SDN Chronicle

Lockdown: APT Groups Continue to Update, Diversify Their Arsenal

Media Release:

2020 is the year when nothing is the same and yet life goes on, for cybercriminals and APT (Advanced Persistent Threats) groups alike.

The Covid-19 pandemic is actively used as bait for many campaigns, large and small. Kaspersky researchers have seen the continued development of APT arsenals on different fronts – from targeting new platforms and active vulnerability exploitation to shifting to new tools entirely.

These and other APT trends from across the world are covered in Kaspersky’s latest quarterly threat intelligence summary.

A three-month APT trends summary for the last quarter is based on Kaspersky’s private threat intelligence research, as well as other sources that cover the major developments the company’s researchers believe the corporate sector should be aware of.

In Q2 2020, Kaspersky researchers observed multiple developments in the TTPs (Tactics, Techniques and Procedures) of APT groups across the world. The most significant changes were implemented by the following groups:

logo of global cybersecurity firm Kaspersky.

“The threat landscape isn’t always full of “groundbreaking” events, yet cybercriminal activity definitely has not been put on hold over the past few months. We see that the actors continue to invest in improvements to their toolsets, diversify attack vectors and even shift to new types of targets. For instance, the use of mobile implants is no longer a novelty. Another trend we see is the move towards financial gain by some APT groups, such as BlueNoroff and Lazarus. Yet, geopolitics remain an important motive for many threat actors too,” comments Vicente Diaz, security researcher, Global Research and Analysis Team, Kaspersky.

“All these developments only highlight the importance of investing in threat landscape intelligence. Cybercriminals do not stop at what they have achieved already but continually develop new TTPs – and so should those who want to protect themselves and their organizations from attack,” adds Diaz.

The Q2 APT trends report summarizes the findings of Kaspersky’s subscriber-only threat intelligence reports, which also include Indicators of Compromise (IoC) data and YARA rules to assist in forensics and malware hunting. For more information, please contact: intelreports@kaspersky.com

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Exit mobile version