Cyber Adversaries Reincorporate Old-School Tactics to Catch Organizations Off-Guard Ahead of Busy Holiday Season
Derek Manky, Chief, Security Insights & Global Threat Alliances,
“Cybercriminals continue to attempt to be a step ahead of cybersecurity professionals. While they develop new malware and zero-day attacks, they also redeploy previously successful tactics to maximize opportunity across the entire attack surface. In addition to essential strategies like patching, segmenting, and training, organizations also need to embrace automation and AI to enhance their ability to correlate threat intelligence and respond to threats in real time. This approach will only be successful, however, when organizations integrate all of their security resources into a security fabric that can see across, and adapt to their rapidly expanding network.”
- The research reveals that cybercriminals continue to look for new attack opportunities throughout the digital attack surface. At the same time, they are shifting attack vectors such as targeting publicly available edge services to counter training and education efforts by organizations that address popular tactics such as phishing.
- The Threat Landscape Index remained relatively consistent during the quarter. There were fluctuations but no significant swings. Regardless, organizations should not let their guard down, instead the index demonstrates consistent and sustained cybercriminal activity.
- For a detailed view of the Threat Landscape Index and subindices for exploits, malware, and botnets, as well as some important takeaways read the blog. Highlights of the report follow.
Shifting Tactics to Catch Organizations By Surprise: The majority of malware is delivered via email, therefore many organizations have been aggressively addressing phishing attacks with end user training and advanced email security tools. As a result, cybercriminals are expanding their ability to deliver malicious malware through other means. These include targeting publicly facing edge services such as web infrastructure, network communications protocols, as well as bypassing ad blocker tools to open attack vectors that don’t rely on traditional phishing tactics. For example, this quarter
Maximizing Earning Potential: Following in the footsteps of the lucrative GandCrab ransomware, which was made available on the dark web as a Ransomware-as-a-Service (RaaS) solution, cybercriminal organizations are launching new services to expand their earning potential. By establishing a network of affiliate partners, criminals are able to spread their ransomware widely and scale earnings dramatically in the process.
Refining Malware for Success: Expanding on these approaches, cybercriminals are also refining malware to evade detection and deliver increasingly sophisticated and malicious attacks, such as the evolution of the Emotet malware. This is a troubling development for organizations as cybercriminals increasingly use malware to drop other payloads on infected systems to maximize their opportunities for financial gain. Recently, attackers have begun using Emotet as a payload delivery mechanism for ransomware, information stealers, and banking trojans including TrickBot, IcedID, and
Maximizing Opportunity with Older Vulnerabilities and Botnets: Targeting older, vulnerable systems that have not been properly secured is still an effective attack strategy.
Similarly, this trend of maximizing existing opportunity also extends to botnets. More so than any other type of threat, the top botnets also tend to carry over from quarter to quarter and region to region globally with little change. This suggests the control infrastructure is more permanent than particular tools or capabilities, and that cybercriminals not only follow new opportunities, but like legitimate businesses, also leverage existing infrastructure whenever possible to increase efficiency and reduce overhead.
Protecting for the Unexpected: Broad, Integrated, and Automated Security
The expanding attack surface and shifting attack strategies of cybercriminals means organizations cannot afford to over-focus on a narrow set of threat trends. It is essential that organizations adopt a holistic approach to securing their distributed and networked environments. This requires the deployment of a security fabric that is broad, integrated, and automated. This approach will enable organizations to reduce and manage the expanding attack surface through broad visibility across integrated devices, stop advanced threats through AI-driven breach prevention, and reduce complexity through automated operations and orchestration. In addition, threat intelligence that is dynamic, proactive, and available in real-time plays a crucial role in identifying trends by following the evolution of attack methods targeting the digital attack surface and then pinpointing cyber hygiene priorities.
Report and Index Overview
The latest Fortinet Threat Landscape Report is a quarterly view that represents the collective intelligence of
- Read the blog for more information about this research.
- View the Fortinet Threat Landscape Index and subindices for botnets, malware, and exploits for Q3, 2019 or access the full report.
- View and read the most recent Adversary Playbook – Emotent – from the
- For a more detailed view into the changing threats and events driving the Fortinet Threat Landscape Index each week, check out our weekly Threat Brief.
- Learn more about
FortiGuard Labsand the FortiGuard Security Services portfolio.
- Learn more about the FortiGuard Security Rating Service, which provides security audits and best practices.
- Read more about Fortinet’s Network Security Expert program ,
Network Security Academyprogram, and the FortiVets program.
- Read more about the Fortinet Security Fabric.
Fortineton Twitter, LinkedIn, YouTube, and Instagram.
Copyright © 2019 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and common law trademarks of Fortinet, Inc., its subsidiaries and affiliates. Fortinet's trademarks include, but are not limited to, the following: Fortinet, FortiGate, FortiGuard, FortiCare, FortiManager, FortiAnalyzer, FortiOS, FortiADC, FortiAP, FortiAppMonitor, FortiASIC, FortiAuthenticator, FortiBridge, FortiCache, FortiCamera, FortiCASB, FortiClient, FortiCloud, FortiConnect, FortiController, FortiConverter, FortiDB, FortiDDoS, FortiExplorer, FortiExtender, FortiFone, FortiCarrier, FortiHypervisor, FortiIsolator, FortiMail, FortiMonitor, FortiNAC, FortiPlanner, FortiPortal, FortiPresence , FortiProxy, FortiRecorder, FortiSandbox, FortiSIEM, FortiSwitch, FortiTester, FortiToken, FortiVoice, FortiWAN, FortiWeb, FortiWiFi, FortiWLC, FortiWLCOS and FortiWLM.
Other trademarks belong to their respective owners. Fortinet has not independently verified statements or certifications herein attributed to third parties and Fortinet does not independently endorse such statements. Notwithstanding anything to the contrary herein, nothing herein constitutes a warranty, guarantee, contract, binding specification or other binding commitment by Fortinet or any indication of intent related to a binding commitment, and performance and other specification information herein may be unique to certain environments. This news release may contain forward-looking statements that involve uncertainties and assumptions, such as statements regarding technology releases among others. Changes of circumstances, product release delays, or other risks as stated in our filings with the Securities and Exchange Commission, located at www.sec.gov, may cause results to differ materially from those expressed or implied in this press release. If the uncertainties materialize or the assumptions prove incorrect, results may differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements. Fortinet assumes no obligation to update any forward-looking statements, and expressly disclaims any obligation to update these forward-looking statements.
|Media Contact:||Investor Contact:||Analyst Contact:|
|John Welton||Peter Salkowski||Ron Davis|
|Fortinet, Inc.||Fortinet, Inc.||Fortinet, Inc.|
Source: Fortinet, Inc.