Cybersecurity

Emerging Cyber Threats: A Comprehensive Analysis of 2024's Most Prevalent Tactics and Techniques

5 min read

This report, based on analysis provided by Microsoft, explores recent trends in cyber threats from April to June 2024. The findings are drawn from 111 articles published by security researchers, curated by Microsoft Threat Intelligence from various trusted sources and included in Microsoft Defender

Emerging Cyber Threats: A Comprehensive Analysis of 2024's Most Prevalent Tactics and Techniques

This report, based on analysis provided by Microsoft, explores recent trends in cyber threats from April to June 2024. The findings are drawn from 111 articles published by security researchers, curated by Microsoft Threat Intelligence from various trusted sources and included in Microsoft Defender Threat Intelligence as open-source intelligence (OSINT) articles. The analysis focuses on nearly 1,000 MITRE ATT&CK framework tags correlated with each article’s content. By extracting insights from these tags and related intelligence, this report highlights the prevalent tactics, techniques, and procedures (TTPs) observed in the cybersecurity landscape over the past quarter. While not exhaustive, the dataset represents a curated collection of high-profile cyber threat intelligence from the security community.

Understanding trending TTPs is critical for prioritizing cybersecurity efforts. This knowledge enables defenders to make informed decisions about the most effective strategies to implement, particularly in directing engineering efforts and allocating finite resources.

Activity Overview

Initial Access: Phishing Phishing continues to be a dominant initial access method, mentioned in a third of the reports, including spear-phishing attachments and links. The persistence of this technique highlights its effectiveness and underscores the need for robust user education and email security measures.

Defense Evasion: Obfuscated Files or Information Over a third of reports highlighted the use of obfuscation techniques, such as dynamic API resolution and steganography, to evade detection. This trend reflects the growing sophistication of malware designed to bypass traditional security measures and the accessibility of obfuscation tools in the cybercrime market.

Command and Control: Ingress Tool Transfer Ingress tool transfer, the most frequently referenced technique, involves transferring tools from an external system to a compromised one. The prevalence of this tactic is driven by increased OSINT reporting on threat actors misusing the ms-appinstaller URI scheme to distribute malware.

Execution: Command and Scripting Interpreter/PowerShell PowerShell remains a prominent execution method, reflecting its broad adoption in attacks over the past decade. The widespread use of PowerShell to launch malicious code is supported by numerous toolkits that enable quick deployment of a variety of attacks.

Exfiltration: Exfiltration over C2 Channel Exfiltration over the command-and-control (C2) channel is the most commonly referenced exfiltration method, highlighting the need for robust network monitoring and anomaly detection to identify and mitigate data breaches. The rise of infostealers like Lumma and DarkGate, which exfiltrate data via C2 channels, contributes to the prominence of this technique.

Impact: Data Encrypted for Impact Ransomware involving data encryption is the most frequently observed impact technique, with groups like LockBit exploiting vulnerabilities. The continued use of Bring Your Own Vulnerable Driver (BYOVD) tactics, such as Warp AV Killer, underscores the ongoing threat posed by ransomware.

Detailed Analysis

Phishing Phishing remains a significant initial access method, with a third of the reports mentioning its use. This includes spear-phishing attachments and links, which involve deceptive attempts to trick individuals into divulging sensitive information or installing malicious software. The persistence of phishing is attributed to its low cost, high success rate, and the rise of sophisticated phishing kits and phishing-as-a-service on the dark web.

For instance, in June, the French Cybersecurity Agency (ANSSI) identified cyberattacks against French diplomatic entities linked to Nobelium (tracked by Microsoft as Midnight Blizzard). These attacks involved phishing campaigns targeting French public and diplomatic entities to exfiltrate strategic intelligence and attack international IT companies.

Defense Evasion: Obfuscated Files or Information Defense evasion through obfuscation was reported in more than a third of the articles. Techniques such as dynamic API resolution, embedded payloads, and steganography are designed to conceal malicious activity and evade detection by security software. This trend indicates increased sophistication in malware and broader access to obfuscation techniques in criminal marketplaces.

In May, Forcepoint researchers identified a DarkGate malware campaign involving PDF lures impersonating invoices, which led to an AutoIt script that employed obfuscation techniques to hide its operations.

Command and Control: Ingress Tool Transfer Ingress tool transfer, appearing in about a quarter of the OSINT articles, involves transferring tools or files from an external system to a compromised one. Threat actors have increasingly misused the ms-appinstaller URI scheme to distribute malware. For example, in June, the SANS Technology Institute reported a NetSupport campaign delivering a malicious client through MSIX packages.

Execution: PowerShell Execution via PowerShell was mentioned in about a quarter of the reports. PowerShell provides a powerful scripting environment that can be exploited for malicious activities. Its widespread use has led to the development of numerous toolkits for quick deployment of attacks.

In June, Trend Micro discovered that Water Sigbin, a China-based threat actor, exploited Oracle WebLogic server vulnerabilities to deploy cryptocurrency-mining malware using fileless attacks through PowerShell scripts.

Exfiltration: Exfiltration over C2 Channel Exfiltration over the C2 channel, where stolen data is transferred from the target's network to an attacker-controlled location, was the most referenced exfiltration method. Infostealers, which are used to steal information and send it to the attacker, heavily utilize this technique.

In May 2024, FortiGuard Labs identified a Rust-based stealer, Fickle Stealer, which exfiltrated data to a C2 server in JSON format, illustrating the importance of robust security measures to prevent data breaches.

Impact: Data Encrypted for Impact Data encryption for impact, particularly through ransomware, was the most observed impact technique. Ransomware groups continue to exploit known vulnerabilities, with recent campaigns targeting web servers through vulnerabilities like CVE-2024-4577.

In July 2024, Symantec reported that LockBit remained a top ransomware threat, followed by Play and Phobos affiliate 8Base. The persistence of these groups highlights the critical need for comprehensive backup, recovery strategies, and continuous security vigilance.

#CyberSecurity #ThreatIntelligence #CyberThreats #MITREATTACK #Phishing #Ransomware #CyberDefense #Infosec #MalwareAnalysis #DataProtection