Cyber-criminals’ use of automated scanning techniques surged over the last year, rising by more than 16% to 36,000 scans per second in 2024, revealing an intensified focus on threat actors’ desire to map exposed services.
Published in its latest Global Threat Landscape Report, FortiGuard Labs analysis shows that cyber-criminals are using automated scanning to capitalise on zero-day vulnerabilities and exposed digital infrastructure, targeting services such as SIP and RDP and IoT protocols like Modbus TCP.
Threat actors were also witnessed harnessing more AI tools to enhance their phishing attempts and evade traditional security controls, with services like FraudGPT, BlackmailerV3, and ElevenLabs making more attacks more believable, scalable and effective, without the ethical restrictions of publicly available AI tools.
While scanning tactics and AI make the work of malicious actors easier, FortiGuard’s report shows that darknet marketplaces are the backbone of their business, offering cheap access to neatly packaged exploit kits, automated programs used to hack systems or applications.
In 2024, cyber-criminal forums increasingly operated as sophisticated marketplaces for these exploit kits, with over 40,000 new vulnerabilities added to the National Vulnerability Database, a 39% rise from 2023.
As well as providing the means for attacking these zero-day vulnerabilities, initial access brokers on the darknet are increasingly offering corporate credentials (20%), RDP access (19%), admin panels (13%), and web shells (12%).
Added to that, FortiGuard said it had also observed a 500% increase in the past year in logs available for systems compromised by infostealer malware, with 1.7 billion stolen credential records shared in these underground forums.
Last year, cyber-criminals shared over 100 billion compromised records on darknet forums, a 42% year-over-year spike, driven largely by the rise of “combo lists” containing stolen usernames, passwords, and email addresses.
More than half of darknet posts involved leaked databases, enabling attackers to automate credential-stuffing attacks at scale, while well-known groups like BestCombo, BloddyMery, and ValidMail continued to lower the barrier to entry by packaging and validating these credentials, driving a surge in account takeovers, financial fraud, and corporate espionage.
Meanwhile, targeted attacks on critical sectors intensified over 2024.
Industries such as manufacturing, healthcare, and financial services experienced a surge in cyber-attacks, with adversaries deploying sector-specific exploitations, with the most targeted sectors being manufacturing (17%), business services (11%), construction (9%), and retail (9%).
The scale at which cyber-criminals can tailor their threats and the speed at which they can act means organisations should take actionable measures to mitigate the risks they pose.
Recommended reading
- Surge in Darknet Activity Ahead of 2024 US Election
- Report: Phishing Clicks Surged 190% in 2024
- How Worried Are Brits About AI-Fuelled Phishing?
According to FortiGuard, firms should therefore look to shift away from traditional threat detection and towards continuous exposure management, including the automation of detection and defence responses, as well as breach and attack simulation (BAS) tools to regularly assess real-world attack scenarios.
Attack surface management is also critical, with FortiGuard’s report emphasising the need for investment in tools to detect exposed assets, leaked credentials, and exploitable vulnerabilities while continuously monitoring darknet forums for emerging threats.
“Cyber-criminals are accelerating their efforts, using AI and automation to operate at unprecedented speed and scale,” said Derek Manky, chief security strategist and VP for threat intelligence at Fortinet.
“The traditional security playbook is no longer enough. Organisations must shift to a proactive, intelligence-led defence strategy powered by AI, zero trust, and continuous threat exposure management to stay ahead of today’s rapidly evolving threat landscape.”





