THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Saturday, June 11, 2022
Discussing the three most critical areas of web security: ransomware, web applications and APIs, and DNS traffic.
FREMONT, CA: A study discovered results on threat actor behaviour via popular attack traffic and methodologies after analysing trillions of data points across numerous platforms. The three papers discuss the most important security developments and create a realistic picture of today's attack landscape. An examination of a Web app and API attack trends provides a fresh look at the infection vectors used by ransomware operators and others, while an analysis of ransomware attack trends highlights the risks and suggests mitigation. An examination of DNS supplements the reports by providing a picture of overall attacks as seen through one of the internet's most fundamental technologies.
With the development of Ransomware-as-a-Service (RaaS) attacks, Akamai studied and identified the most recent and effective components of ransomware attackers' methodology, tools, and strategies, including those used by the Conti ransomware gang. The following are some of the key findings:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
● Sixty per cent of successful Conti assaults targeted American corporations, while thirty per cent targeted European Union companies.
● The threat of supply chain disruption, critical infrastructure effects, and supply chain hacks are all highlighted in an examination of the industries targeted.
● The most effective Conti assaults target companies with revenues ranging from USD 10 million to USD 250 million, demonstrating a "goldilocks" spectrum of successful attack targets among middle and small enterprises.
● The group's tactics, methods, and procedures are well-known, a grim reminder of the tools at other hackers' disposal. However, with the correct mitigation, these attacks can be avoided.
● Conti's article stresses hacking and hands-on propagation above encryption, which should encourage network defenders to focus on those sections of the death chain as well, rather than just the encryption phase.
Significant rises in web application and API attacks were detected across the globe in the first half of 2022, with more than nine billion attack attempts to date. The following are the specifics for each of the company's major observations:
● In the first half of this year, web application attack attempts against customers increased by more than 300 per cent year over year, the biggest increase was ever seen.
● LFI assaults have now surpassed SQLi attacks as the most common WAAP attack vector, with a year-over-year increase of approximately 400 per cent.
● Commerce has been the most heavily damaged vertical, accounting for 38 per cent of recent attack activity, while technology has experienced the biggest growth so far in 2022.
Researchers discovered the following after analysing more than 7 trillion DNS queries every day and proactively identifying and blocking threats such as malware, ransomware, phishing, and botnets:
● More than one out of every ten monitored devices communicated with domains linked to malware, ransomware, phishing, or command and control at least once.
● According to phishing traffic, the majority of victims were targeted by scams that exploited and imitated technological and financial companies, which affected 31 per cent and 32 per cent of victims, respectively.
● According to a study that looked at over 10,000 harmful JavaScript samples — including malware droppers, phishing pages, fraudsters, and crypto-miner malware — at least 25 per cent of the samples used JavaScript obfuscation techniques to avoid detection.
More in News