IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the most-targeted sectors
ID: adec086b-e748-5968-bc37-d7ced16524d3
STIX ID: report--adec086b-e748-5968-bc37-d7ced16524d3
Feed Name: Cisco Talos
Talos Incident Response reports ransomware was the top observed threat in Q4 2023 (28% of engagements), documenting first-time responses to Play, BlackSuit, Cactus, and NoEscape operations; common initial access vectors included compromised credentials, exploited public-facing applications (e.g., ZeroLogon and Citrix Bleed), and phishing (including malicious QR codes), with attackers leveraging tools such as AnyDesk, ScreenConnect, PsExec, Mimikatz, Cobalt Strike and Sliver for credential theft, lateral movement, exfiltration, and encryption; education and manufacturing were the most targeted sectors and Talos recommends stronger MFA adoption, patching prioritization, and mobile device management to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
