2023-02-24-IBM-X-Force_Threat_Intelligence_Index_2023_58页_914kb
报告摘要
2023 X-Force Threat Intelligence Index Summary
This report highlights key trends in cybersecurity threats observed in 2022 by IBM Security X-Force.
Key Findings
Threat Actors and Tactics
- Backdoor Deployment: The most common attack (21% of incidents), often leading to ransomware or data theft.
- Ransomware: Remained the second most frequent attack (17% of incidents), declining slightly from 2021.
- Phishing: Continued as the dominant initial access method (41% of cases), with spear-phishing attachments being the most common sub-technique.
Geographic and Industry Trends
- Asia-Pacific: The most targeted region (31% of incidents), with manufacturing leading in attacks (24.8%).
- Manufacturing: The most targeted industry globally (24.8% of incidents), accounting for 28% of backdoor deployments.
Notable Malware and Campaigns
- Emotet: Resurged due to its variant targeting metadata, contributing to a spike of Emotet cases in 2022 (47% of backdoors globally).
- Rust: Increasingly used in malware due to its evasion capabilities and cross-platform support.
- Ransomware Variants: LockBit (including LockBit 3.0) was the most prevalent family, tied with WannaCry for 17% of attacks.
Impact of the Ukraine War
- Wiper Malware: Unprecedented deployment in Ukraine (AcidRain, WhisperGate, etc.), targeting critical infrastructure.
- Hacktivism: Led to a resurgence of politically motivated attacks (e.g., KillNet, Anonymous).
Vulnerability and Exploit Trends
- Exploit Utilization: Vulnerabilities accounted for 26% of attacks, with a reduced proportion of weaponizable exploits (36% of vulnerabilities vs. 2018).
- Critical Vulnerabilities: Log4j (CVE-2021-45057) and Meltdown/Spectre were top exploited vulnerabilities.
Recommendations
- Know Your Adversary: Focus on threat actors targeting your industry and geography.
- Manage Visibility: Ensure comprehensive monitoring and timely alert actions.
- Be Prepared: Develop and regularly test incident response plans.
Conclusion
- Key Trends: Shift toward container-based malware delivery, rise of Rust-based attacks, and increased targeting of OT/ICS systems.
- Geopolitical Impact: Russia-Ukraine war intensified hacktivism and destructive cyberattacks.
- Challenges: Organizations face evolving extortion tactics and require stronger detection and response capabilities.
For detailed data and vulnerabilities, refer to the full report.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载