According to research by Crowdstrike, during the first months of 2020 there was a significant increase in sophisticated hands-on hacking attacks.

We are talking about hands-on hacking when themselves hackers explore the compromised systems and do not use programmed scripts that perform automated processes.
The increase in hands-on attacks is largely due to the constant evolution of hackers . Cybercriminals are constantly developing new tools, techniques, and processes. At the same time, the COVID-19 pandemic has given hackers the opportunity to carry out even more attacks.
The researchers examined a series of hands-on attacks and analyzed their findings in the Threat Hunting Report 2020.In the first half of 2020, 41,000 intrusions were discovered, a number that exceeds the total hands-on intrusions in all of 2019 (35,000).
Crowdstrike Vice President Jennifer Ayerssaid the increase in attacks during 2020 is concerning.
“Keep in mind that the report essentially refers to the first half of the year, and in half a year we have already significantly surpassed the number of attacks we observed in 2019 and 2018“.
In hands-on hacking campaigns, hackers gain access to the victims' network using stolen or exposed credentials. They then gain access to accounts and systems and spread across the network. And because the access is essentially legal, it is difficult to notice unusual activity.

In the past, this type of attack was mainly used by state hackers, but now other hacking groups are also carrying out such attacks.
Government hackers use hands-on intrusions for espionage campaigns and intellectual property theft. Other groups typically use them for ransomware attacks that encrypt entire networks.
According to researchers, almost all industry sectors have faced hands-on attacks this year, with technology, telecommunications , and finance being the most targeted sectors.
However, despite the dramatic increase in attacks, organizations can protect themselves by following some basic security measures, such as applying updates, using strong passwords , and creating backups .Multi -factor authentication is also very important for protecting accounts.
