The majority of cyberattacks conducted in 2021 did not use malware, with cybercriminals adapting their tactics to avoid detection.
While there has been numerous warnings about the threat of ransomware, the Global Threat Report from cybersecurity experts Crowdstrike noted that 62% of cyberattacks were malware free in 2021.
According to the company, this trend demonstrates how cybercriminals are increasingly attempting to accomplish their objectives without writing malware to the endpoint.
Instead accessing systems and deploying malware to steal data or money, they have been observed using a ‘living off the land’ (LOTL) approach. This is where threat actors steal legitimate credentials or use built-in tools to enter networks.
This helps them evade detection by legacy antivirus products – which are trained to spot the introduction of malware, not unauthorised intruders masquerading as legitimate users.
However, despite the growing popularity among cybercriminals of malware-free attacks, Crowdstrike also found an 82% increase in ransomware-related data leaks. 2020 saw a total number of 1,474 data leaks taking place after ransomware attacks, hitting 2,686 in 2021.
The dominant motive for cyberattacks was e-crime, where hackers aim to access data for financial reasons. These account for 49% of all activity observed by Crowdstrike.
Meanwhile, targeted intrusions from state-sponsored groups looking to conduct cyber espionage, cause destruction or generate revenue to support a regime accounted for 18% of attacks.
Hacktivist activity, which looks to create visibility or publicity to support a cause or ideology, was responsible for 1%, and the remaining 32% of attacks was unattributed.
The company tracked over 170 adversary groups, with 21 newly named in 2021.
Russia has generally been seen as home to the largest share of cybercriminal groups. A recent report found almost a quarter of spam emails sent in 2021 came from its territory, while another claimed that almost three quarters of money stolen in ransomware attacks that year went to Russia-linked groups.
Recommended
- DIGIT Movers and Shakers | January 2022
- Inform low-income families of ‘social tariffs’ to fight living costs, says Ofcom
- Edinburgh hospitality tech firm finds success despite sector downturn
However, Crowdstrike pointed to the emergence of multiple Iran-nexus adversaries and activity clusters since late 2020.
These groups have adopted the use of ‘lock-and-leak’ attacks — disruptive information operations using ransomware to encrypt target networks and subsequently leak victim information via actor-controlled personas or entities.
The cybersecurity group also noted that China-linked groups were able to exploit new vulnerabilities at a much faster rate in 2021. Since 2020, CrowdStrike Intelligence confirmed a sixfold increase in vulnerability exploitation and linked 10 named adversaries or activity clusters to these attacks.
In addition, two new animals entered the cybersecurity landscape in 2021, joining Russian BEARS, Iranian KITTENS, and criminal SPIDERS – WOLVES, which are linked to Turkey, and OCELOTS, which are connected to Colombia.
Crowdstrike warned that these new adversaries demonstrate the growing offensive capabilities outside of territories traditionally associated with cyber operations.
“In the face of massive disruption brought about by the COVID-driven social, economic and technological shifts of 2020, adversaries refined their tradecraft to become even more sophisticated and brazen,” said CrowdStrike CEO and Co-Founder George Kurtz in the report.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





