Site navigation

2023 Active Advisory Report: Shorter Dwell Times and Late Patches

Elizabeth Greenberg

,

active advisory report
Attack dwell times are shrinking, vulnerabilities are being patched too late, and threat actors are accessing Active Directory infrastructure – the first half of 2023 is already seeing interesting trends in cybersecurity. 

This is all according to Sophos, a cybersecurity company, which released their Active Adversary Report for Tech Leaders 2023, aimed to outline the major trends and – and dangers – on the cybersecurity sphere in the first half of 2023.

The data found that ransomware was still the most common attack method in the first half of 2023, account for 68.75% of all attacks. This is followed by network breach (16.25%), data extortion (16.25%), and data exfiltration (2.5%).

Importantly, the report highlighted the many vulnerabilities and reasons threat actors always seem just a step ahead of tech leaders and cybersecurity specialists.

Ransomware Dwell Times are Down 

A major finding of the report is the drop in dwell times – the time between when a threat actor access a target’s systems and when the attack is first detected or executed.

In the first half of 2023, the median dwell time declined from 10 days in 2022 to just eight days, but this trend is not true across all cybercrime.

Ransomware appears to be leading the charge – the median dwell times for these incidents fell from nine days to just five days. However, all other non-ransomware incidents rose from 11 to 13 days.

Now, it is not easy to take these metrics in a positive or negative light – the decline could be due to a faster detection and response time to threats, but could also lead to threat actors attempting to go even faster.

Compromised Credentials Top Root Causes

Compromised credentials continually provide access for threat actors to more easily remotely infiltrate a network and breach sensitive data – in the first half of 2023, 50% of root causes for attacks were from compromised credentials, beating out vulnerability exploitation which tallied at 23% of attack routes.

A lack of multi-factor authentication (MFA) makes compromised credentials even easier to use for threat actors to gain network access and expose data – but MFA was not configured in 23% of the cases Sophos investigated in the first half of 2023.

Attackers are Reaching Active Directory

In addition, Sophos X-Ops found that it took on average less than a day — approximately 16 hours — for attackers to reach Active Directory (AD), one of the most critical assets for a company. AD typically manages identity and access to resources across an organization, meaning attackers can use AD to easily escalate their privileges on a system to simply log in and carry out a wide range of malicious activity.

“Attacking an organization’s Active Directory infrastructure makes sense from an offensive view. AD is usually the most powerful and privileged system in the network, providing broad access to the systems, applications, resources and data that attackers can exploit in their attacks. When an attacker controls AD, they can control the organization. The impact, escalation, and recovery overhead of an Active Directory attack is why it’s targeted,” said John Shier the field CTO at Sophos.

“Getting to and gaining control of the Active Directory server in the attack chain provides adversaries several advantages. They can linger undetected to determine their next move, and, once they’re ready to go, they can blast through a victim’s network unimpeded.

“Full recovery from a domain compromise can be a lengthy and arduous effort. Such an attack damages the foundation of security upon which an organization’s infrastructure relies. Very often, a successful AD attack means a security team has to start from scratch.”

Patching Efforts are Too Little, Too Late, Too Often. 

As pointed out by Sophos, patches are vital in removing different vulnerabilities and narrowing the ways in which threat actors can access networks and data.

While patches may be available, they are not always implemented, or systems are not updated to offer better protection and mitigate the effects of vulnerabilities.

Sophos found two instances of patches not being implemented on vulnerabilities in time to stop attacks. Zoho ManageEngine had two vulnerabilities which had a patch available since October 28, 2022, but an advisory was not released until January 10, 2023. Attacks using this vulnerability occurred on 18 and 20 January, 82 days after the patch had been available.

In another case, a ProxyNotShell vulnerability had an advisory published 30 September 2022, an available path on 8 November, but attacks occured on 19 May 2023, leaving a patch gap of 192 days.

Sophos did identify some improvements in 2023, however, in the cases of the 3CX and PaperCut vulnerabilities.

Essentially, patching is important, and patching in a timely manner is vital to stopping attackers from exploiting vulnerabilities.

Threat Actors Don’t Have Office Hours

This was another point Sophos drove home in their report – threat actors do not work a regular nine to five to take holidays, and can actually exploit these slower times to take advantage of a smaller or absent workforce.


Recommended


In 81% of ransomware attacks, the final payload was launched outside of traditional working hours, and for those that were deployed during business hours, only five happened on a weekday.

The number of attacks detected increased as the week progressed, most notably when examining ransomware attacks. Nearly half (43%) of ransomware attacks were detected on either Friday or Saturday.

“In some ways we’ve been victims of our own success,” Shier said.  “As adoption of technologies like XDR (extended detection and response) and services such as MDR (managed detection and response) grows, so does our ability to detect attacks sooner. Lowering detection times leads to a faster response, which translates to a shorter operating window for attackers. At the same time, criminals have been honing their playbooks, especially the experienced and well-resourced ransomware affiliates, who continue to speed up their noisy attacks in the face of improved defences.”

“But, it doesn’t mean we’re collectively more secure. This is evidenced by the levelling off of non-ransomware dwell times. Attackers are still getting into our networks, and when time isn’t pressing, they tend to linger. But all the tools in the world won’t save you if you’re not watching. It takes both the right tools and continuous, proactive monitoring to ensure that criminals have a worse day than you do. This is where MDR can really close the gap between attackers and defenders, because even when you’re not watching, we are,” said Shier.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data