Which is the most dangerous global hacking cyber group? – AlienVault research

Stu Sjouwerman | Feb 2, 2018

AlienVault researchers have listed Sofacy, also known as Fancy Bear or APT28, as the most capable hacking group in the world. This was based on ranking the top threat actors which have been reported the most frequently on the AlienVault Open Threat Exchange (OTX) Platform.

The results were then formulated to measure the cyber group’s activity (the number of times AlienVault vendors reported them) alongside the measure of their known capabilities over the past two years:

 

otx_2

Sofacy gained notoriety in the past for targeting NATO and defence ministries and have most recently expanded their operations by targeting multinational organisations and individuals. In second place is Lazarus, who is reported to be operating from North Korea. Although extremely active, their attacks are mainly focused on South Korea.

Three years ago, these positions could easily have been dominated by Chinese groups. However, according to OTX research, there has been a significant decrease in the number of targeted attacks on western organisations by threat actors located in China. Stone Panda, ranked in at number 10, is the highest threat actor operating out of China.

Interestingly, there was only one threat actor among the top five with a primary motive for economic gain. The Anunak/ Carbanak malware was well documented in the news with the group behind the attack reportedly stealing over $500 million from various financial institutions. It is thought that the Anunak toolset is shared discretely among a select few in the criminal cyber world.

This research was analysed and produced using AlienVault’s OTX platform, a sharing platform for daily cyber threats, and concludes a three-part series.

Part 1 focused on exploits tracked by OTX, with the most commonly reported being CVE-2017-0199 on Microsoft Office. Part 2 addresses malware, with MjRat Variants ranking as the most frequently detected malware.

Source: ITSecurityGuru.org

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.