Site navigation

Comment | The Cyber-crime Threat Landscape in 2023

Mike McLellan

,

cyber-crime threat 2023
Russian escalation, Chinese espionage, Iranian “hacktivism” and the threat of cybercrime – Mike McLellan, Director of Intelligence at Secureworks, breaks down the geopolitical factors shaping cyber security threats for the year.

2022 saw its fair share of cyber security headlines.

The Russian invasion of Ukraine highlighted how states might use offensive cyber operations to support kinetic military operations. China and Iran were both publicly accused of targeting human rights organisations. And ransomware and businessemail compromise continued to jostle for top spot as the main cybercrime threat organisations face.

Beyond the headlines, we saw some interesting shifts in both tools and tactics of cyber adversaries.

Already 2023 has had a number of significant cyber moments, not least of which was a ransomware attack on Royal Mail, part of the UK’s critical infrastructure. As the cyber community gathers for ScotSecure, it is a great time to take stock and predict the trends that we think will shape the threat landscape in 2023.

State-sponsored activity

In 2022, we saw increased levels of state-sponsored activity, originating from a number of countries

But the drivers behind the activity and the tactics used varied widely. This will continue into 2023, as governments use their cyber capabilities as one way of advancing their economic and political goals.

Russian cyber activity will be split between targeting Ukraine and advancing its broader intelligence objectives

With no prospect of an immediate end to the conflict in Ukraine, we can expect more conflict-related cyber activity aimed at degrading Ukraine’s critical infrastructure and government services and collecting foreign intelligence useful to the Russian government from entities engaged in the war effort.

Groups tied to the Russian intelligence services will also continue to target geographic neighbours with disinformation campaigns, intelligence gathering, and possibly low-level disruptive attacks.

However, Russia also continues to pursue its broader long-term intelligence objectives. Traditional espionage targets will continue to be a focus; for example, we saw evidence through the summer of 2022 of Russian intelligence services using spear phishing emails to target staff at two national laboratories in the U.S. that conduct cutting edge energy research.

Large scale, covert intelligence gathering by Russian state-sponsored threat actors will continue, enabled through the exploitation of cloud environments, internet backbone infrastructure, or pervasive identity management systems.

China will continue to prioritise political and economic cyber espionage

Economic and political motives will continue to drive China’s intelligence gathering activity.

The newly re-elected Xi Jinping and his Chinese Communist Party will continue to use its intelligence apparatus to help meet broader economic and social objectives as it strives to maintain control, for example in its approach to COVID-19. Surveillance of dissident groups and individuals critical of the Chinese government will also continue, including through ongoing targeting of international non- governmental organisations.

Chinese threat actors will likely continue to target high-tech companies that operate in or supply industries such as energy, manufacturing, housing, and natural resources as it looks to upgrade its domestic industries.

Foreign governments will also continue to be a focus, particularly in East Asia and in relation to China’s Belt and Road Initiative. We are keeping a close eye on the developing geopolitical situation around Taiwan and the South China Sea, although it is likely that much of the pre-positioning required to enable disruptive cyberattacks against critical infrastructure in the event of an invasion will have already occurred.

Iranian government-sponsored harassment and cybercrime will overlap

The way in which the Iranian intelligence services outsource operations to cyber security organisations in Iran blurs the lines between state-sponsored activity and cybercrime. We have seen this recently with the IRGC-affiliated COBALT MIRAGE threat group, who conduct espionage but also financially motivated ransomware attacks.

That cybercrime activity is by its nature opportunistic, meaning that it has and will continue to impact organisations of all shapes and sizes globally.

We anticipate the continuation of low intensity conflict between Iran and regional adversaries, particularly Israel. Operations conducted under the guise of hacktivism and cybercrime will actually be intended to disrupt critical infrastructure, leak sensitive information, and expose foreign intelligence operatives.

Organisations should be wary of Iran and other hostile states using faked social media personas to socially engineer their intended targets.

The cybercrime landscape

Opportunistic cybercrime threats will continue to be the main problem for most organisations. This is not a problem without a solution; many, many organisations are successfully defending themselves daily. Incidents typically happen due to a failure or lack of security controls.

Organisations can mitigate this threat if they invest in fundamental security controls such as asset management, patching, multi-factor authentication and security monitoring.

Ransomware-as-a-Service will remain prosperous

The Ransomware-as-a-Service (RaaS) landscape will continue to be dominated by a handful of organised cybercrime groups operating a limited number of highly active schemes.

New ransomware variants will continue to appear and disappear but will likely find it hard to establish a significant market presence. Successful schemes will continue attract more affiliates, but scheme operators will need to be vigilant for rogue affiliates undermining their business model by targeting critical infrastructure and misjudging the intensity of the ensuing political and law enforcement reaction.

The ‘detection window’ between initial access to an environment and the deployment of ransomware will continue to shrink.

We’ll also see experienced threat actors operating as affiliates of these established RaaS schemes to make attribution more difficult and evade sanctions enforced by the U.S. and other authorities that target named cybercriminals.

Extortion-only attacks will rise in popularity

Despite being relatively unsophisticated by nature, extortion attacks will continue to shed light on gaps in organisations’ security controls and will increase in number this year. However, ransomware attacks will remain more popular for cybercriminals because they provide a greater return onnvestment.

Primary vectors will continue to change

Attackers move with the times and are constantly looking for new ways to outfox security teams and gain access to networks.

This will continue in 2023 as the threat landscape evolves.

We expect to see a particular focus on bypassing multi-factor authentication as this critical security control continues to see increased adoption rates by organisations and individuals.

AI will not significantly alter the threat landscape, at least not yet

There has been a lot of attention around AI-generated content, especially with the emergence of tools such as ChatGPT. The security industry occasionally likes to overstate the threat posed by sophisticated attacks that use AI and machine learning technologies.


Recommended


The reality is that attackers will do no more than the bare minimum required for them to be successful. ‘Traditional’ tools and techniques continue to be effective and is the more immediate threat that we need to defend against.

Over the course of the year, we’ll see a lot of hype around AI, deepfakes and the like, which risks becoming a distraction for security teams.

The importance of a well-rounded defence strategy

The pace of the cybersecurity industry shows no signs of slowing down as we head into 2023. The pressure on security teams is relentless, so they too must be relentless in their pursuit of protecting organisations.

Getting the basics of good cyber hygiene nailed down is an absolute must. Maintaining a solid understanding of the threat landscape and the tactics used by adversaries is an important step, but security teams must also look to identify and protect their key assets and prioritise vulnerability management.

Not only is it critical to comprehensively monitoring the entire network, from endpoints to cloud assets, as traditional techniques and point solutions like endpoint detection and response are no longer effective in fighting today’s threats. But it’s vital that businesses are equipped to filter out and prioritise the most important threats to their business to mitigate them efficiently and effectively.

This holistic approach will be vital to ensuring security against nation states and cybercrime gangs alike over the next 12 months.

Mike McLellan

Director of Intelligence at Secureworks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data