Darktrace, a global leader in cyber security artificial intelligence, today released three new cyber-threat trend reports revealing 2022 attack data observed across its global customer fleet. The industry reports pertain to the energy, healthcare, and retail sectors respectively.
“These industry-specific reports are the first of their kind released by Darktrace, representing an important effort to surface the data underpinning the rapidly evolving threat landscape that we are defending against,” commented Toby Lewis, Global Head of Threat Analysis, Darktrace.
Energy Sector: Key Findings
Against the backdrop of a global energy crisis, Darktrace’s energy sector report reveals that illegal crypto-mining threats, whereby bad actors steal energy and processing power from other devices and networks, are on the rise across the industry. Notable findings include:
- High-priority crypto-mining accounted for 13 times more of all observed cyber incidents in the U.K. energy sector in 2022 compared to 2021
- High-priority crypto-mining accounted for 3 times more of all observed cyber incidents in the U.S. energy sector in 2022 compared to 2021
The report divulges two real-world crypto-mining threat finds from a European and U.S. energy organization respectively, which were both stopped by Darktrace’s AI technology. In the former case, attackers were caught attempting to mass pool crypto-mining capabilities using 5 internal servers at the organization.
Retail Sector: Key Findings
As online shopping remains popular, Darktrace’s retail sector report reveals that over the course of 2022, criminals increasingly turned toward credential theft, spoofing and stuffing to target this multi-billion-dollar industry’s online infrastructure. Notably:
- Credential theft, spoofing and stuffing accounted for over 170% more of all observed cyber incidents in the U.S. retail sector in 2022 compared to 2021
- Credential theft, spoofing and stuffing accounted for over 14% more of all observed cyber incidents in the U.K. retail sector in 2022 compared to 2021
- Credential theft, spoofing and stuffing accounted for over 70% more of all observed cyber incidents in the Australian retail sector in 2022 compared to 2021
One threat find in the report from August 2022 details the discovery of a never-before-seen attack tool lying dormant inside a well-known U.K. automotive retailer. Months before Darktrace had been adopted by the retailer, one of its devices had become infected with novel malware that lay dormant, establishing a foothold and waiting for the right time to launch an attack. After deployment, Darktrace AI caught the malware when it made multiple authentication attempts using spoofed credentials for one of the organization’s security managers. If successful, the attack could have undermined the organization’s entire security posture, allowing malicious software to gain control of the company’s infrastructure from within.
The report details a real-world sophisticated threat faced by a U.S. healthcare provider in which a malicious PowerShell script was discovered to be deployed on one of the organization’s internal servers, an attempt to give bad actors remote control over the target network. The threat was autonomously thwarted by Darktrace’s RESPOND™ technology before attackers could do harm.