Loading...
Report details growing cyber threats from China, rise of RansomHub, and intensifying cyber threat landscape
Trellix Uncovers Diversification of Ransomware Ecosystem as Cybercriminal Use of AI Expands
Media Contact
Sarah Erman
media@trellix.com
Trellix, the company delivering cybersecurity’s broadest AI-powered platform, today released
Severity: Warning Message: Undefined array key 2 Filename: views/newsdetail_view.php Line Number: 97 Backtrace:
File: /home/judfadzm/public_html/webinar4demand.com/application/views/newsdetail_view.php
File: /home/judfadzm/public_html/webinar4demand.com/application/controllers/News.php
File: /home/judfadzm/public_html/webinar4demand.com/application/controllers/News.php
File: /home/judfadzm/public_html/webinar4demand.com/index.phpA PHP Error was encountered
Line: 97
Function: _error_handler
Line: 82
Function: view
Line: 16
Function: index
Line: 317
Function: require_once
Severity: Warning
Message: Attempt to read property "image_name" on null
Filename: views/newsdetail_view.php
Line Number: 97
Backtrace:
File: /home/judfadzm/public_html/webinar4demand.com/application/views/newsdetail_view.php
Line: 97
Function: _error_handler
File: /home/judfadzm/public_html/webinar4demand.com/application/controllers/News.php
Line: 82
Function: view
File: /home/judfadzm/public_html/webinar4demand.com/application/controllers/News.php
Line: 16
Function: index
File: /home/judfadzm/public_html/webinar4demand.com/index.php
Line: 317
Function: require_once
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20241120041969/en/
The top five most active ransomware groups according to Trellix's November CyberThreat Report (Graphic: Trellix)
The research examines an increasingly complex ransomware ecosystem where groups have adopted advanced tools with embedded AI to spread ransomware. Further findings include the accelerated use of endpoint detection and response (EDR) evasion, password spray, infostealer, and backdoor tools and techniques to execute attacks. Trellix telemetry reveals China-affiliated threat actor groups remain a prevalent source of nation-state advanced persistent threat (APT) activities, with Mustang Panda generating more than 12% of detected APT activity alone.
“The last six months delivered AI advancements, from AI-driven ransomware to AI-assisted vulnerability analysis, evolving criminal strategies, and geopolitical events, which have reshaped the cyber landscape. Resilience planning has never been more important for cybersecurity teams,” said John Fokker, Head of Threat Intelligence, Trellix Advanced Research Center. “We’ve seen significant events, including state-sponsored attacks on critical infrastructure, the growth of AI-driven ransomware, and the rise of hacktivism tied to global conflict. The increased use of generative AI by cybercriminals has also posed new challenges. The industry must continue monitoring for transformative use of AI by cybercriminals to strengthen defenses.”
An evolving ransomware ecosystem
With several arrests, the indictment of LockBit leaders, and action to dismantle infrastructure by global law enforcement, the Trellix Advanced Research Center observed a diversification of ransomware groups, expanded use of AI-powered tools to deliver ransom demands, and a focus on tools built specifically to evade endpoint detection and response (EDR) solutions.
The broader cyber threat landscape
The Trellix Advanced Research Center examined industry cyber threat data, with analysis pointing to a rise in attacks from North Korea-aligned group Kimsuky, which doubled the activity of other APT groups. The study of industry reports of cybersecurity events also revealed a targeted distribution across critical sectors, with the government bearing the brunt of attacks (13%), followed by the financial sector (7%) and manufacturing (5%).
The CyberThreat Report: November 2024 includes proprietary data from Trellix’s sensor network, investigations into nation-state and cybercriminal activity by the Trellix Advanced Research Center, and open and closed-source intelligence. It integrates AI-assisted data gathering to enhance the depth and timeliness of insights. The report is based on telemetry related to threat detections, when a file, URL, IP address, suspicious email, network behavior, or other indicator is detected and reported by the AI-powered Trellix Security Platform. This report represents data collected April 1 - September 30, 2024.
Additional Resources:
About the Trellix Advanced Research Center
The Trellix Advanced Research Center is at the forefront of research into the emerging methods, trends, and tools used by cyber threat actors across the global cyber threat landscape. Our elite team of researchers serve as the premier partner of CISOs, senior security leaders, and their security operations teams worldwide. The Trellix Advanced Research Center provides operational and strategic threat intelligence through cutting-edge content to security analysts, powers our industry-leading AI-powered cybersecurity platform, and offers intelligence products and services to customers globally. More at https://www.trellix.com/en-us/advanced-research-center.html.
Follow Trellix on LinkedIn and X.
View source version on businesswire.com: https://www.businesswire.com/news/home/20241120041969/en/