2019年中网络攻击趋势报告(英文版)_24页_3mb
报告摘要
2019 Mid-Year Cyber Attack Trends Summary
Core Content
This report outlines the major cyber attack trends observed in the first half of 2019, highlighting the increasing sophistication and diversification of attack methods across various domains. It emphasizes the importance of understanding these threats to enhance organizational security measures.
Main Trends
1. Software Supply Chain Attacks on the Rise
- Overview: Threat actors are increasingly targeting the software supply chain by injecting malicious code into legitimate components.
- Categories:
- Targeted Attacks: Focus on finding the weakest link in a target's supply chain, such as the ShadowHammer attack on ASUS.
- Broad Distribution Attacks: Exploit widely used components to compromise a large number of users, such as MageCart-style attacks on PrismWeb.
- Government Response:
- The US Department of Homeland Security (DHS) established a task force to manage supply chain risks.
- The White House declared foreign supply chain threats a national emergency and banned Huawei.
- Mobile Supply Chain Threats:
- Operation Sheep revealed the SWAnalytics infected SDK, which was used in mobile apps to distribute malware.
- Cybercriminals use the reputation of third-party vendors to distribute malware, leveraging their distribution mechanisms.
2. Email Scams Gear Up
- Overview: Email-based attacks have evolved with more sophisticated tactics to evade detection and establish credibility.
- Key Scams:
- Sextortion Scams: Threaten victims with exposure of personal data, often using credentials from previous breaches.
- Business Email Compromise (BEC): Impersonates legitimate entities (e.g., Microsoft Office 365, Gmail) to trick victims into transferring funds.
- Evasion Techniques:
- Encoded emails, embedded images, and complex underlying code to bypass security solutions.
- Social engineering and personalized content to avoid detection.
- Example: A sextortion campaign falsely claimed to be from the CIA, warning victims of child pornography distribution and demanding $10,000 in Bitcoin.
3. Attacks Against Cloud Environments
- Overview: The rise of cloud adoption has led to increased targeting of cloud resources and data.
- Common Threats:
- Misconfiguration: A major cause of data breaches, as seen with Facebook and Box.com.
- Cloud Cryptomining: Attackers exploit cloud infrastructure for mining, using vulnerable Docker hosts and evading security products.
- New Attack Vectors:
- Cloudborne: Hardware re-provisioning to new customers could retain backdoors for future attacks.
- Recommendation: Enterprises must adopt best security practices to protect cloud assets.
4. The Evolving Mobile Landscape
- Overview: Mobile devices are increasingly targeted due to their role in personal and business activities.
- Key Threats:
- Banking Malware: Rose sharply, with Ramnit and Ursnif being the most prevalent.
- Evasion Techniques: Delayed execution, transparent icons, and encrypted payloads to avoid detection.
- Examples:
- Triada: A powerful Android modular Trojan ranked first in several regions.
- Lotoor: Exploits Android vulnerabilities to gain root access.
- Conclusion: Mobile attacks are becoming more complex and persistent.
5. Ongoing Trends
- Targeted Ransomware:
- Emotet and TrickBot are used to distribute ransomware like Ryuk and LockerGoga.
- Emotet, once a Banking Trojan, has evolved into a modular, self-propagating botnet.
- Cryptominers:
- Despite the CoinHive shutdown, cryptominers remain prevalent.
- CryptoLoot and DarkGate are emerging as significant threats, with DarkGate offering additional capabilities beyond mining.
- DNS Attacks:
- Target the Domain Name System (DNS), manipulating records to compromise networks.
- These attacks allow legitimate-looking certificates and are a major concern for ICANN and DHS.
- Notable campaigns include DNSpionage and SeaTurtle.
Key Information
- Cryptominers: Declined from 42% in 2018 to 26% in 2019 due to CoinHive shutdown, but still a significant threat.
- Ransomware: Targeted attacks have become more destructive, with Emotet and TrickBot playing central roles in distribution.
- Supply Chain Attacks: Highlight the vulnerability of trusted third-party vendors and the need for stricter security protocols.
- Email Scams: Evolved with advanced social engineering and evasion tactics, posing a serious risk to both individuals and organizations.
- Cloud Security: Misconfiguration and poor management remain the top threats, with Cloudborne and Docker exploitation being notable.
- Mobile Threats: Increased in both volume and complexity, with Triada and Lotoor being key examples.
Conclusion
The first half of 2019 has shown that cyber threats are becoming more sophisticated, diversified, and persistent. Organizations must remain vigilant and adapt to the evolving threat landscape by implementing robust security measures, especially in areas such as supply chain integrity, email security, cloud configuration, and mobile device protection.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载