In today’s hyper-connected world, it’s no longer a question of if we’ll be attacked – but when. Symantec’s Internet Security Threat Report (ISTR), Volume 20, reveals a tactical shift in cybercriminal behavior: they are infiltrating networks and avoiding detection by breaching the infrastructure of large organizations and using that infrastructure to their advantage. 
“Attackers don’t need to break into a corporate network by ‘kicking down the door’ when the keys are already available for use,” said Christos Ventouris, Information Security Specialist for Southeast Europe for Symantec. “We see attackers tricking companies by infecting themselves with common program upgrade software that contains a Trojan, patiently waiting for their targets to download the specific file, which ultimately gives them unrestricted access to the corporate network.”
Attackers achieve with speed and precision
It was a record year for zero-day vulnerabilities, according to Symantec’s report. The report also says that it took software companies an average of 59 days to create and release patches – a big jump from the four-day average in 2013. Attackers took advantage of this delay and, in the case of Heartbleed, exploited the vulnerability within four hours. There were a total of 24 zero-day vulnerabilities discovered in 2014, leaving the field open for attackers to exploit known security holes before patches were released, Symantec.
Meanwhile, the most advanced attackers continue to breach networks with high-level spear-phishing attacks, which increased by 8% in 2014. The element that is particularly interesting is the precision of these attacks, which used 20% fewer emails to successfully infiltrate organizations – targets and to incorporate more drive-by malware downloads and other web-based exploits.
Additionally, Symantec observed the attackers:
- To use stolen email accounts from a victim – a company to find new victims higher up the chain
- To exploit companies' management tools and processes to move stolen intellectual property data within the corporate network before its exfiltration
- To create custom attack software within their victims' network to further conceal their activities.
Digital Extortion in Bloom
The email remains a significant vector of cybercriminal attacks, but they continue to experiment with new attack methods on mobile devices and social networks, aiming to gain access to more people with less effort.
“Cybercriminals are basically lazy. They prefer automated tools and the contribution of clumsy consumers to do the “hard” work” said Mr. Christos Ventouris, Information Security Specialist for Southeast Europe at Symantec. “Last year, 70% of fraud incidents carried out on social networks were conducted manually, as attackers exploited users' willingness to trust content shared by their friends.”
While scams on social networks provide cybercriminals with easy money, some resort to more profitable and aggressive attack methods, such as ransomware, which saw a 113% increase last year. More specifically, there were 45 times more crypto‑ransomware attack victims than in 2013. Instead of pretending to be law‑enforcement officials imposing fines for stolen content, as was done in the past with traditional ransomware, the attackers changed their attack style, holding files, photos and other digital content of the victim in their possession, no longer covering their intentions.
Protect it, so you don't lose it!
As attackers persist and evolve, there are certain tips that can help businesses and consumers protect themselves in the best possible way. Initially, Symantec recommends the following best practices:
For Businesses:
- Don't be left unprotected: Use advanced threat management solutions that will help you find signs of threat exposure and respond faster to incidents.
- Take a robust approach to security: Implement a multi-layered endpoint and network security approach that includes encryption, strong authentication, and reputation-based technologies. Partner with a managed security services provider to extend your company's IT team.
- Prepare for the worst: Incident management ensures that your security framework is optimal, measurable, and reliable, and that any lessons learned from the past have strengthened your company’s approach to security. Consider bringing an external partner into your broader organization to help with crisis management.
- Provide your executives with ongoing training: Establish guidelines and corporate practices and procedures to protect sensitive data on personal and corporate devices. Regularly assess internal IT teams through hands-on exercises to ensure they have the right skills to combat cyber threats.
For consumers:
- Use strong passwords:This issue is constantly being emphasized. Using strong and unique passwords for your accounts and devices and renewing them regularly – ideally every three months – is the most effective solution. Never use the same password for multiple accounts.
- Be careful on social media: Don't click on links in unknown and unexpected emails or social media messages, especially if they come from unknown sources. Scammers know that users are more likely to click on links that come from friends, so they compromise these accounts to send malicious links to the account owner's contacts.
- Know what you're sharing: When you install a network device, like a home router, or download a new app, browse and find out what data that app is accessing. Turn off remote access when it's not necessary.

