Connect with us

Hi, what are you looking for?

HEADLINES

Report shows up to 300% increase in attacks from opportunistic targeting

Healthcare, manufacturing, and finance industries all saw an increase in attacks (200%, 300%, and 53% respectively), with these top three sectors accounting for a combined total of 62% of all attacks in 2020, up 11% from 2019.

NTT Ltd., a global technology services provider, launched its 2021 Global Threat Intelligence Report (GTIR), which reveals how hackers are taking advantage of the global destabilization by targeting essential industries and common vulnerabilities from the shift to remote working. Healthcare, manufacturing, and finance industries all saw an increase in attacks (200%, 300%, and 53% respectively), with these top three sectors accounting for a combined total of 62% of all attacks in 2020, up 11% from 2019. 

As organizations race to offer more virtual, remote access through the use of client portals, application-specific and web-application attacks spiked, accounting for 67% of all attacks, which has more than doubled in the past two years. Healthcare bore the brunt of these attacks from its shift to telehealth and remote care, with 97% of all hostile activity targeted at the industry being web-application or application-specific attacks.

The GTIR provides insights from NTT’s Cybersecurity Advisory that applies a maturity score of an industry’s security program, with a higher number indicating a more mature plan of action. Concerningly, healthcare and manufacturing have relatively low maturity scores of only 1.02 and 1.21, respectively. These have decreased from 2019’s baseline of 1.12 and 1.32, while attack rates have significantly risen. Manufacturing has experienced a three-year decline in scores, most likely due to changes in the operating environment and the evolution of attacks. On the other hand, finance continued to demonstrate the highest maturity benchmark score for the third consecutive year, of 1.84, a 0.02 decrease on last year, however. 

Kazu Yozawa, CEO of NTT’s Security division, says: “Last year we predicted a surge in targeted, opportunistic attacks and unfortunately, this has proven all-too-true. While these industries have done their best to maintain essential services throughout disruptive times, the fall in security standards when companies need them most is alarming. As services continue to move online and become increasingly digital to account for the new normal, organizations must be extra vigilant in upholding and maintaining best practices in their security.”

Malware sees a metamorphosis: Crypto malware surges while Trojans become more common

While malware is becoming more commoditized in features and functionality, it also became more diverse over the last year with the growth of multi-function malware. Cryptominers have replaced spyware as the most common malware in the world, but the use of certain variants of malware against specific industries continues to evolve. Worms appeared most frequently in the finance and manufacturing sectors. Healthcare was impacted by remote access trojans, while the technology industry was targetted by ransomware.  The education sector was hit by cryptominers due to the popularization of mining among students who exploit unprotected infrastructures.

Advertisement. Scroll to continue reading.

The crypto-currency market is a prime example, with cryptominers accounting for a staggering 41% of all detected malware in 2020. XMRig coinminer was the most common variant, representing nearly 82% of all coinminer activity and nearly 99% in EMEA specifically. 

Mark Thomas, who leads NTT’s Global Threat Intelligence Center comments: “On one hand you have threat actors taking advantage of a global disaster, and on the other, cybercriminals capitalizing on unprecedented market booms. The common thread throughout both of these situations is unpredictability and risk. Changes in operating models or adoption of new technologies present opportunities for malicious actors and with a surging crypto-currency market popular among inexperienced students; attacks were bound to happen. Now, as we enter a more stable phase of the pandemic, organizations and individuals alike must prioritize cybersecurity hygiene across all industries, including the supply chain.”

Further 2021 GTIR highlights:

  • Attacks against manufacturing increased from 7% last year to 22%; healthcare increased from 7% to 17%; and finance is up from 15% to 23%.
  • Organizations in multiple industries saw attacks related to the COVID-19 vaccine and associated supply chains.
  • COVID-19 cybercriminal opportunism intensified, with groups such as the Ozie Team, Agent Tesla and TA505, along with nation-state actors like Vicious Panda, Mustang Panda and Cozy Bear very active in 2020.
  • The most commonly occurring forms of malware in 2020 were Miners: 41%; Trojans: 26%; Worms: 10%, Ransomware 6%.
  • Cryptominers dominated activity in Europe, the Middle East and Africa (EMEA) and the Americas but were relatively rare in Asia Pacific (APAC).  
  • OpenSSL was the most targeted technology in the Americas but was not even on the top 10 list in APAC.  
  • Ongoing fallout following the Schrems II decision invalidated the EU-US Privacy Shield and placed additional obligations on organizations transferring personal data from the EU to third countries.
  • NTT’s research shows that 50% of organizations globally are prioritizing securing their cloud services – making it the top cybersecurity focus over the next 18 months.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

While investigating ForumTroll, researchers identified that the attackers used a spyware LeetAgent, which stood out due to its commands written in leetspeak, a rare...

HEADLINES

Based on the latest Kaspersky Industrial Control Systems Cyber Emergency Response Team (ICS CERT) report, the Southeast Asia cluster recorded the highest global rates...

HEADLINES

This new solution for Sophos XDR and Sophos MDR continuously monitors customer environments for identity risks and misconfigurations and scans the dark web for...

White Papers

As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate – meaning users have become more accustomed to jumping through hoops to...

HEADLINES

The Philippines’ the Cybercrime Investigation and Coordinating Center (CICC) has recently raised alarm over the proliferation of deepfakes, particularly AI-generated pornographic content. The call...

HEADLINES

From identity theft to deepfakes, fraud is evolving fast, leaving businesses struggling to keep up. A fragmented, siloed system creates critical blind spots: when...

White Papers

Despite the Chinese government’s internet restrictions and eCrime crackdown, anonymized marketplaces remain central to cybercrime activity across Asia Pacific and Japan (APJ).

HEADLINES

13% of critical alerts went unnoticed or misclassified, giving attackers an opening to exploit weak points such as identity recovery workflows and lateral movement...

Advertisement