Kaspersky researchers have shared their vision for Advanced Persistent Threats (APTs) in 2020, noting that the landscape of targeted attacks will change in the coming months. The general trend shows that threats will evolve in quality and become more targeted, such as the development and spread of machine learning, deep learning technologies, or tensions around trade routes between Asia and Europe.
The predictions were developed based on the changes monitored by the global research and analysis team in 2019 to support the cyber community with some guidance and insights. Along with a series of industry and technology threat predictions, it will help prepare for the challenges that will arise in the next 12 months.

After several personal data breaches that occurred in recent years, the amount of personal information available made it easier for attackers to carry out targeted attacks, based on the information leaked by victims.
False flag attacks reach a whole new level
This will grow further, with threat actors seeking to not only avoid attribution, but also actively shift the blame to someone else. Malware, scripts, publicly available security tools or admin software, mixed with two false flags, where security researchers are “hungry” for any small clue.
Ransomware shifts towards targeted threats
A possible twist could be that, instead of destroying all files, hackers could threaten to publish data they have stolen from the company.

New banking regulations in the EU open up new avenues of attack
Given that banks will have to open up their infrastructure and data to third parties, it is likely that attackers will seek to abuse these mechanisms with new fraudulent schemes.
Mobile APTs are developing faster
There is no reason to believe that this will stop anytime soon. However, due to the increased attention being paid to this issue by the security community, we believe that the number of attacks being detected and analyzed in detail will also increase.

Abuse of personal information is increasing, due to AI
This technology is already in use and it is only a matter of time before some attackers exploit it.
