{"id":800992,"date":"2024-03-15T12:03:44","date_gmt":"2024-03-15T12:03:44","guid":{"rendered":"https:\/\/telecomlive.in\/web\/2024\/03\/15\/data-and-credential-theft-malware-top-two-threats-against-smbs-in-2023-ransomware-remains-biggest-cyberthreat-says-sophos-report\/"},"modified":"2024-03-15T12:03:44","modified_gmt":"2024-03-15T12:03:44","slug":"data-and-credential-theft-malware-top-two-threats-against-smbs-in-2023-ransomware-remains-biggest-cyberthreat-says-sophos-report","status":"publish","type":"post","link":"https:\/\/telecomlive.in\/web\/2024\/03\/15\/data-and-credential-theft-malware-top-two-threats-against-smbs-in-2023-ransomware-remains-biggest-cyberthreat-says-sophos-report\/","title":{"rendered":"Data and credential theft malware top two threats against SMBs in 2023, ransomware remains biggest cyberthreat, says Sophos report"},"content":{"rendered":"<p>Data and credential theft malware were top two threats against small- and medium-sized businesses (SMBs) with nearly 50 per cent of malware detections for SMBs being keyloggers, spyware and stealers, malware that attackers use to steal data and credentials, said a report by Sophos. In its annual 2024 Sophos Threat Report, the company that delivers cybersecurity as a solution, said that attackers subsequently use this stolen information to gain unauthorized remote access, extort victims, deploy ransomware, and more. <\/p>\n<p>The Sophos report also analysed initial access brokers (IABs)\u2014criminals who specialize in breaking into computer networks. As seen in the report, IABs are using the dark web to advertise their ability and services to break specifically into SMB networks or sell ready-to-go-access to SMBs they\u2019ve already cracked.<\/p>\n<p>\u201cThe value of \u2018data,\u2019 as currency has increased exponentially among cybercriminals, and this is particularly true for SMBs, which tend to use one service or software application, per function, for their entire operation. For example, let\u2019s say attackers deploy an infostealer on their target\u2019s network to steal credentials and then get hold of the password for the company\u2019s accounting software. Attackers could then gain access to the targeted company\u2019s financials and have the ability to funnel funds into their own accounts,\u201d said Christopher Budd, Director of Sophos X-Ops research at Sophos. \u201cThere\u2019s a reason that more than 90 per cent of all cyberattacks reported to Sophos in 2023 involved data or credential theft, whether through ransomware attacks, data extortion, unauthorized remote access, or simply data theft.\u201d<br \/>\nRansomware still the biggest cyberthreat to SMBs <\/p>\n<p>While the number of ransomware attacks against SMBs has stabilized, it continues to be the biggest cyberthreat to SMBs. Out of the SMB cases handled by Sophos Incident Response (IR), which helps organizations under active attack, LockBit was the top ransomware gang wreaking havoc. Akira and BlackCat were second and third, respectively. SMBs studied in the report also faced attacks by lingering older and lesser-known ransomware, such as BitLocker and Crytox, it said.<\/p>\n<p>Ransomware operators continue to change ransomware tactics, according to the report. This includes leveraging remote encryption and targeting managed service providers (MSPs). Between 2022 and 2023, the number of ransomware attacks that involve remote encryption\u2014when attackers use an unmanaged device on organizations\u2019 networks to encrypt files on other systems in the network\u2014increased by 62 per cent. <\/p>\n<p>In addition, this past year, Sophos\u2019s Managed Detection and Response (MDR) team responded to five cases involving small businesses that were attacked through an exploit in their MSPs\u2019 remote monitoring and management (RMM) software.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data and credential theft malware were top two threats against small- and medium-sized businesses (SMBs) with nearly 50 per cent of malware detections for SMBs being keyloggers, spyware and stealers, malware that attackers use to steal data and credentials, said a report by Sophos. In its annual 2024 Sophos Threat Report, the company that delivers cybersecurity as a solution, said that attackers subsequently use this stolen information to gain unauthorized remote access, extort victims, deploy ransomware, and more. The Sophos report also analysed initial access brokers (IABs)\u2014criminals who specialize in breaking into computer networks. As seen in the report, IABs [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[7],"tags":[],"class_list":["post-800992","post","type-post","status-publish","format-standard","hentry","category-it-2"],"acf":[],"_links":{"self":[{"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/posts\/800992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/comments?post=800992"}],"version-history":[{"count":0,"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/posts\/800992\/revisions"}],"wp:attachment":[{"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/media?parent=800992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/categories?post=800992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomlive.in\/web\/wp-json\/wp\/v2\/tags?post=800992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}