fear, concern, and curiosity regarding the pandemic created a valuable subject matter for cybercriminals who used COVID-19 themes in phishing campaigns and lures. CrowdStrike also identified both eCrime and targeted intrusion adversaries explicitly targeting the healthcare industry throughout the past year. Along with the potential disruption to critical functions, the secondary threat of ransomware operations that exfiltrate data was also observed across all sectors.
2. Supply Chain Attacks Continue to be a Major Intrusion Vector
Supply chain attacks have been highlighted as a threat by CrowdStrike since 2018, and 2020 saw them continue to be a major intrusion vector. Software-based attacks enabled malicious actors to propagate to many targets from a single intrusion. Meanwhile, hardware and third-party compromises were also observed. O365 and Azure were consistent targets of one adversary who had a detailed understanding of the authentication and access controls associated with these Microsoft platforms. Supply chain and trusted relationship compromises were identified from both eCrime and targeted intrusion adversaries.
3. Data Extortion Methods Are Being Used by Big Game Hunters
During 2020, Big Game Hunting (BGH) leant increasingly towards incentivising victims to engage in ransom negotiations. Over the course of the year, data theft and the use of Dedicated Leak Sites (DLS) became as deeply implanted in BGH ransomware operations as encryption. While the majority of ransomware operations were opportunistic, more ransomware-associated data extortion operations were seen in the industrial, engineering and manufacturing industries.
CrowdStrike found the eCrime ecosystem to still consist of a vast number of interconnected enterprises often supporting BGH operations. However, a noteworthy development was the pivotal role that access brokers played in supporting a variety of actors in 2020. Also, in 2020, targeted intrusion actors from China, Russia and Iran, among other countries, pursued actions likely related to strategic national security and espionage priorities dictated by their state’s.
As well as highlighting the key trends, CrowdStrike’s report puts forward a number of recommendations to help assist businesses in addressing emerging threats and possible vulnerabilities within their systems. Recommendations suggest that security teams should:
During 2020, not only were adversaries undeterred by COVID-19, but they were also motivated to exploit the situation. In 2021, BGH operations will continue to find ways to maximise their impacts on targets, and both eCrime and targeted intrusion will continue to find new methods to bypass detection.
Threat actors are getting braver and more shrewd by the day. As such, every business needs to employ comprehensive cloud-native technology to stay ahead of the game. To find out more about the challenges your business faces and the recommended defences you need, download the CrowdStrike 2021 Global Threat Report for the full details.