Top attack vectors: October 2021
ID: f1ca2e63-7ec1-5a66-ae57-d2cffe2fc92b
STIX ID: report--f1ca2e63-7ec1-5a66-ae57-d2cffe2fc92b
Feed Name: Expel Blog
In October 2021 the SOC observed three primary attack vectors: vishing to trick users into installing legitimate remote access software (e.g., ScreenConnect, AnyDesk, TeamViewer) to gain interactive endpoint access; a significant rise in crypto-focused malicious activity including cryptojacking and malware that harvests cryptocurrency wallet data (25% of payloads targeting wallets, 50% cryptomining payloads); and persistent phishing/BEC targeting O365 (42% of incidents). The report emphasizes detection and resilience measures—security awareness and vishing training, application allowlisting and EDR coverage, network controls and resource alarms for mining detection, phish-resistant MFA and disabling legacy protocols, and use of hardware wallets for stored crypto.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
