HomeinetKaspersky: 2016 the end of APT attacks as we know them

Kaspersky: 2016 will be the end of APT attacks as we know them

During Kaspersky Lab's European Cyber ​​Security Weekend, which is taking place these days in Budapest, Kaspersky Lab experts revealed their predictions for 2016.

The 2016 predictions are based on the expertise of the Global Research and Analysis Team, the company's 42 leading security experts from around the world. Each member of the Team contributed their unique expertise. In 2015 alone, their expertise and insights led to the release of detailed reports on 12 APT attack vectors, speaking different languages, including French, Arabic, Chinese, Russian and English.Kaspersky Security

“The security industry faces a new year of challenging developments. We believe that sharing our knowledge and predictions with our colleagues, as well as government agencies, law enforcement agencies and private sector organizations, will foster the necessary collaboration to proactively and proactively address the upcoming challenges,” said Marco Preuss, Head of Kaspersky Lab’s European Research Center.

Kaspersky experts estimate that digital espionage will see a significant evolution in its field in 2016. First, there will be a dramatic change in the way APT attack actors are structured and operate. It is expected that we will see a reduced emphasis on “persistence” and a greater focus on malware that either installs itself in the device memory or does not create folders, in order to reduce the traces they leave on an “infected” system and avoid detection. In addition, it is estimated that these actors will have less need to demonstrate superior digital skills. Therefore, the return on an “investment” in such means will determine a large part of the relevant decision-making process for state-sponsored attackers. As a result, there will be a reorientation towards ready-made malware instead of “investments” in bootkits, rootkits and custom malware.

In the longer term, it is expected that more “new players” will enter the APT space. The number of “digital mercenaries” will increase, as there will be more stakeholders who aim to profit from cyberattacks. “Digital mercenaries” will offer specialized knowledge to anyone willing to pay, while also selling digital access to high-ranking victims, a practice that could be characterized as “Access-as-a-Service”.

Threats targeting consumers will also evolve. According to Kaspersky Lab experts, ransomware will gain more ground than banking Trojans and is expected to expand into new areas, such as OS X devices, which are often owned by wealthier and therefore more profitable targets, as well as mobile devices and the Internet-of-Things in general.

Cybercriminals are constantly looking for new ways to force their victims to pay. Therefore, alternative payment systems, such as ApplePay and AndroidPay, as well as exchanges are expected to be growing targets for financial cyberattacks.

In 2015, Kaspersky Lab experts observed an increase in the number of DOXing attacks, i.e. public shaming and blackmail attacks, as many (from Hactivists to government agencies) adopted the strategy of publishing private photos, information and customer lists, using it to embarrass their targets. Unfortunately, Kaspersky Lab expects this practice to continue to grow exponentially in 2016.

To be able to minimize the future risks associated with the digital attacks of the future, businesses should create and develop a comprehensive security strategy. It is important to train staff on digital security, implement multi-layered protection for end users with additional preventive layers to protect all infrastructure elements, apply patches for vulnerabilities, pay attention to everything mobile, and implement encryption on communications and sensitive data. Companies that face a high risk of falling victim to digital attacks should consider creating a dedicated Security Operations Center.

Individuals should invest in a strong security solution for all devices and switch to encrypted communication. However, they should not rely solely on technology. By studying the basics of digital security and exploring the options that come with a security solution, they can avoid many incidents. After all, with an increasing part of our lives exposed online, it could be useful to review our online habits, as once information is “uploaded” to the Internet, it stays there forever and can be used against individuals or businesses.

The full report is available on Securelist.com. To read Kaspersky Lab experts’ predictions for 2015, please read the Kaspersky Security Bulletin 2014 posts titled “2015 Predictions” and “

“The security industry faces a new year of challenging developments. We believe that sharing our knowledge and predictions with our colleagues, as well as government agencies, law enforcement agencies and private sector organizations, will foster the necessary collaboration to proactively and proactively address the upcoming challenges,” said Marco Preuss, Head of Kaspersky Lab’s European Research Center.

Kaspersky experts estimate that digital espionage will see a significant evolution in its field in 2016. First, there will be a dramatic change in the way APT attack actors are structured and operate. It is expected that we will see a reduced emphasis on “persistence” and a greater focus on malware that either installs itself in the device memory or does not create folders, in order to reduce the traces they leave on an “infected” system and avoid detection. In addition, it is estimated that these actors will have less need to demonstrate superior digital skills. Therefore, the return on an “investment” in such means will determine a large part of the relevant decision-making process for state-sponsored attackers. As a result, there will be a reorientation towards ready-made malware instead of “investments” in bootkits, rootkits and custom malware.

In the longer term, it is expected that more “new players” will enter the APT space. The number of “digital mercenaries” will increase, as there will be more stakeholders who aim to profit from cyberattacks. “Digital mercenaries” will offer specialized knowledge to anyone willing to pay, while also selling digital access to high-ranking victims, a practice that could be characterized as “Access-as-a-Service”.

Threats targeting consumers will also evolve. According to Kaspersky Lab experts, ransomware will gain more ground than banking Trojans and is expected to expand into new areas, such as OS X devices, which are often owned by wealthier and therefore more profitable targets, as well as mobile devices and the Internet-of-Things in general.

Cybercriminals are constantly looking for new ways to force their victims to pay. Therefore, alternative payment systems, such as ApplePay and AndroidPay, as well as exchanges are expected to be growing targets for financial cyberattacks.

In 2015, Kaspersky Lab experts observed an increase in the number of DOXing attacks, i.e. public shaming and blackmail attacks, as many (from Hactivists to government agencies) adopted the strategy of publishing private photos, information and customer lists, using it to embarrass their targets. Unfortunately, Kaspersky Lab expects this practice to continue to grow exponentially in 2016.

To be able to minimize the future risks associated with the digital attacks of the future, businesses should create and develop a comprehensive security strategy. It is important to train staff on digital security, implement multi-layered protection for end users with additional preventive layers to protect all infrastructure elements, apply patches for vulnerabilities, pay attention to everything mobile, and implement encryption on communications and sensitive data. Companies that face a high risk of falling victim to digital attacks should consider creating a dedicated Security Operations Center.

Individuals should invest in a strong security solution for all devices and switch to encrypted communication. However, they should not rely solely on technology. By studying the basics of digital security and exploring the options that come with a security solution, they can avoid many incidents. After all, with an increasing part of our lives exposed online, it could be useful to review our online habits, as once information is “uploaded” to the Internet, it stays there forever and can be used against individuals or businesses.

The full text of the report is available on the Securelist.comwebsite.for To read Kaspersky Lab experts' predictions 2015, you can read the posts in Kaspersky Security Bulletin 2014, entitled " 2015 Predictions " and " A Look into the APT Crystal Ball " .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS