惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Exploits, Access, Extortion: Know Your Enemy in 2024 and ...
Intel 471 · 2024-05-07 · via Intel 471 Blog

Arm Yourself with Knowledge in The 471 Cyber Threat Report 2024

It’s time to arm yourself against cybercrime with the Intel 471 Cyber Threat Report 2024, our comprehensive cyber threat intelligence (CTI) analysis of threat actor activity and techniques from January 2023 to March 2024. We also look at the varied motivations of hacktivist groups, ransomware gangs, and initial access brokers (IABs), and highlight emerging trends to help you stay ahead of a rapidly changing threat landscape.

In the past year, law enforcement agencies have notched significant wins against major ransomware-as-a-service (RaaS) operators, disrupting ALPHV aka BlackCat in December 2023 and LockBit in February 2024. These, however, occurred at the end of a year in which reported ransomware attacks almost doubled to 4,429. LockBit was again the most prevalent ransomware variant, impacting 981 victims, followed by ALPHV, which impacted 427 victims, many in healthcare and other critical sectors.

It’s too early to tell whether these victories will leave a lasting impact on RaaS operators. LockBit’s response demonstrated the sophistication of the underground cybercrime economy. After re-establishing the LockBit data leaks blog, its victim-shaming site, the actor threatened to buy compromised network access credentials related to all U.S. government, educational, and nonprofit organizations from IABs.

Additionally, Intel 471 saw activity from IABs, a key enabler in cybercrime, grow and shift in 2023. We reported 5,347 instances of IAB vendors offering compromised credentials and/or alleged unauthorized access to networks or systems in 2023. We also track “specified access” when there are indicators that a threat actor has verified the validity of access being sold as operational.

See the report to also find out which industries and countries were most impacted and the most common IAB tactics, techniques, and procedures (TTPs) we observed. This rapidly evolving threat landscape is one reason Intel 471 recently acquired Cyborg Security and its HUNTER platform, which gives threat hunting teams a powerful set of tools to proactively detect stealthy threats.

Other major factors that will influence cybercrime trends in 2024 include:

  • Hacktivism: The pro-Russian NoName057(16) group accounted for almost 60% of all hacktivist incidents during 2023. Intel 471 observed shifting alliances within hacktivist groups, and the reignition of the Israeli-Palestinian conflict in October caused significant fluctuations in activity, with Cyber Toufan becoming the most active pro-Palestinian group.
  • Malware: Infostealers accounted for 21% of all malware-related offerings. This dominance is expected to persist into 2024 due to the efficiency, profitability, and low entry barrier they provide cybercriminals.
  • Vulnerabilities: Intel 471’s Vulnerability Intelligence team found a 43% increase in zero-day vulnerabilities in 2023.
  • Looming Cyber Threats: The online ecosystem known as “TheCom” enabled individuals to form small subgroups with experienced threat actors online and combine techniques to elevate their capabilities of breaching corporations.
  • Artificial Intelligence and Deepfakes: Deepfakes were named one of the most common ways threat actors leveraged AI in 2023. With AI rapid advancements, threat actors were able to create deepfake content in a cost-effective way.

Download the 2024 Cyber Threat Report today to see the culmination of Intel 471’s dedication to exposing the tactics of global adversaries which we share in real time with clients through TITAN, our platform that collects, interprets, structures, and validates human-led, automation-enhanced results.