{"id":16155,"date":"2024-03-22T14:44:01","date_gmt":"2024-03-22T13:44:01","guid":{"rendered":"https:\/\/telecomkh.info\/?p=16155"},"modified":"2024-03-22T14:44:01","modified_gmt":"2024-03-22T13:44:01","slug":"cyber-threat-surge-trend-micro-blocks-160-billion-incidents-in-2023","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=16155","title":{"rendered":"Cyber threat surge: Trend Micro blocks 160 billion incidents in 2023"},"content":{"rendered":"<p><strong>Ransomware detections fall 14% as alternative attack strategies evolve<\/strong><\/p>\n<p>Trend Micro Incorporated, a global cybersecurity leader, revealed a 10% annual increase in total threats blocked in 2023 and warned that attackers are using more advanced methods to target fewer victims with the potential for higher financial gains.<br \/>\nJon Clay, VP of threat intelligence at Trend: \u00abWe&#8217;re blocking more threats than ever before for our customers. But understand that adversaries showed a variety and sophistication of TTPs in their attacks, especially in defense evasion. As our report demonstrates, network defenders must continue to proactively manage risk across the entire attack surface today. Understanding the strategies favored by our adversaries is the foundation of effective defense.\u00bb<br \/>\nTrend Micro blocked 161 billion threats overall in 2023, compared to 82 billion threats five years ago. In 2023, threats blocked by email and web reputation dropped annually by 47% and 2%, respectively. Threats blocked by Trend&#8217;s Mobile Application Reputation Service (-2%), Smart Home Network (-12%), and Internet of Things Reputation Service (-64%) also declined. However, there was a 35% annual increase in threats blocked under Trend&#8217;s File Reputation Service (FRS).<br \/>\nThis could indicate that threat actors are choosing their targets more carefully. Instead of launching attacks on a wider range of users and relying on victims clicking on malicious links in websites and emails, they&#8217;re targeting a smaller number of higher-profile victims with more sophisticated attacks. This might enable them to bypass early detection layers like network and email filters\u2014which could explain the surge in malicious file detections at endpoints.<\/p>\n<p>Some other trends observed in the report include:<br \/>\n\u2022 APT actors showed a variety and sophistication of their attacks against victims, especially around defense evasion tactics.<br \/>\n\u2022 Email malware detection surged by 349% year-on-year (YoY), while malicious and phishing URL detections declined by 27% YoY \u2013 again highlighting the trend for more using malicious attachments in their attacks.<br \/>\n\u2022 Business email compromise (BEC) detections increased 16% YoY.<br \/>\n\u2022 Ransomware detections dropped 14% YoY. However, once again, the increase in FRS detections may indicate that threat actors are getting better at evading primary detection via techniques such as Living-Off-The-Land Binaries and Scripts (LOLBINs\/LOLBAs), Bring Your Own Vulnerable Driver (BYOVD), zero-day exploits, and AV termination.<br \/>\n\u2022 Linux and MacOS ransomware attacks were 8% of the overall ransomware detections.<br \/>\n\u2022 There was an increase in remote encryption, intermittent encryption, EDR bypass using unmonitored virtual machines (VMs), and multi-ransomware attacks where victims were hit more than once. Adversaries have recognized EDR as a formidable defense but are now utilizing bypass tactics to get around this technology.<br \/>\n\u2022 Thailand and the US were the top two ransomware victim countries, with banking as the most affected sector.<br \/>\n\u2022 The top MITRE ATT&amp;CK detections were defense evasion, command &amp; control, initial access, persistence, and impact<br \/>\n\u2022 Risky cloud app access was the top risk event detected by Trend&#8217;s attack surface risk management (ASRM), recorded almost 83 billion times.<br \/>\n\u2022 Trend&#8217;s Zero Day Initiative discovered and responsibly disclosed 1914 zero-days, up 12% YoY. These included 111 Adobe Acrobat and Reader bugs. Adobe was the number one vendor for vulnerability reporting, and PDFs were the number one spam attachment type.<br \/>\n\u2022 Windows applications were the top 3 vulnerabilities exploited through detections from our virtual patches.<br \/>\n\u2022 Mimikatz (used in data harvesting) and Cobalt Strike (used in Command &amp; Control) continued to be the preferred legitimate tools to abuse to aid criminal activity.<\/p>\n<p>In light of these findings, Trend advises network defenders to:<br \/>\n\u2022 Work with trusted security vendors with a cybersecurity platform approach to ensure resources are not only secured but also continuously monitored for new vulnerabilities.<br \/>\n\u2022 Prioritize SOC efficiency by monitoring cloud applications carefully as they become more closely integrated into day-to-day operations.<br \/>\n\u2022 Ensure all the latest patches\/upgrades are applied to operating systems and applications.<br \/>\n\u2022 Utilize comprehensive security protocols to safeguard against vulnerabilities, tighten configuration settings, control application access, and enhance account and device security. Look to detect ransomware attacks earlier in the attack lifecycle by shifting left in defenses during initial access, lateral movement, or data exfiltration stages.<\/p>\n<p><span style=\"color: #999999;\"><em>Above, Jon Clay, VP of threat intelligence at Trend Micro<\/em><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware detections fall 14% as alternative attack strategies evolve Trend Micro Incorporated, a global cybersecurity leader, revealed a 10% annual increase in total threats blocked in 2023 and warned that attackers are using more advanced methods to target fewer victims with the potential for higher financial gains. Jon Clay, VP of threat intelligence at Trend: &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=16155\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abCyber threat surge: Trend Micro blocks 160 billion incidents in 2023\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":16156,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16155"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16155"}],"version-history":[{"count":1,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16155\/revisions"}],"predecessor-version":[{"id":16157,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16155\/revisions\/16157"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/16156"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}