Mandiant M-Trends 2022 Report Provides Inside Look at the Evolving Global Cyber Threat Landscape Directly from the Frontlines
Mandiant, Inc. (NASDAQ: MNDT) released its M-Trends 2022 report, showcasing cyber threat evolution and response metrics from October 2020 to December 2021. Key findings include a global median dwell time reduction from 24 days in 2020 to 21 days in 2021, with the APAC region experiencing the most significant drop. The report highlights over 1,100 new threat groups and 733 malware families tracked during the period, emphasizing China's increasing cyber espionage efforts. The report also stresses the importance of security preparedness amid rising ransomware and supply chain attacks.
- Global median dwell time decreased from 24 days to 21 days, indicating improved detection.
- APAC region experienced the most significant reduction in median dwell time from 76 days to 21 days.
- Mandiant tracked 1,100+ new threat groups and 733 malware families, enhancing threat intelligence.
- The report highlights an overall improvement in threat detection and response capabilities.
- China's cyber espionage activities are increasing, posing risks to intellectual property.
- Ransomware attacks targeting virtualization infrastructure are on the rise.
Global median dwell time continues to decline; however, a significant number of new threat groups and malware families have emerged
Global Median Dwell Time Drops to Three Weeks
According to the M-Trends 2022 report, the global median dwell time––which is calculated as the median number of days an attacker is present in a target’s environment before being detected––decreased from 24 days in 2020 to 21 days in 2021. Digging deeper, the report notes that the APAC region saw the biggest decline in median dwell time, dropping to just 21 days in 2021 compared to 76 days in 2020. Median dwell time also fell in EMEA, down to 48 days in 2021 compared to 66 days the year before. In the
When comparing how threats were detected across different regions, the report found that in EMEA and APAC, the majority of intrusions in 2021 were identified by external third parties (
Organizations’ improved threat visibility and response as well as the pervasiveness of ransomware––which has a significantly lower median dwell time than non-ransomware intrusions––are likely driving factors behind reduced median dwell time, per the report.
New Threats Emerge as China Ramps Up Espionage Activity
M-Trends 2022 also notes a realignment and retooling of
Strengthening Security Posture
To further support community and industry efforts,
Additional takeaways from M-Trends 2022 Report include:
-
Infection Vector: For the second year in a row, exploits remained the most frequently identified initial infection vector. In fact, of the incidents that
Mandiant responded to during the reporting period,37% started with the exploitation of a security vulnerability, as opposed to phishing, which accounted for only11% . Supply chain compromises increased dramatically, from less than1% in 2020 to17% in 2021. -
Target industries impacted: Business and professional services and financial were the top two industries targeted by adversaries (
14% , respectively), followed by healthcare (11% ), retail and hospitality (10% ) and tech and government (both at9% ). -
New Multifaceted Extortion and Ransomware TTPs:
Mandiant observed multifaceted extortion and ransomware attackers using new tactics, techniques and procedures (TTPs) to deploy ransomware rapidly and efficiently throughout business environments, noting that the pervasive usage of virtualization infrastructure in corporate environments has made it a prime target for ransomware attackers.
Executive Quotes
“This year’s M-Trends report reveals fresh insight into how threat actors are evolving and using new techniques to gain access into target environments. While exploits continue to gain traction and remain the most frequently identified infection vector, the report notes a significant increase in supply chain attacks. Conversely, there was a noticeable drop in phishing this year, reflecting organizations’ improved awareness and ability to better detect and block these attempts. In light of the continued increased use of exploits as an initial compromise vector, organizations need to maintain focus on executing on security fundamentals––such as asset, risk and patch management.” –
“Multifaceted extortion and ransomware continue to pose huge challenges for organizations of all sizes and across all industries, with this year’s M-Trends report noting a specific rise in attacks targeting virtualization infrastructure. The key to building resilience lies in preparation. Developing a robust preparedness plan and well-documented and tested recovery process can help organizations successfully navigate an attack and quickly return to normal business operations.” –
“Chinese cyber espionage activity ramped up significantly in recent years, with
"Several trends from previous years continued into 2021.
M-Trends 2022 Methodology:
The metrics reported in M-Trends 2022 are based on
Resources:
- M-Trends 2022 Report: https://www.mandiant.com/m-trends
- Blog: https://www.mandiant.com/resources/m-trends-2022
- M-Trends 2022 Virtual Summit: https://www.brighttalk.com/summit/5120-m-trends-virtual-summit/
- Defender’s Advantage Podcast: https://www.mandiant.com/resources/podcasts/defenders-advantage/m-trends-2022
About
Since 2004,
Join the conversation. Follow us on Twitter, LinkedIn, Facebook, and YouTube.
© 2022
View source version on businesswire.com: https://www.businesswire.com/news/home/20220419005242/en/
Media
Media.Relations@Mandiant.com
Investors
Investor.Relations@Mandiant.com
Source:
FAQ
What does the Mandiant M-Trends 2022 report reveal about median dwell time?
How many new threat groups were identified in the Mandiant report?
What is the significance of supply chain attacks in the M-Trends 2022 report?
What are the main industries targeted by cyber attacks according to the report?