IT threat evolution Q2 2024
ID: 33d6af2c-48b5-580c-84ca-9ea88f5346ad
STIX ID: report--33d6af2c-48b5-580c-84ca-9ea88f5346ad
Feed Name: Securelist by Kaspersky
This report details multiple high-risk threats: a sophisticated supply-chain backdoor was introduced into the XZ/liblzma build to subvert OpenSSH (CVE-2024-3094) and was shipped in major Linux distributions; targeted campaigns (DuneQuixote, ToddyCat) and numerous malware families (CR4T, QakBot exploits, various stealers) are actively used for data theft and persistent access; the LockBit builder continues to enable customized ransomware operations and law enforcement disruption did not fully stop activity; and novel ransomware (ShrinkLocker) abuses BitLocker to render recovery difficult. The report highlights attacker sophistication, active exploitation evidence, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
