SOPHOS-2021在不确定的世界中驾驭网络安全(英文)-2021.3-36页_3mb
报告摘要
Sophos 2021 Threat Report Summary
Core Content
The Sophos 2021 Threat Report provides an in-depth analysis of the evolving cybersecurity landscape, focusing on ransomware, everyday enterprise threats, the impact of the pandemic, and emerging risks on nontraditional platforms. The report emphasizes the importance of collaboration and shared intelligence in combating cyber threats.
Main Points
Ransomware
- Ransomware evolution: Ransomware actors are increasingly using data theft as a secondary extortion tactic, not just encrypting data.
- Ransom increases: Ransom demands have risen significantly, with the average ransom payout increasing by 21% in the last quarter and nearly tripling over the past year.
- Collaboration among threat actors: Ransomware groups are collaborating more closely, acting like cybercrime cartels rather than isolated entities.
- Attack speed: Ransomware attacks are becoming faster, with some completing in hours instead of days or weeks.
- Backup destruction: Attackers are now targeting and destroying backups to ensure victims have no alternative but to pay the ransom.
- Data exfiltration tools: Attackers use legitimate tools like Total Commander, 7zip, and Mega.nz to steal and store data without detection.
Everyday Threats to Enterprises
- Server attacks: Windows and Linux servers are frequently targeted, often due to their access to sensitive data and lack of monitoring.
- RDP as a vector: Remote Desktop Protocol is a common entry point for attackers, used for both initial access and lateral movement.
- Commodity malware: Even "ordinary" malware like Dridex and Emotet can lead to major breaches if not detected early.
- Security hygiene: Many attacks stem from poor security practices, such as weak passwords and unpatched systems.
- Malware as content distribution networks: Some malware families are evolving to act as distribution channels for other malicious payloads.
Impact of the Pandemic (COVID-19)
- Remote work challenges: The shift to remote work expanded the attack surface, with home networks now part of the enterprise perimeter.
- Cloud computing: Cloud services are used extensively for secure operations but also become targets for data exfiltration.
- Social engineering: Attackers used pandemic-related themes to exploit trust and gain access to organizations.
- Self-organized response: Cybersecurity professionals globally formed the CCTC (COVID-19 Cyber Threat Coalition) to combat pandemic-driven attacks, acting as a not-for-profit commons.
Nontraditional Platforms
- Mobile malware: Android Joker malware is on the rise, and ads/PUAs are becoming harder to distinguish from malware.
- Security tool abuse: Attackers are leveraging security tools and utilities for malicious purposes.
- Digital epidemiology: Data scientists are applying epidemiological techniques to analyze malware and spam, improving detection and response.
Key Takeaways
- Collaboration is key: Sharing threat intelligence and working together across the industry is crucial for effective cybersecurity.
- Ransomware is becoming more sophisticated: With increased collaboration among threat actors and faster attack methods, ransomware is more dangerous than ever.
- Security hygiene remains critical: Basic security practices are often the first line of defense against many attacks.
- Cloud and remote work introduce new risks: These trends have created new attack vectors that require updated defenses.
- Commodity malware can be dangerous: Even common malware can cause significant damage if not properly managed.
- Data exfiltration is a growing concern: Attackers are using this tactic to increase pressure on victims to pay ransoms.
Conclusion
The report highlights the need for continued collaboration, improved security practices, and adaptive defense strategies. As cyber threats evolve, so must our response, with a focus on real-time threat intelligence sharing, enhanced cloud security, and proactive measures against both traditional and nontraditional attack vectors.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载