HP Threat Research Blog Five Cybercrime Trends to Expect in the Year Ahead

January 20, 2023 Category: Threat Research By: HP Wolf Security Comments: 0

Five Cybercrime Trends to Expect in the Year Ahead

The HP Wolf Security Threat Insights team has seen the cyber threat landscape evolve significantly in the past year. Threat actors are working together more closely, trading access to networks, malware strains, and attack techniques. Commoditization is driving cheaper malware – our recent Evolution of Cybercrime report found three-quarters of malware kits cost less than $10 – making cybercrime a simpler and more appealing option compared to other types of crime. Tightened budgets in 2023 will mean organizations need to do more with less when it comes to security. So, we will likely see more users – and their PCs and printers – end up in the crosshairs of attackers in the coming year.

As cybercrime becomes more collaborative against a backdrop of economic downturn, here are some of the key security trends organizations should keep in mind during 2023:

1. Intentional Investing in Cybersecurity Will be Key for 2023

Although cybersecurity spending is set to increase by 13.2% in 2023, budgets will be under scrutiny to focus only on the most pressing cybersecurity needs. So, it’s important to be intentional about where to invest. Good governance means appropriately handling a company’s resources, including budgets. With an ocean of security issues to boil, understanding which areas expose the company to the most risk is essential.

Security leaders must think about their organization’s value proposition while understanding risk appetite and position on the business curve – whether you’re in hyper-growth or pivoting into a new market. These factors help you contextualize which assets to focus on and where new risks may emerge. Then you can figure out the best areas to prioritize and what investments are needed.

It’s important to consider grouping certain risks, for example, in service businesses people are their most valuable ‘assets’. Here, applying technologies like isolation can help defend against the most common attacks targeting those workers – such as malware and social engineering. There may be gaps in basic cyber hygiene within the organization’s supply chain footprint that need addressing.

Essentially, know the highest risk areas throughout the business, know where is most likely to be targeted, and know how much you can afford to invest. A solid cybersecurity foundation can ensure maximum resilience.

2. More Cyber Hustlers and Money Mules Could Appear in the Wake of Rising Costs

The rise of platform-based business models has created a cybercrime gig economy that makes cyberattacks easier, cheaper and more scalable. This is enticing cyber hustlers – opportunists with low levels of technical skill – to access what they need to turn a profit.

Email is the most common attack vector, particularly for opportunists looking to make money fast with simple techniques like scams and phishing. So, an economic downturn could increase the number of scam emails we see in our inboxes.

In the interconnected cybercrime ecosystem, threat actors can easily monetize these types of attacks. And if they compromise a corporate device, they can sell that access to bigger players, like ransomware gangs. We may also see more people recruited into money-muling schemes looking to make money fast, enabling cybercriminals to launder ransom payments and fraudulent transactions. This all feeds into the cybercrime engine, giving organized groups even more reach.

As attacks against users increase, security must be baked into people’s PCs from the hardware up – so they can easily prevent, detect and recover from attacks using tools like HP Sure Recover. Isolating risky activities is an effective way of eliminating entire classes of threats without relying on detection. Threat containment technology like HP Sure Click Enterprise ensures that if a user opens a malicious link or email attachment, the malware can’t infect the endpoint. This way organizations can protect employees without hindering their workflows.

3. Established Hackers to Invest in Advanced Attacks Below the Operating System

In 2023, organizations should take control of firmware security. Once, firmware attacks were only used by highly advanced threat groups and nation states. But over the last year, we’ve seen early signs of increased interest and development of attacks below the operating system in the cybercrime underground – from tools to hack BIOS passwords, to rootkits and trojans targeting a device’s firmware. We now see firmware rootkits advertised on cybercrime marketplaces for a few thousand dollars.

Advanced threat actors are always aiming to keep their attack capabilities ahead of the curve. Unfortunately, organizations often overlook firmware security, creating a large attack surface for adversaries to exploit. Access to the firmware level enables attackers to gain persistent control and hide below the operating system, making them very hard to detect – let alone remove and remediate.

Organizations should follow best practices and standards to secure device hardware and firmware. They should also evaluate state of the art technology that is available to protect, detect, and recover from such attacks like HP Sure Start, Sure Recover, Sure Admin, or Tamper Lock.

4. Remote and Privileged Access will be on the Frontline

We expect session hijacking – where an attacker commandeers a remote access session to access sensitive data and systems – will increase in 2023. By targeting users with privileged access to data and systems – like domain, IT, cloud and system administrators – these attacks are higher impact, challenging to detect and more difficult to remediate.

In an attack scenario, the targeted user will typically be unaware that a compromise has occurred. It takes milliseconds for an attacker to inject key sequences that could create a backdoor within a privileged environment. These attacks are all the more dangerous because they can bypass Privileged Access Management (PAM) systems that employ multi-factor authentication, such as smart cards.

Suppose such an attack involves an industrial control system operating within a factory or industrial plant. The intrusion could impact availability and, potentially, physical safety. Carefully segregating access to systems is the only way to counter these attacks. Traditionally, organizations would achieve this through physically separate systems, like privileged access workstations, but now hypervisor-based approaches like HP Sure Access Enterprise use virtualization to enforce strong virtual separation too.

5. Nation State Trickle Down Increases Prospect of Threat Actors Exploiting Printers for Financial Gain

This year, we could see print security’s WannaCry moment as nation state techniques exploiting printers trickle down to the wider cybercrime economy – just as we saw with the EternalBlue leak. This will lead to cybercrime groups exploiting printers for financial gain. There’s plenty of motivation for doing so. Accessing printers could allow attackers to capture confidential documents and data for ransomware purposes or use the printer as a launch point to other devices on corporate networks.

Aiding attackers in these efforts is a plethora of exposed and unsecured print devices, handling sensitive information and even connecting to corporate devices. Compromising these devices and hijacking them will be easy pickings, as few see their printer as an attack vector.

To defend against attacks on printers, organizations must improve cyber security hygiene. Updates must be applied regularly, and devices should be regularly monitored and analyzed to see if they are in a breach state. Overlooking print security leaves a gaping hole in cybersecurity posture, one attackers will gladly walk through on their way to your organization’s crown jewels.

Combatting Rising Threats

No matter what threats organizations face in 2023, the way we protect devices and data needs to evolve. Boardrooms will need to be smart about how they allocate their resources. Meanwhile, security teams will need excellent visibility of which areas of the organization are most at risk and the impact of a breach.

Most breaches start at the endpoint, so HP Wolf Security’s layered and integrated approach to security, which starts at the hardware level, will enable organizations to manage their cyber risk – reducing their attack surface against current and growing threats. By building resilience into systems, organizations can gain actionable security insights into their environment and keep key data protected.

About the Author

HP Wolf Security

Recent Posts

2023-01-20T14:03:11+00:00January 20th, 2023|Threat Research|