CrowdStrike’s Annual Threat Report Reveals Uptick Around Ransomware and Disruptive Operations; Exposes Evolution of eCrime Ecosystem
CrowdStrike (NASDAQ: CRWD) released its 2022 Global Threat Report, revealing an alarming 82% increase in ransomware-related data leaks, with 2,686 attacks recorded in 2021. The report introduced new adversaries, WOLF from Turkey and OCELOT from Colombia, and highlighted that eCrime activity constituted 49% of intrusion attempts. Additionally, adversaries are evolving tactics, with 62% of recent detections being malware-free. The report emphasizes the ongoing threat of nation-state actors like Russia, Iran, and China, prompting businesses to enhance their security strategies.
- Released the 2022 Global Threat Report, providing critical cybersecurity insights.
- Reported an 82% increase in ransomware-related data leaks, indicating rising threat awareness.
- Introduced new adversaries, enhancing the understanding of the threat landscape.
- Noted that 49% of intrusion attempts were attributed to financially motivated eCrime.
- 62% of recent detections were malware-free, indicating a shift in adversary techniques.
- The increase in ransomware-related attacks shows a growing threat landscape.
- Emerging adversaries like WOLF and OCELOT may pose additional risks to cybersecurity.
- Heightened activity from nation-state actors could lead to increased operational disruptions for businesses.
Report reveals adversaries adopt the use of “lock-and-leak” operations; identifies expanded targeting of Cloud Service Providers by
The landmark CrowdStrike Intelligence report documents both the continued evolution of nation-state affiliated and criminal adversaries, as well as the increased sophistication, velocity and impact of targeted ransomware, disruptive operations and cloud-related attacks in 2021. Key findings in this year's report give organizations the insight required to mature their security strategies and defend their businesses against prolific cyber threats.
Nation-State and Criminal Groups Continue to Expand
The 2021 threat landscape became more crowded as new adversaries emerged. CrowdStrike Intelligence today tracks more than 170 in total. Notable adversary updates include:
-
Financially motivated eCrime activity continues to dominate the interactive intrusion attempts tracked by CrowdStrike OverWatch. Intrusions attributed to eCrime accounted for nearly half (
49% ) of all observed activity. -
Iran -based adversaries adopt the use of ransomware as well as “lock-and-leak” disruptive information operations – using ransomware to encrypt target networks and subsequently leak victim information via actor-controlled personas or entities. -
In 2021,
China -nexus actors emerged as the leader in vulnerability exploitation and shifted tactics to increasingly targeting internet-facing devices and services like Microsoft Exchange. CrowdStrike Intelligence confirmedChina -nexus actor exploitation of 12 vulnerabilities published in 2021. -
Russia -nexus adversary COZY BEAR expands its targeting of IT to cloud service providers in order to exploit trusted relationships and gain access to additional targets through lateral movement. Additionally, FANCY BEAR increases the use of credential-harvesting tactics, including both large-scale scanning techniques and victim-tailored phishing websites. -
The
Democratic People's Republic of Korea (DPRK) targeted cryptocurrency-related entities in an effort to maintain illicit revenue generation during economic disruptions caused by the COVID-19 pandemic. -
eCrime actors — including affiliates of DOPPEL SPIDER and WIZARD SPIDER — adopted Log4Shell as an access vector to enable ransomware operations. State-nexus actors, including NEMESIS KITTEN (
Iran ) and AQUATIC PANDA (China ), were also affiliated with probable Log4Shell exploitation before the end of 2021.
Adversary Tradecraft Becomes More Sophisticated
The report highlights that the startling growth and impact of targeted ransomware, disruptive operations and an uptick in cloud-related attacks in 2021 was a palpable force felt across nearly every industry and in every country.
-
CrowdStrike Intelligence observed an
82% increase in ransomware-related data leaks in 2021, with 2,686 attacks as ofDecember 31, 2021 , compared to 1,474 in 2020.
-
The
CrowdStrike eCrime Index (ECX) depicts that ransomware attacks were highly lucrative spanning all of 2021.The ECX displays the strength, volume and sophistication of the cybercriminal market, and is updated weekly based on 20 unique indicators of criminal activity, tracking things like Big Game Hunting victims, data leaks, and ransom demands. Over the course of 2021, CrowdStrike’s ECX noted the following:
○
○ CrowdStrike Intelligence saw on average over 50 targeted ransomware events per week.
○ Observed ransomware-related demands averaged
-
Adversaries are increasingly exploiting stolen user credentials and identity to bypass legacy security solutions – of all detections indexed in the fourth quarter of 2021,
62% were malware-free.
“As cyber criminals and nation-states around the world continue to adapt in the changing, interconnected landscape, it’s critical that businesses evolve to defend against these threats by integrating new technologies, solutions and strategies,” said
Download the 2022 CrowdStrike Global Threat Report.
About
Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities.
Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value.
Learn more: https://www.crowdstrike.com/
Follow us: Blog | Twitter | LinkedIn | Facebook | Instagram
Start a free trial today: https://www.crowdstrike.com/free-trial-guide/
©2022
View source version on businesswire.com: https://www.businesswire.com/news/home/20220215005198/en/
press@crowdstrike.com
Source:
FAQ
What does the 2022 CrowdStrike Global Threat Report reveal about ransomware?
Which new adversaries were introduced in the 2022 CrowdStrike report?
How did eCrime activity perform according to the CrowdStrike report?
What trends were noted regarding malware in the CrowdStrike report?