How Nation-State Cybercriminals Are Targeting the Enterprise
ID: b5c22083-5d83-5634-a054-e99867ffe33b
STIX ID: report--b5c22083-5d83-5634-a054-e99867ffe33b
Feed Name: Dark Reading
This commentary outlines how nation-state cyber operations have expanded from traditional critical infrastructure to a broader range of enterprises, citing groups like Velvet Ant, GhostEmperor (with the Demodex rootkit), and Volt Typhoon. It contrasts mission-driven nation-state objectives with ransomware ROI motives, describes persistence and evasion tactics (e.g., exploiting legacy F5 BIG-IP as internal C2, log tampering, lateral movement), and recommends proactive measures such as rehearsed response playbooks, optimized detection/visibility, AI-driven tooling, and pre-crisis collaboration with government and industry peers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
