LockBit ransomware gang most apt to leak stolen victim data

Issue 1 2023 News & Events

Trellix has released The Threat Report: February 2023 from its Advanced Research Centre, examining cybersecurity trends from the final quarter of 2022. Trellix combines telemetry collected from the world’s largest network of endpoint protection installs and its complete XDR product line with data gathered from open- and closed-source intelligence reports to deliver the report insights.


Carlo Bolzonello.

“Q4 saw malicious actors push the limits of attack vectors,” said John Fokker, Head of Threat Intelligence, at Trellix Advanced Research Centre. “Grey zone conflict and hacktivism led to an increase in cyber as statecraft and activity across threat actor leak sites. As the economic climate changes, organisations need to make the most effective security out of scarce resources.”

In South Africa, the threats and vulnerabilities follow similar targets and methods of infiltration, where human error, rather than system flaws, is exploited. Country lead for Trellix South Africa, Carlo Bolzonello, points to our most important institutions as the most attractive prey for international syndicates.

“The South African context for our findings overlaying the global results shows that ransomware and email threats are still top of the biggest threats to South Africa, with government a large focus followed by financial organisations,” Bolzonello says.

The report includes evidence of malicious activity linked to ransomware and nation-state backed advanced persistent threat (APT) actors, and examines threats to email, the malicious use of legitimate security tools, and more. Key findings include:

LockBit 3.0 most aggressive with ransom demands: While no longer the most active ransomware group (based on Trellix telemetry) – Cuba and Hive ransomware families generated more detections in Q4 – the LockBit cybercriminal organisation’s leak site reported the most victims. This makes LockBit the most vehement in pressuring their victims to comply with ransom demands. These cybercriminals use a variety of techniques to execute their campaigns, including exploiting vulnerabilities found as far back as 2018.

Nation-state activity led by China: APT actors linked to China, including Mustang Panda and UNC4191, were the most active in the quarter, generating a combined 71% of detected nation-state backed activity. Actors tied to North Korea, Russia, and Iran followed. The same four countries ranked the most active APT actors in public reports.

Critical infrastructure sectors most targeted: Sectors across critical infrastructure were most impacted by cyberthreats. Trellix observed 69% of detected malicious activity linked to nation-state backed APT actors targeting transportation and shipping, followed by energy, oil, and gas. According to Trellix telemetry, finance and healthcare were among the top targeted sectors by ransomware actors, and telecom, government and finance among the top sectors targeted via malicious email.

Fake CEO emails led to business email compromise: Trellix determined that 78% of business email compromise (BEC) involved fake CEO emails using common CEO phrases. This was a 64% increase from Q3 to Q4 2022. Tactics included asking employees to confirm their direct phone number to execute a voice-phishing – or vishing – scheme. 82% were sent using free email services, meaning threat actors need no special infrastructure to execute their campaigns.

The Threat Report: February 2023 includes proprietary data from Trellix’s sensor network, investigations into nation-state and cybercriminal activity by the Trellix Advanced Research Centre, open- and closed-source intelligence, and threat actor leak sites. The report is based on telemetry related to detection of threats, when a file, URL, IP-address, suspicious email, network behaviour or other indicator is detected and reported by the Trellix XDR platform.

Find more at https://www.trellix.com/en-us/advanced-research-center.html




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Protect the integrity of critical video evidence
Surveillance News & Events
SWEAR has announced the Community Video Integrity Project, a new initiative designed to help cities and public agencies proactively protect the integrity of critical video and establish a verifiable record of authenticity from the moment it is captured.

Read more...
Keenfinity creates two security businesses
News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
The Keenfinity Group, today announced the creation of two dedicated businesses from its former Intrusion & Access portfolio. Radionix will focus exclusively on intrusion alarm systems, while MiCOS will become a dedicated access control company.

Read more...
Genetec global leader in video management software
Genetec News & Events Surveillance
Independent analyst firms rank Genetec as global leader in video management software. Research shows continued market share gains for Genetec as both the VMS and VSaaS markets continue to expand worldwide.

Read more...
DeepAlert Launches COMMAND
News & Events Surveillance
Cloud-based, AI-powered surveillance monitoring platform cuts operator alert fatigue and response times, and becomes DeepAlert's primary monitoring platform for security companies and control rooms worldwide.

Read more...
ONVIF strengthens authenticity of video surveillance footage
Surveillance News & Events
Amid a rising tide of manipulated and AI-generated footage, the add-on will equip the surveillance industry with a shared, standards-based way to establish where video came from and whether it has remained unaltered.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Integrating the industry
News & Events Infrastructure
With private security, neighbourhood watches, CCTV, drones, control rooms and community safety networks expanding across the country, the next frontier may not be more technology, but connecting what already exists.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Gallagher Security assists St Vincent School for the Deaf
Gallagher News & Events Access Control & Identity Management
At a time when vehicle purchase and running costs are higher than ever, St. Vincent School for the Deaf will have a more reliable vehicle thanks to a recent donation from Gallagher Security.

Read more...
Free live travel risk map covering multiple countries
News & Events Security Services & Risk Management
Most widely cited travel risk maps are published once a year as static documents, but risk conditions do not follow a publishing calendar. The Sicuro map draws on official travel advisories from the ...

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.