Now Tec BlogNow Tec Blog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Labor wins new mega-donor with £5m for next UK elections

    June 4, 2023

    Saudi Arabia to cut crude oil production by 1 million barrels per day in July | OPEC News

    June 4, 2023

    The role of in-memory computing in the 5G network era

    June 4, 2023
    Facebook Twitter Instagram
    • Home
    • Business

      Labor wins new mega-donor with £5m for next UK elections

      June 4, 2023

      Amazon unfazed by remote workers protesting mandatory return to office

      June 4, 2023

      Saudi Arabia to cut production under new OPEC+ deal

      June 4, 2023

      CEOs need to stay away from AI regulation

      June 4, 2023

      Expected to star in headsets at Apple developer conference

      June 4, 2023
    • Gadgets

      Moon Girl & Devil Dinosaur Season 2 Adds Edward James Olmos

      June 4, 2023

      Legacy of Yangchen YA novel to be released in July

      June 4, 2023

      Final Cut Pro and Logic Pro for iPad make attractive cases for tablet-based studios

      June 4, 2023

      Directors Guild signs three-year employment contract with Hollywood

      June 4, 2023

      Hitting the Books: Why we like bigger things better

      June 4, 2023
    • Tech

      14 Best Laptop Backpacks (2023): Weatherproof, Sustainable and Stylish

      June 4, 2023

      Mathematicians discover hidden structures in common types of space

      June 4, 2023

      Depth sets the stage for action in Tears of the Kingdom

      June 4, 2023

      If Pinocchio doesn’t surprise you, Microsoft’s Sydney shouldn’t surprise you either.

      June 4, 2023

      Apple WWDC 2023: What to expect from software and hardware

      June 4, 2023
    • World

      Saudi Arabia to cut crude oil production by 1 million barrels per day in July | OPEC News

      June 4, 2023

      Pro-Ukrainian fighters attack southern Russia.Prisoner of War Offers | Russo-Ukrainian War News

      June 4, 2023

      Hundreds of thousands march against government in Poland | Protest news

      June 4, 2023

      NATO chief urges Turkey not to veto Swedish alliance | NATO News

      June 4, 2023

      Will Simsek, a market veteran, be able to pull Turkey’s economy back from the brink? | Business and Economic News

      June 4, 2023
    • AI

      Financial Advisors Leverage AI to Work More Efficiently and Faster

      June 4, 2023

      How to create generative AI trust for enterprise success

      June 4, 2023

      Ezra Receives FDA Clearance for AI Tool That Makes MRI Faster and Cheaper

      June 4, 2023

      How researchers used AI to find antibiotics against superbugs

      June 4, 2023

      We asked AI for 5 tips for losing weight… Here are the answers

      June 4, 2023
    • Apple

      How AI will impact Irish tech, accounting and law firm employment – The Times

      June 3, 2023

      Apple WWDC 2023: How to Watch Live and What to Expect

      June 2, 2023

      Apple needs to prove why mixed reality headsets matter

      June 2, 2023

      Apple WWDC 2023 — what it means for you

      June 2, 2023

      Sale: Sonos Get Up To 25% Off Speakers And Soundbars In New Summer Sale

      June 2, 2023
    • ChatGPT

      Will ChatGPT Help or Harm Your Small Business?

      June 4, 2023

      Beware of fake ChatGPT apps: Sophos exposes scam tactics costing users thousands of dollars

      June 4, 2023

      I asked ChatGPT to write a Brother Country song for me, and it was hilariously accurate

      June 4, 2023

      Raspberry Pi Brings Big Mouth Billy Bass to Life with ChatGPT

      June 4, 2023

      When I asked ChatGPT about Polkadot’s price in 2024, the answer was…

      June 4, 2023
    • Cyber Security

      Impact of IMO 2023 on Cybersecurity

      June 4, 2023

      Impact of IMO 2023 on Cybersecurity

      June 4, 2023

      What is Blue Teaming and how does it improve cybersecurity?

      June 4, 2023

      Strengthening cybersecurity in the Canadian financial sector

      June 4, 2023

      10 Best SIEM Tools For SOC Operations

      June 4, 2023
    • Computing

      The role of in-memory computing in the 5G network era

      June 4, 2023

      8 Benefits of Cloud Computing

      June 4, 2023

      A powerful tool for genomic research

      June 4, 2023

      D-Wave: Quantum Computing Might Be With Us (NYSE:QBTS)

      June 4, 2023

      Quantum Computing in Materials Science

      June 4, 2023
    • Science

      Anastasia Paul Named 2023 Outstanding Animal Science Student

      June 4, 2023

      NCERT science curriculum needs to be ‘streamlined’ again

      June 4, 2023

      Food forest cultivated in Science North

      June 4, 2023

      Set in the 1980s HIV/AIDS crisis, Love + Science opens Off-Broadway on June 4

      June 4, 2023

      Scientists identify mysterious ancient marine reptile from 240 million years ago

      June 4, 2023
    Facebook Twitter Instagram
    Now Tec BlogNow Tec Blog
    • Home
    • Business

      Labor wins new mega-donor with £5m for next UK elections

      June 4, 2023

      Amazon unfazed by remote workers protesting mandatory return to office

      June 4, 2023

      Saudi Arabia to cut production under new OPEC+ deal

      June 4, 2023

      CEOs need to stay away from AI regulation

      June 4, 2023

      Expected to star in headsets at Apple developer conference

      June 4, 2023
    • Gadgets

      Moon Girl & Devil Dinosaur Season 2 Adds Edward James Olmos

      June 4, 2023

      Legacy of Yangchen YA novel to be released in July

      June 4, 2023

      Final Cut Pro and Logic Pro for iPad make attractive cases for tablet-based studios

      June 4, 2023

      Directors Guild signs three-year employment contract with Hollywood

      June 4, 2023

      Hitting the Books: Why we like bigger things better

      June 4, 2023
    • Tech

      14 Best Laptop Backpacks (2023): Weatherproof, Sustainable and Stylish

      June 4, 2023

      Mathematicians discover hidden structures in common types of space

      June 4, 2023

      Depth sets the stage for action in Tears of the Kingdom

      June 4, 2023

      If Pinocchio doesn’t surprise you, Microsoft’s Sydney shouldn’t surprise you either.

      June 4, 2023

      Apple WWDC 2023: What to expect from software and hardware

      June 4, 2023
    • World

      Saudi Arabia to cut crude oil production by 1 million barrels per day in July | OPEC News

      June 4, 2023

      Pro-Ukrainian fighters attack southern Russia.Prisoner of War Offers | Russo-Ukrainian War News

      June 4, 2023

      Hundreds of thousands march against government in Poland | Protest news

      June 4, 2023

      NATO chief urges Turkey not to veto Swedish alliance | NATO News

      June 4, 2023

      Will Simsek, a market veteran, be able to pull Turkey’s economy back from the brink? | Business and Economic News

      June 4, 2023
    • AI

      Financial Advisors Leverage AI to Work More Efficiently and Faster

      June 4, 2023

      How to create generative AI trust for enterprise success

      June 4, 2023

      Ezra Receives FDA Clearance for AI Tool That Makes MRI Faster and Cheaper

      June 4, 2023

      How researchers used AI to find antibiotics against superbugs

      June 4, 2023

      We asked AI for 5 tips for losing weight… Here are the answers

      June 4, 2023
    • Apple

      How AI will impact Irish tech, accounting and law firm employment – The Times

      June 3, 2023

      Apple WWDC 2023: How to Watch Live and What to Expect

      June 2, 2023

      Apple needs to prove why mixed reality headsets matter

      June 2, 2023

      Apple WWDC 2023 — what it means for you

      June 2, 2023

      Sale: Sonos Get Up To 25% Off Speakers And Soundbars In New Summer Sale

      June 2, 2023
    • ChatGPT

      Will ChatGPT Help or Harm Your Small Business?

      June 4, 2023

      Beware of fake ChatGPT apps: Sophos exposes scam tactics costing users thousands of dollars

      June 4, 2023

      I asked ChatGPT to write a Brother Country song for me, and it was hilariously accurate

      June 4, 2023

      Raspberry Pi Brings Big Mouth Billy Bass to Life with ChatGPT

      June 4, 2023

      When I asked ChatGPT about Polkadot’s price in 2024, the answer was…

      June 4, 2023
    • Cyber Security

      Impact of IMO 2023 on Cybersecurity

      June 4, 2023

      Impact of IMO 2023 on Cybersecurity

      June 4, 2023

      What is Blue Teaming and how does it improve cybersecurity?

      June 4, 2023

      Strengthening cybersecurity in the Canadian financial sector

      June 4, 2023

      10 Best SIEM Tools For SOC Operations

      June 4, 2023
    • Computing

      The role of in-memory computing in the 5G network era

      June 4, 2023

      8 Benefits of Cloud Computing

      June 4, 2023

      A powerful tool for genomic research

      June 4, 2023

      D-Wave: Quantum Computing Might Be With Us (NYSE:QBTS)

      June 4, 2023

      Quantum Computing in Materials Science

      June 4, 2023
    • Science

      Anastasia Paul Named 2023 Outstanding Animal Science Student

      June 4, 2023

      NCERT science curriculum needs to be ‘streamlined’ again

      June 4, 2023

      Food forest cultivated in Science North

      June 4, 2023

      Set in the 1980s HIV/AIDS crisis, Love + Science opens Off-Broadway on June 4

      June 4, 2023

      Scientists identify mysterious ancient marine reptile from 240 million years ago

      June 4, 2023
    Now Tec BlogNow Tec Blog
    Home»Cyber Security»Editorial: Dragos Industrial Ransomware Attack Analysis – Q1 2023
    Cyber Security

    Editorial: Dragos Industrial Ransomware Attack Analysis – Q1 2023

    eduardo_alves38By eduardo_alves38May 26, 2023Updated:May 26, 2023No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editorial: Dragos Industrial Ransomware Attack Analysis – Q1 2023
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ransomware attacks will continue to pose a significant threat to industry organizations and infrastructure in the first quarter of 2023, highlighting the continued growth in sophistication and opportunism of ransomware groups.

    As such, it is critical that industry organizations remain vigilant and employ robust cybersecurity measures to protect their operations and infrastructure. Twenty of the 61 ransomware groups we track have caused significant damage to industry organizations through the use of continuously evolving tactics.

    Two new important trends were observed in the first quarter. The first is exploitation of zero-day vulnerabilities. The second is the exploitation of a recently discovered vulnerability. For example, in February Clop ransomware group Claimed to have impacted 130 organizations using the GoAnywhere zero-day vulnerability (CVE-2023-0669). Dragos is aware of 14 industry organizations that this group has impacted, but it is unclear if this group used his GoAnywhere vulnerability. Other ransomware groups such as Cuba and Play used a zero-day exploit called OWASSRF to exploit CVE-2022-41080 and Compromise an unpatched Microsoft Exchange server.

    Dragos detected 214 ransomware incidents. This was a 13% increase over the previous quarter. The impact of ransomware attacks on industry organizations has been more difficult and devastating than in previous quarters.For example, Copper Mountain Mining Corporation (CMMC) Affected by AlphaV ransomware, facilitating the separation of ICS/OT networks and the switch to manual operation. Meanwhile, Dole Foods had to temporarily shut down its production plants in North America due to the effects of the large-scale disaster. Ransomware attack on IT systems.

    The motives behind ransomware attacks vary and are often difficult to ascertain with certainty. However, multiple factors can significantly drive ransomware activity, including financial gain, geopolitical tensions, and economic conditions.

    Governments are ramping up efforts and regulations to combat the threat of ransomware. An example in the United States is Ransomware Vulnerability Warning Pilot (RVWP) According to the Cybersecurity and Infrastructure Security Agency (CISA), this Cyber ​​Incident Reporting Under the Critical Infrastructure Act 2022 (Sacia). As part of the RVWP, CISA leverages existing powers and technology to proactively identify information systems with security vulnerabilities commonly associated with ransomware attacks.

    Dragos analyzes ransomware variants affecting industry organizations around the world and tracks ransomware information through public reports and information uploaded or displayed on dark web resources. By their very nature, these sources report victims who allegedly paid or “collaborated” with criminals. However, there is no one-to-one correlation between attacks as a whole and attacks that elicit victim cooperation.

    Here’s a breakdown of ransomware activity this quarter:

    ice cover

    Ransomware by region

    Globally, 44% of the 214 ransomware attacks affected industrial organizations and infrastructure in North America, resulting in a total of 95 incidents. Within North America, he over 41% of all ransomware attacks occurred in the United States. Europe was second with 59 incidents with 28 percent of the global total, followed by Asia with 15 percent and he with 33 incidents. 5% (10%) in South America incident), medium East had 4% (8 cases), Africa 3% (6 cases) and Australia just 1% (3 cases).

    Ransomware by sector and subsector

    Sixty-seven percent of ransomware attacks affected manufacturing (143), the same as last quarter. Food and Beverage was next with 13% (28) of attacks, almost double the number of attacks last quarter. Seven percent of attacks (15 incidents) targeted the energy sector, and 5% (10 incidents) targeted the pharmaceutical sector. Oil & Gas had 3% (7, up from 4 last quarter), while Transportation had around 3% (6). The mining and water sectors were affected, accounting for 1% of all attacks.

    The industrial ransomware incidents we tracked affected 36 unique manufacturing subsectors. The building materials manufacturing sector topped the list with 14 percent (20 attacks), followed by the automotive manufacturing sector with 10 percent (14 attacks). The remaining manufacturing subsectors affected are shown in Figure 1 below.

    Figure 1: Ransomware incidents by sector

    Ransomware by Group

    Dragos tracked the activity of 20 ransomware groups compared to 24 groups in the previous quarter. An analysis of ransomware data shows Lockbit 3.0 accounted for 36% of all ransomware attacks and 77 incidents, almost double the number of incidents last quarter. AlphaV was responsible for 13% of attacks. Royal was next at 12%. Black Busta and Crop Next are each 7%, and Play is 5%. The rest of the attackers are shown in Figure 2 below.

    Figure 2: Ransomware incidents by ransomware group

    Ransomware victim trends

    Dragos continued to monitor the damage trends of ransomware groups. However, this does not determine the permanent focus of these groups, as victimology can change over time. Dragos observed three more ransomware groups impacting industry sectors and regions in this last quarter than in Q4 2022. Based on our Q1 2023 analysis, we observed some of the most active ransomware groups impacting the following industries and regions:

    • abyss, Bianlianand Everest: Manufactured in North America.
    • Avos Locker, royal, not safe, Lorenz: Food and Beverage and Manufacturing.
    • play and like a storm: manufacturing and energy.
    • CL0P leak: Transportation facilities
    • Daishin team: North American Food and Beverages.
    • Malox: Manufacturing and Oil & Gas.
    • black buster: North America and Europe.
    • black bite: North America.

    There were groups that were observed in Q4 2022 but not in Q1 2023 and vice versa. Also, for the first time this year, we observed ransomware groups Medusa Blog, Dark Power, and Unsafe. It is unclear if these new groups are entirely new groups or groups reformed from other groups.

    what’s next?

    We have integrated operational technology (OT) kill processes into ransomware stocks, flattened networks that allow ransomware to spread into OT environments, or proactive production by operators to prevent ransomware. We have high confidence that ransomware will continue to disrupt industrial operations through outages and more. From the spread to industrial control systems. Due to changes in ransomware groups, we are reasonably confident that new or reformed ransomware groups will continue to emerge in the next quarter.

    Furthermore, as victims refuse to pay ransoms and government efforts to ban this continue to erode ransomware groups’ revenues, ransomware groups have turned to industry organizations to meet their financial goals. We rate with some confidence when we step up our damaging efforts.

    Seth Enoka is a Senior Principal Incident Response Consultant at Dragos.

    Editorial: Dragos Industrial Ransomware Attack Analysis – Q1 2023

    Seth_Enoka_vqxht5.jpg

    cyber security logo

    Last updated: May 26, 2023

    Publication date: May 26, 2023



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    eduardo_alves38
    • Website

    Related Posts

    Impact of IMO 2023 on Cybersecurity

    June 4, 2023

    Impact of IMO 2023 on Cybersecurity

    June 4, 2023

    What is Blue Teaming and how does it improve cybersecurity?

    June 4, 2023
    Add A Comment

    Leave A Reply Cancel Reply

    Editors Picks

    Will ChatGPT Help or Harm Your Small Business?

    June 4, 2023

    Beware of fake ChatGPT apps: Sophos exposes scam tactics costing users thousands of dollars

    June 4, 2023

    I asked ChatGPT to write a Brother Country song for me, and it was hilariously accurate

    June 4, 2023

    Raspberry Pi Brings Big Mouth Billy Bass to Life with ChatGPT

    June 4, 2023
    Top Reviews
    Advertisement
    Demo
    Now Tec Blog
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • About us
    • DMCA
    • Privacy Policy
    © 2023 nowtecblog. Designed by nowtecblog.

    Type above and press Enter to search. Press Esc to cancel.