Darktrace, the cybersecurity firm, has released its First 6: Half-Year Threat Report 2024, identifying key threats and attack methods facing businesses across the first half of 2024.
The findings show that cyber-crime as a service continues to dominate the threat landscape, with malware-as-a-service (MaaS) and ransomware-as-a-service (RaaS) tools being heavily utilised by attackers.
Using these models, cyber-criminals provide access to malicious software and related infrastructure, such as pre-made malware or phishing templates, for a fee. This lowers the barrier of entry for inexperienced attackers to carry out potentially disruptive attacks, regardless of their level of skill or technical ability.
For example, a recent study by Kaspersky revealed that ready made botnet networks, infected with malware, were being sold by cyber-criminals for as little as $99 (£77.87).
According to this latest Darktrace report, information-stealing malware strains were the most commonly observed type of malware attacks between January and June 2024, accounting for 29% of initial findings. The research further identifies the other significant malware threats as being trojans (15%), remote access trojans (12%), botnets (6%), and loaders (6%).
The Darktrace study also reveals the emergence of new threats alongside persistent ones. Notably, the rise of Qilin ransomware, which employs refined tactics such as rebooting infected machines in safe mode to bypass security tools and making it more difficult for human security teams to react quickly.
Phishing emails are reportedly still among the most used tactics for ransomware and malware attackers to gain access to systems, with Darktrace detecting 17.8 million phishing emails across its fleet between December 21st, 2023, and July 5th, 2024.
Of those emails, 56% passed through all existing security layers, 62% successfully passed DMARC authentication, and 550,000 malicious QR codes were detected within them that, when scanned, would direct recipients to a malicious endpoint where attackers can infect a device with malware or steal a user’s login credentials.
The growing sophistication of attacks is also evident in the increase in attackers using popular, legitimate third-party services, such as Dropbox and Slack, to evade detection. By blending in with normal network traffic, attackers can bypass conventional security measures that might otherwise identify or block malicious activity.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
To combat the evolving methods used by attackers, the report emphasises the need for organisations to incorporate AI-driven security measures into their systems, allowing for the detection of malicious activity in real time without relying on prior knowledge of specific tactics.
Commenting on the findings, Nathaniel Jones, director of strategic threat and engagement at Darktrace, said: “The persistence of MaaS/RaaS service models alongside the emergence of newer threats like Qilin ransomware underscores the continued need for adaptive, machine learning powered, security measures that can keep pace with a rapidly evolving threat landscape.”
The rise in overall attacks has been well documented, with recent reports that companies are under critical attack – the type of attack most likely to deplete business resources – for 50 hours out of a 40-hour working week, with 12.6% of all revenues exposed to cyber-threats without proper protection.





