Adversaries are Accelerating Targeted Access to Critical Networks 3x Times Faster Than Before, CrowdStrike Reveals in Annual Threat Hunting Report
CrowdStrike Inc. has released its annual Falcon OverWatch report, highlighting a 60% increase in attempted intrusions across all industries. The average breakout time for intruders has decreased to 1 hour and 32 minutes, indicating a rise in sophisticated cyberattack tactics. Notably, 68% of detections were malware-free, with China, North Korea, and Iran identified as the most active state-sponsored groups. The report also reveals a 100% increase in cryptojacking incidents and substantial activity targeting the telecommunications sector.
- 60% increase in attempted intrusions indicates growing market demand for cybersecurity.
- Average breakout time dropped to 1 hour 32 minutes, showcasing improved detection capabilities.
- 68% of recent detections were malware-free, highlighting the evolving tactics of threat actors.
- Surge in interactive intrusion activity in the telecommunications sector may create opportunities for cybersecurity solutions.
- Increased sophistication of cyberattacks suggests higher risks for potential breaches.
- Rise in cryptojacking incidents might indicate vulnerabilities within networks.
OverWatch also exposes an uptick in targeting from China-Nexus adversaries; attacks targeting telecommunications and retail more than doubled in the past year
The report also showcases a significant drop in average breakout time – the time it takes for an intruder to begin moving laterally outside of the initial beachhead to other systems in the network – of just one hour 32 minutes, a threefold decrease from 2020. These sobering statistics show how threat actors are constantly adapting tactics, techniques, and procedures (TTPs) to accelerate their march toward their objectives.
Additional significant OverWatch observations include:
-
Adversaries have moved beyond malware. They are using increasingly sophisticated and stealthy techniques tailor-made to evade detections — of all of the detections indexed by
CrowdStrike Threat Graph® in the past three months,68% were malware-free. -
China ,North Korea andIran were the most active state-sponsored groups. The report reveals the majority of targeted intrusion activity from adversary groups were based out ofChina ,North Korea , andIran . - A massive surge in interactive intrusion activity targeting the telecommunications industry. This activity spans all major geographic regions and has been tied to a diverse range of adversaries.
- WIZARD SPIDER was the most prolific cyber criminal. In fact, this group was seen in nearly double the number of attempted intrusions than any other eCrime group. WIZARD SPIDER is behind targeted operations using Ryuk and, more recently, Conti ransomware.
-
A
100% increase in instances of cryptojacking in interactive intrusions year-over-year, correlating with increases in cryptocurrency prices. - Access Brokers had a banner year. eCrime actors who specialize in breaching networks to sell that access to others played a growing and important role for other eCrime actors to stage their attempted intrusions.
“Over the past year, businesses faced an unprecedented onslaught of sophisticated attacks on a daily basis. Falcon OverWatch has the unparalleled ability to see and stop the most complex threats — leaving adversaries with nowhere to hide,” said
The report is comprised of threat data from Falcon OverWatch, CrowdStrike’s industry-leading managed threat hunting team, with contributions from
The mission of Falcon OverWatch is to augment the powerful, autonomous protection of the Falcon platform with smart, mission-focused expertise to deliver the outcomes necessary to stay safe. Falcon OverWatch harnesses the massive power of the
For additional information on the report, please visit the
You can download a complimentary copy of the report here.
About
With
There’s only one thing to remember about
Qualifying organizations can gain full access to Falcon Prevent™ by starting a free trial.
Learn more: https://www.crowdstrike.com/
© 2021
View source version on businesswire.com: https://www.businesswire.com/news/home/20210908005382/en/
press@crowdstrike.com
Source:
FAQ
What does the 2021 Falcon OverWatch report reveal about cyber threats?
Which countries are identified as the most active in cyber intrusions according to the report?
How has the average breakout time for cyber intruders changed?
What trends in malware usage were noted in the report?