2025年全球威胁报告_53页_11mb
报告摘要
CrowdStrike 2025 Global Threat Report Summary
Core Content
The CrowdStrike 2025 Global Threat Report provides an in-depth analysis of the evolving cyber threat landscape, emphasizing the rise of enterprising adversaries who are adopting enterprise-like strategies and leveraging advanced technologies such as generative artificial intelligence (genAI) to conduct more efficient and sophisticated attacks. The report underscores the increasing speed, volume, and complexity of cyber threats, particularly highlighting the shift toward malware-free attack techniques and the growing reliance on identity attacks and vulnerability exploits.
Main Points and Key Information
Adversaries Are Becoming More Business-Like
- Adversaries are using more efficient and focused methods, similar to enterprise organizations, to conduct cyberattacks.
- The enterprising adversary is a central theme of the report, reflecting the increasing sophistication and organization of threat actors.
- GenAI has become a valuable tool for adversaries, enabling them to perform social engineering, disinformation, and influence operations with greater effectiveness.
Increasing Threat Sophistication and Speed
- Breakout time, the time it takes for an adversary to move laterally across a network, has decreased dramatically.
- Average breakout time: 48 minutes
- Fastest breakout time observed: 51 seconds
- Vishing (voice phishing) attacks have seen explosive growth, increasing by 442% in 2024.
- Interactive intrusions are on the rise, with a 35% year-over-year increase in campaigns.
- These attacks rely on hands-on-keyboard techniques that mimic legitimate user behavior, making them harder to detect.
Shift in Initial Access Techniques
- Adversaries are moving away from phishing to alternative access methods, including vishing, callback phishing, and access broker services.
- Access broker activity increased by 50% year-over-year, indicating a growing trend of selling access to other threat actors.
- Valid account abuse was responsible for 35% of cloud-related incidents, highlighting the increasing focus on identity compromise as a gateway to enterprise systems.
China-Nexus Activity
- China-nexus adversaries have seen a 150% increase in activity across all sectors.
- Some industries experienced 200-300% more attacks.
- These adversaries are using operational relay box (ORB) networks to improve operations security (OPSEC) and infrastructure management.
Adversary Examples and Case Studies
-
CURLY SPIDER:
- One of the fastest and most adaptive eCrime adversaries in 2024.
- Executed attacks in under 4 minutes, without needing to breakout to another device.
- Used vishing and RMM tools like Microsoft Quick Assist to gain access.
- Established persistence by modifying registry run keys and using cloud-hosted payloads.
- Connected to Black Basta ransomware operations through collaboration with WANDERING SPIDER.
-
CHATTY SPIDER:
- A Russia-based eCrime adversary using callback phishing to gain access.
- Targets the legal and insurance sectors.
- Demands ransoms up to 8 million USD.
-
PLUMP SPIDER:
- A Brazil-based eCrime adversary focused on wire fraud.
- Uses vishing to direct users to RMM tools and remote support platforms.
- Compromises payment systems for fraudulent financial transfers.
Key Trends
- Malware-free attacks now account for 79% of all detections in 2024, up from 40% in 2019.
- Identity-based attacks are becoming more prevalent, with adversaries exploiting valid credentials and cloud misconfigurations.
- GenAI is being used in social engineering and disinformation campaigns, especially by China-, Russia-, and Iran-affiliated groups.
- Cloud exploitation is increasing, with SaaS-based attacks becoming a major threat vector.
- Proactive threat hunting and AI-native defense strategies are critical for detecting and stopping enterprising adversaries.
Recommendations for Organizations
- Prioritize identity protection to prevent unauthorized access.
- Harden cloud environments against credential abuse and misconfigurations.
- Accelerate response times to counter rapid breakout events.
- Leverage AI-driven threat hunting to detect stealthy adversary movements.
- Implement real-time threat detection to halt intrusions before they spread.
CrowdStrike's Approach to Cyber Defense
- CrowdStrike employs Counter Adversary Operations, combining threat intelligence and proactive hunting to detect and neutralize threats.
- The CrowdStrike Falcon® platform uses AI-native techniques to monitor and analyze trillions of telemetry events.
- The Falcon Adversary OverWatch™ threat hunting team responded to 304 FAMOUS CHOLLIMA incidents in 2024.
- New dashboards and click-to-hunt capabilities help organizations quickly investigate and respond to threats.
- Counter Adversary Playbooks provide a framework for building comprehensive intelligence monitoring programs.
Conclusion
The report emphasizes that adversaries are evolving rapidly, and defenders must adapt to stay ahead. With the rise of enterprising adversaries, genAI, and malware-free attacks, organizations must adopt proactive and AI-enhanced security strategies to mitigate risks and protect their digital assets. The CrowdStrike Falcon® platform and Counter Adversary Operations are central to this effort, offering real-time detection, threat intelligence, and rapid response capabilities.
试读结束,高清完整版pdf/doc/ppt,请点下载