Le Lézard
Classified in: Science and technology
Subject: Survey

Elastic Global Threat Report 2023 Reveals Dominance of Ransomware


Elastic® (NYSE: ESTC) ("Elastic"), the company behind Elasticsearch®, today announced its second Elastic Global Threat Report, issued by Elastic Security Labs. Based on observations from more than 1 billion data points over the last 12 months, the report reveals ransomware is expanding and diversifying; more than half of all observed malware infections were on Linux systems; and credential access techniques have become an essential part of the cloud intrusion process.

Key findings from the report include:

Malware Trends

The majority of malware observed was composed of a small number of highly prevalent ransomware families and commercial off-the-shelf (COTS) tools. As financially motivated threat communities adopt or offer malware-as-a-service (MaaS) capabilities, enterprises should heavily invest in developing security functions with broad visibility of low-level behaviors to expose previously undiscovered threats.

Endpoint Behavior Trends

The most sophisticated threat groups evade security by withdrawing to edge devices, appliances, and other platforms where visibility is at its lowest. As never before, the report highlights the need for enterprises to evaluate the tamper-resistant nature of their endpoint security sensors and consider monitoring projects to track vulnerable device drivers used to disable security technologies. In addition, organizations with large Windows environments should track vulnerable device drivers to disable these essential technologies.

Cloud Security Trends

As enterprises increasingly migrate on-premises resources to hybrid or entirely cloud-based environments, threat actors are taking advantage of misconfigurations, lax access controls, unsecured credentials, and no functional principle of least privilege (PoLP) models. Organizations can dramatically reduce the risk of compromise by implementing the security features that their cloud providers already support and monitoring for common credential abuse attempts.

"Today's threat landscape is truly borderless, as adversaries morph into criminal enterprises focused on monetizing their attack strategies," said Jake King, head of security intelligence and director of engineering at Elastic. "Open source, commodity malware, and the use of AI have lowered the barrier to entry for attackers, but we're also seeing the rise of automated detection and response systems that enable all engineers to better defend their infrastructures. It's a cat-and-mouse game, and our strongest weapons are vigilance and the continued investment in new defense technologies and strategies."

Additional Resources

Download the report
Read the blog
Join the webinar

About the Report

The 2023 Elastic Global Threat Report is a summary of observations distilled down to a small number of distinct categories. The report is based on Elastic telemetry, public, and third-party data voluntarily submitted to surface threats based on observations from more than 1 billion data points over the last 12 months. All information has been responsibly sanitized where applicable to protect the identities of those involved.

About Elastic

Elastic (NYSE: ESTC) is a leading platform for search-powered solutions. Elastic understands it's the answers, not just the data. The Elasticsearch platform enables anyone to find the answers they need in real-time using all their data, at scale. Elastic delivers complete, cloud-based, AI-powered solutions for enterprise security, observability and search built on the Elasticsearch platform, the development platform used by thousands of companies, including more than 50% of the Fortune 500. Learn more at elastic.co


These press releases may also interest you

at 16:20
Summit Therapeutics Inc. ("Summit," "we," or the "Company") today announced the grant of inducement awards of options to purchase a collective total of up to 330,000 shares of common stock. Awards were made to six new employees of the Company. The...

at 16:19
The Autorité des marchés financiers ("AMF") cautions Québec consumers about the website dr-hypotheque.ca.  According to information...

at 16:15
Block, Inc. will release financial results for the second quarter of 2024 on Thursday, August 1, 2024, after market close. Block will also host a conference call and earnings webcast at 2:00 p.m. Pacific Time/5:00 p.m. Eastern Time on the same day...

at 16:15
Snap Inc. will hold its quarterly conference call to discuss second quarter 2024 financial results on Thursday, August 1, 2024 at 2:30 p.m. Pacific Time (5:30 p.m. Eastern Time). A live webcast and replay of the conference call will be accessible...

at 16:10
bluebird bio, Inc. today announced that the Compensation Committee of the Company's Board of Directors approved an inducement grant of stock options to purchase a total of 300,000 shares of common stock to its chief financial officer, James...

at 16:10
AppLovin Corporation, ("AppLovin" or the "Company") the leading marketing platform, today announced it will report financial results for the second quarter on Wednesday, August 7, 2024 after the U.S. stock market closes. An accompanying webinar...



News published on and distributed by: