THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, December 06, 2021
Advanced persistent threats target companies, governments, and freedom campaigners, to mention a few. This activity evolves as more threat actors improve their skills.
FREMONT CA: Kaspersky announced its advanced threat forecasts for 2022, and the company's ideas on the scenario for the year ahead are rather interesting. According to him, there will be new advanced threats this year.
Recent legal cases against offensive security firms like NSO have highlighted the usage of surveillance software. NSO, an Israeli firm that provides aggresive security, is accused of supplying governments with malware that targets journalists and activists. Following the action, the U.S. Department of Commerce added NSO to its list of entities for violating US national security or foreign policy objectives. The department added Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE LTD to the list (Singapore).
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Hacking mobile devices is not new, but it is incredibly sensitive. Kaspersky emphasized a key distinction between Android and iOS, the two major mobile operating systems. As a result, Android has a more criminal-oriented malware environment, whereas iOS is usually targeted by advanced nation-state sponsored cyberespionage. The Pegasus case revealed by Amnesty International 2021 brought a new dimension to the iOS zero-click, zero-day attacks.
The mandatory rule of working from home in pandemic creates opportunities for attackers to compromise corporate networks. Social engineering and brute-force attacks can gain corporate service credentials. And utilizing personal devices at home rather than business ones makes it easier for attackers. New opportunities to exploit home computers that are not fully patched or protected will be looked at by threat actors to gain an initial foothold on corporate networks.
The rising geopolitical tensions around the Middle East and Turkey, along with Africa's rapid urbanization and massive investment, are likely to increase the number of large APT assaults in the META region, particularly in Africa.
Cloud security offers several benefits for businesses worldwide, but access is usually restricted to a single password or API key. Outsourced services like online document management or file storage also contain data that APT threat actors may find valuable. According to Kaspersky, those will, draw state actors and become major targets in sophisticated attacks.
Attackers avoid low-level bootkits because they are more likely to cause system failures. It also takes more effort and talent to build them. The offensive research on bootkits is still going on, and more complex implants are predicted. Aside from that, if secure boot becomes more common, attackers will need to uncover exploits or weaknesses in this security mechanism, Kaspersky stated.
In 2021, cyberwarfare increased the use of legal indictments in hostile operations. Yet states who denounce APT operations are often conducting their own at the same time. Those will need to create a distinction between the cyberattacks that are acceptable and those that are not. Kaspersky believes some countries will publish their taxonomy of cyber-offense in 2022, detailing which types of attack vector and behavior are off-limits.
More in News