HomeSecurityAPT groups are committing more targeted cybercrimes

APT groups are committing more targeted cybercrime

Cybercrime campaigns and high-profile advanced threat groups are changing the way they target victims and are focusing more on complex relationships with “secure syndicate” partnerships to disguise activity, according to the latest 2019 Cyber ​​Threatscape report from Accenture.

A shift to high-level exploitation models for cybercrime

The report notes a significant increase in threat actors and groups conducting targeted attacks for financial gain, also referred to as “big game hunting.”.

Despite arrests of individuals associated with online underground marketplaces, activity among APT groups – such as the Cobalt Group, FIN7, and Contract Crew – has continued. Accenture Security have also observed the shared use of tools that automate the process of mass production of malicious documents to spread malware ,such as More Eggs, which is used in both conventional crimeware campaigns (a category of malware specifically designed to automate cybercrime) and targeted attacks.

The ongoing activity is linked to relationships forming between “secure syndicates” that work closely together and use the same tools – indicating a significant shift in the way threat actors collaborate in the underground economy.

With syndicates working together, the lines are even more blurred between threat groups, making attribution more difficult.

Additionally, Accenture Security analysts have observed a shift in how the Cobalt group targets victims to gain access to victims' supply chain networks.

While malware has typically been sent to Internet users via phishing emails , analysts are now seeing the emergence of malware that runs through web browsers and focuses on targeting specific merchants and retailers.

cyberspace

The global battlefield of disinformation

The report also finds evidence of the continuing global disinformation battlefield affecting social media and warns that threat actors are becoming increasingly adept at exploiting legitimate tools.

While disinformation campaigns to influence both domestic and foreign political sentiment and national elections continue, the broader potential impact of disinformation on global financial markets is even more significant.

The financial services industry – and more specifically high-frequency trading algorithms, which rely on fast, text-driven information sources – are likely to be targeted in large-scale payback efforts in the future.

Increase in ransomware: network access for sale

Additionally, ransomware is increasingly plaguing businesses and government infrastructure, with the number of ransomware tripling in the last two years.

In addition to delivery via spam campaigns, analysts have observed the Nikolay and GandCrab threat groups planting ransomware directly into networks via network.

Actors are offering to sell Remote Desktop Protocol (RDP) access to corporate networks, which they have likely obtained through compromised servers and RDP, to those in underground communities.

About Accenture's Threat Environment Report Accenture

Leveraging Accenture's threat-security integrity capabilities and research from primary and secondary open source materials, the annual report provides insights and predictions about the cyber-healthcare landscape and how it will change over the coming year.

The goal is to help organizations stay ahead of threats specific to their organization, industry, and geography.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS