{"id":4595,"date":"2024-04-29T16:35:05","date_gmt":"2024-04-29T04:35:05","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/04\/29\/cybersixgill-2024\/"},"modified":"2025-03-10T17:10:41","modified_gmt":"2025-03-10T04:10:41","slug":"cybersixgill-2024","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/04\/29\/cybersixgill-2024\/","title":{"rendered":"Some thoughts on Cybersixgill&#8217;s State of the Underground 2024 report"},"content":{"rendered":"\n<p>We had a briefing with <a href=\"https:\/\/cybersixgill.com\" target=\"_blank\" rel=\"noreferrer noopener\">Cybersixgill<\/a> earlier this month. To talk threat intelligence, disruption, leveraging generative AI in threat intelligence, supporting SOC analysts with AI-infused analysis, and more. Cybersixgill collects and analyzes 10 million threat signals each day for its threat intelligence service.<\/p>\n\n\n\n<p>Cybersixgill released its annual <a href=\"https:\/\/cybersixgill.com\/company\/press\/cybersixgill-releases-annual-state-of-the-underground-report-revealing-dark-web-threat-actor-activities-and-behaviors-in-2023\" target=\"_blank\" rel=\"noreferrer noopener\">State of the Underground<\/a> report in February (read the press release for the summary and register for the full details in the report). The report itself is 52 pages in length, and covers threat actor trends across six areas, e.g., compromised credit cards, messaging platform usage, initial access. <\/p>\n\n\n\n<p>Here&#8217;s our key takeaways:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Compromised credit cards less of a problem<\/strong><br>The market for compromised credit cards has collapsed over the past 5 years, from 140 million cards in 2019 to 12 million in 2023. Improved fraud detection and prevention is a key contributor to this change.<\/li>\n\n\n\n<li><strong>Less activity on underground forums and messaging apps<\/strong><br>Threat actors are making less use of underground forums and messaging apps, e.g., Telegram. However, much of this is due to significantly less activity by right-wing extremist groups and the disbandment of popular forums.<\/li>\n\n\n\n<li><strong>Vulnerabilities need to be paired with likelihood of exploit to be meaningful in defensive strategies<br><\/strong>There were 7 CVEs introduced in 2023 that scored the highest marks for likelihood of being exploited within the next 90 days. MOVEit Transfer was in first place. In the top 10, half were for Microsoft products.<\/li>\n\n\n\n<li><strong>Stealer malware continues to get worse<br><\/strong>Stealer malware grew in popularity in 2023, with 617 new types of malware (including stealers) mentioned on underground forums. Raccoon Stealer had &gt;50% market share in 2023.<\/li>\n\n\n\n<li><strong>Availability of compromised endpoints for sale increased, too<br><\/strong>The number of compromised endpoints increased (almost doubled, actually), which is problematic since they can be used for data theft, lateral movement, botnet recruitment, and more.<\/li>\n\n\n\n<li><strong>Ransomware attack volumes were down, but ransom payouts up significantly<\/strong><br>Fewer attacks (by around 10%) combined with significantly higher ransom payouts (almost doubled) means ransomware continues to be a significant threat. While the likelihood of being targeted went down, for those that are targeted and compromised, costs are much higher.<\/li>\n<\/ul>\n\n\n\n<p>Thanks to Cybersixgill for assembling such a good resource. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersixgill&#8217;s State of the Underground report highlights declining credit card fraud, reduced forum activity, critical CVEs, rising stealer malware, and increased compromised endpoints for sale. Ransomware attacks decreased, but payouts rose sharply, emphasizing the ongoing threat.<\/p>\n","protected":false},"author":384585,"featured_media":4728,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027499,712027179,21182911],"tags":[712027521],"class_list":["post-4595","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-ransomware","category-threat-intelligence","tag-research-reports-we-didnt-write"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2024\/05\/cybersixgill2024.jpg?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1c7","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4595"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4595\/revisions"}],"predecessor-version":[{"id":4669,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4595\/revisions\/4669"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4728"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}