IBM Security has published its annual X-Force Threat Intelligence Index revealing that, although the share of ransomware incidents decreased only slightly (four percent) in 2022, attackers were nonetheless more successful in detecting and preventing ransomware. Despite this, attackers continued to innovate, with the report showing that the average time to complete a ransomware attack fell from two months to less than four days.
According to the 2023 report, last year the focus of attackers was on introducing backdoors that allow remote access to systems. About 67 percent of backdoor cases were related to ransomware, and the targets managed to detect them before their installation. This increased installation of backdoors can be partially attributed to their high market value. Specifically, X-Force recorded that access to existing backdoors is sold for as much as $10,000, which is significant compared to data on stolen credit cards that are sold daily for less than $10 per card.
– The shift towards earlier detection of attacks and response has allowed adversaries to be disrupted at an earlier stage, thereby temporarily slowing the progress of ransomware. However, it is only a matter of time before today’s backdoor problem becomes tomorrow’s ransomware crisis. Attackers always find new ways to evade detection. Good defense is no longer enough. To end this ongoing race with attackers, companies must adopt a proactive threat-focused security strategy,” said Charles Henderson, head of IBM Security X-Force.
The IBM Security X-Force Threat Intelligence Index tracks new and existing trends and patterns of attacks collected from billions of data points from network and endpoint devices, incident response engagements, and other sources.
Some key findings in the 2023 report include:
– Extortion: Go-to threat method. The most common consequence of cyber attacks in 2022 was extortion, primarily through ransomware attacks or attacks involving business email compromise.
– Cybercriminals use email communication as a weapon. In 2022, there was a significant increase in email thread hijacking by attackers who used compromised email addresses to insert themselves into existing correspondence, posing as the original participant. X-Force recorded a 100 percent increase in such attempts on a monthly basis compared to data from 2021.
