2019年第四季度网络安全威胁论报告(英文版)_31页_4mb
报告摘要
Cybersecurity Threatscape Summary - Q4 2019
Core Content
This document outlines the cybersecurity threatscape in Q4 2019, highlighting the increasing complexity and frequency of cyberattacks across various sectors and attack methods.
Main Points
- Increase in Cyberincidents: There was a 12% rise in the number of unique cyberincidents compared to the previous quarter.
- Targeted Attacks: The share of targeted attacks increased by 2 percentage points, reaching 67%, due to a surge in APT (Advanced Persistent Threat) attacks against individual organizations and entire industries.
- Top Attack Targets: The most targeted sectors included government, industry, finance, healthcare, and education. IT and retail also saw a significant increase in attacks.
- Payment Card Information: Payment card data accounted for 32% of all stolen data from organizations, a 25% increase from the previous quarter, attributed to the holiday season and MageCart attacks.
- Ransomware Trends: Ransomware attacks increased in danger, with 36% of malware infections targeting organizations and 17% targeting individuals. Attackers began publishing stolen data if ransom is not paid, as companies increasingly use backups.
- Attack Methods: Malware use, credential compromise, social engineering, hacking, and web attacks were the primary methods used by cybercriminals.
- Social Engineering: 54% of attacks in Q4 2019 used social engineering combined with malware. Phishing emails, fake documents, and QR codes were common tools.
- Hacking: Vulnerabilities such as BlueKeep and CVE-2019-11043 were exploited to deliver malware and perform attacks. Attackers also used browser exploits to mimic technical support.
- Web Attacks: Web resources were frequently targeted by hacktivists and for stealing user credentials. SQL injection and DoS attacks were notable.
- Credential Compromise: Attackers used brute-force attacks and harvested credentials from breached databases. These were often sold on the darkweb or published freely.
Key Information
Attack Targets
- Computers, servers, and network equipment
- Web resources
- Humans
- POS terminals and ATMs
- Mobile devices
- IOT (Internet of Things)
Attack Methods
- Malware use: Ransomware was the most prevalent, with groups like Sodinokibi, Maze, Ryuk, and Bitpayer causing widespread damage.
- Credential compromise: Attackers used weak passwords to infect devices and add them to botnets for mining or DDoS attacks.
- Social engineering: Phishing emails and fake documents were used to trick users into revealing sensitive information.
- Hacking: Exploitation of known vulnerabilities allowed attackers to gain unauthorized access and control.
- Web attacks: Hacktivists and cybercriminals targeted web resources to steal data or disrupt services.
Victim Categories
- Government: Targeted by APT groups like Gamaredon and Bisonal, with a high use of malware and social engineering.
- Industrial Companies: Faced attacks from groups such as RTM, often involving malware and credential theft.
- Financial Institutions: Targeted for financial gain and data theft.
- Healthcare: Suffered from ransomware and data breaches.
- IT: Experienced attacks targeting their infrastructure and services.
- Retail: Suffered from MageCart attacks and other web-based threats.
- Individuals: 10% of all attacks targeted individuals, with credentials being a major form of stolen data.
- Telecom and Blockchain: Also targeted, though less frequently than other sectors.
Recommendations
For Companies
- Implement robust backup systems to mitigate ransomware risks.
- Monitor and detect APT attacks through advanced threat monitoring.
- Secure web resources against vulnerabilities and breaches.
For Vendors
- Ensure products are secure and updated to prevent exploitation of known vulnerabilities.
- Collaborate with security researchers to identify and patch potential security holes.
For Users
- Avoid opening suspicious attachments and links.
- Be cautious with mobile devices and avoid jailbreaking unless necessary.
- Use strong passwords and enable multi-factor authentication.
About the Research
The report is conducted by Positive Technologies, focusing on the Q4 2019 cybersecurity landscape. It includes data on attack methods, targets, and trends, with insights from threat monitoring and expert analysis.
Group Profiles
- Gamaredon: Targeted Ukrainian government and military organizations, using template injection to bypass antivirus detection.
- Bisonal: Attacked government institutions in Mongolia, South Korea, and Russia, using RTF documents with exploits for CVE-2018-0798.
- SongXY: Also targeted government institutions, using similar tactics as Bisonal.
- RTM: Actively attacked industrial companies in Russia and the CIS, as well as other sectors like government and finance.
Additional Notes
- The use of social engineering combined with malware is a growing trend.
- The rise in ransomware attacks is driven by the increasing use of backups by companies.
- The holiday season and the popularity of MageCart attacks contributed to the surge in payment card data theft.
- Attackers are adapting their tactics to bypass traditional security measures, such as email security gateways and antivirus software.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载