Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Portugal attack stalls in DR Congo World Cup draw

    June 18, 2026

    U.S. Polo Assn. Unveils Spring-Summer 2027 Collection at the 110th Edition of Pitti Immagine Uomo

    June 18, 2026

    China raises emergency response after Qinghai earthquake

    June 17, 2026
    Facebook X (Twitter) Instagram
    Malawi MailMalawi Mail
    • Automotive

      Porsche reveals bespoke 911 GT3 RS in Macadamiametallic

      May 18, 2026

      Mercedes-Benz unveils electric C-Class in Seoul

      April 21, 2026

      2027 Mercedes-Benz S-Class adds DIGITAL LIGHT micro-LEDs

      January 30, 2026

      Ford issues US recall for Escape Focus Explorer and Lincoln MKC

      January 22, 2026

      EU softens 2035 ban on combustion engine vehicles

      December 17, 2025
    • Business

      Samsung leads global chip investment with US$59.2B spend

      June 10, 2026

      Egypt GDP rises 5.2% as foreign reserves climb

      June 8, 2026

      Korean cosmetics exports hit US$5.6 billion in five months

      June 8, 2026

      Investor interest lifts UAE real estate in global index

      June 5, 2026

      Dollar heads for weekly gain as yen nears 160 level

      June 5, 2026
    • Entertainment

      Sony confirms God of War trilogy remake and PS5 prequel

      February 13, 2026

      Apple Arcade adds Jeopardy and NFL games in September update

      August 19, 2025

      Moscow hosts historic 47th international festival

      April 19, 2025

      Legal action against ‘Ketamine Queen,’ doctors in Perry overdose

      August 17, 2024

      Web3 leader Immutable rolls out $50M gaming rewards initiative

      April 27, 2024
    • Health

      Ebola cases in DR Congo rise as WHO warns on spread

      June 13, 2026

      DR Congo Ebola cases rise to 598 as deaths reach 115

      June 10, 2026

      WHO reports 507 Ebola cases across Congo and Uganda

      June 8, 2026

      Global health bodies seek $518 million for Ebola response

      June 6, 2026

      WHO says Congo Ebola response improves as challenges remain

      June 4, 2026
    • Lifestyle

      JP Morgan funds Fresha with $31 million for AI and robotics growth

      August 23, 2024

      Adidas, Highsnobiety debut limited-edition sneakers

      January 6, 2024

      Unraveling Starbucks’ phenomenon as a worldwide coffee powerhouse

      September 1, 2023

      How Nike’s Kobe 8 Protro Halo Marks an Emotional Milestone

      August 29, 2023

      From labels to legacy – understanding fashion’s hierarchy

      August 21, 2023
    • Luxury

      Global luxury market contracts for first time since Great Recession

      November 18, 2024

      Uncover the allure of Rolex Deepsea – luxury awaits.

      April 10, 2024

      Beyond timekeeping to the prestige of the Rolex Day-Date

      March 2, 2024

      Rare uncut emerald dazzles at Sharjah show

      February 1, 2024

      Porsche and Frauscher launch the electric 850 Fantom Air

      October 17, 2023
    • News

      China raises emergency response after Qinghai earthquake

      June 17, 2026

      Dubai Customs helps seize 1.332 tonnes of Tapentadol

      June 16, 2026

      UAE President and Sisi discuss ties and region in Cairo

      June 16, 2026

      Dubai Customs intercepts 223 live animals at airport

      June 13, 2026

      UAE and US discuss UN cooperation in Abu Dhabi

      June 11, 2026
    • Sports

      Portugal attack stalls in DR Congo World Cup draw

      June 18, 2026

      France opens World Cup with 3-1 win over Senegal

      June 17, 2026

      South Korea tops Czechia 2-1 in FIFA World Cup Group A

      June 12, 2026

      Magnitude claims Dubai World Cup 2026 title with strong run

      March 28, 2026

      Griekspoor meets Medvedev in Dubai title match

      February 28, 2026
    • Technology

      PM Modi strengthens India France technology and innovation ties in Nice

      June 16, 2026

      Nvidia expands South Korea AI and data centre deals

      June 9, 2026

      South Korea launches $665.5 million industrial growth fund

      May 20, 2026

      Space42 says Foresight boosts UAE space industry

      May 8, 2026

      India weighs $11 billion fund to boost chipmaking

      March 13, 2026
    • Travel

      Etihad adds free medical cover for Abu Dhabi visitors

      June 13, 2026

      Etihad expands Paris route with double daily A380 flights

      May 20, 2026

      flydubai adds daily Dubai Bangkok flights from July

      April 21, 2026

      Etihad expands Africa network with six new routes

      April 18, 2026

      Yas Waterworld adds 11 attractions for April 4 opening

      March 24, 2026
    Malawi MailMalawi Mail
    Home » Ransomware Dwell Time Hits Low of 24 Hours
    PR Newswire

    Ransomware Dwell Time Hits Low of 24 Hours

    October 5, 2023
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    Analysis from Secureworks annual State of The Threat Report shows ransomware median dwell time has dropped from 4.5 days to less than 24 hours in a year

    ATLANTA, Oct. 5, 2023 /PRNewswire/ — Ransomware is being deployed within one day of initial access in more than 50% of engagements, says Secureworks® (NASDAQ: SCWX) Counter Threat Unit™ (CTU™). In just 12 months the median dwell time identified in the annual Secureworks State of the Threat Report has freefallen from 4.5 days to less than one day. In 10% of cases, ransomware was even deployed within five hours of initial access.

    www.secureworks.com

    “The driver for the reduction in median dwell time is likely due to the cybercriminals’ desire for a lower chance of detection. The cybersecurity industry has become much more adept at detecting activity that is a precursor to ransomware. As a result, threat actors are focusing on simpler and quicker to implement operations, rather than big, multi-site enterprise-wide encryption events that are significantly more complex. But the risk from those attacks is still high,” said Don Smith, VP Threat Intelligence, Secureworks Counter Threat Unit.

    “While we still see familiar names as the most active threat actors, the emergence of several new and very active threat groups is fuelling a significant rise in victim and data leaks. Despite high profile takedowns and sanctions, cybercriminals are masters of adaptation, and so the threat continues to gather pace,” Smith continued.

    The annual State of the Threat report examines the cybersecurity landscape from June 2022 to July 2023. Key findings include:

    • While some familiar names including GOLD MYSTIC (LockBit), GOLD BLAZER (BlackCat/ALPV), and GOLD TAHOE (Cl0p) still dominate the ransomware landscape, new groups are emerging and listing significant victim counts on “name and shame” leak sites. The past four months of this reporting period have been the most prolific for victim numbers since name-and-shame attacks started in 2019.
    • The three largest initial access vectors (IAV) observed in ransomware engagements where customers engaged Secureworks incident responders were: scan-and-exploit, stolen credentials and commodity malware via phishing emails.
    • Exploitation of known vulnerabilities from 2022 and earlier continued and accounted for more than half of the most exploited vulnerabilities during the report period.

    Most Active Ransomware Groups

    The same threat groups continued to dominate in 2023 as in 2022. GOLD MYSTIC’s LockBit remains the head of the pack, with nearly three times the number of victims as the next most active group, BlackCat, operated by GOLD BLAZER.

    New schemes have also emerged and posted numerous victims. MalasLocker, 8BASE and Akira (which ranked at number 14) are all newcomers that made an impact from Q2 2023. 8BASE listed nearly 40 victims on its leak site in June 2023, only slightly fewer than LockBit. Analysis shows that some of the victims go back as far as mid 2022, although they were dumped at the same time. MalasLocker’s attack on Zimbra servers from the end of April 2023 accounted for 171 victims on its leak site in May. The report examines what leak site activity actually reveals about ransomware attack success rates — it’s not as straightforward as it seems.

    The report also reveals that victim numbers per month from April-July 2023 were the most prolific since name and shame emerged in 2019. The highest number of monthly victims ever was posted to leak sites in May 2023 with 600 victims, three times as many as in May 2022.

    Top Initial Access Vectors for Ransomware

    The three largest initial access vectors (IAV) observed in ransomware engagements where customers engaged Secureworks incident responders were: scan-and-exploit (32%), stolen credentials (32%) and commodity malware via phishing emails (14%).

    Scan-and-exploit involves the identification of vulnerable systems, potentially via a search engine like Shodan or a vulnerability scanner, and then attempting to compromise them with a specific exploit. Within the top 12 most commonly exploited vulnerabilities, 58% have CVE dates of earlier than 2022. One (CVE-2018-13379) also made the top 15 most routinely exploited list in 2021 and 2020.

    “Despite much hype around ChatGPT and AI style attacks, the two highest profile attacks of 2023 thus far were the result of unpatched infrastructure. At the end of the day, cybercriminals are reaping the rewards from tried and tested methods of attack, so organizations must focus on protecting themselves with basic cyber hygiene and not get caught up in hype,” Smith continued.

    The World of Nation-State Attackers

    The report also examines the significant activities and trends in the behavior of state-sponsored threat groups belonging to China, Russia, Iran, and North Korea. Geopolitics remains the primary driver for state-sponsored threat groups across the board.

    China:

    China has shifted part of its attention to Eastern Europe, while also maintaining a focus on Taiwan and other near neighbors. It displays a growing emphasis on stealthy tradecraft in cyberespionage attacks — a change from its previous “smash-and-grab” reputation. The use of commercial tools like Cobalt Strike, as well as Chinese open-source tooling, minimizes risk of attribution and blends with activity from post-intrusion ransomware groups.

    Iran:

    Iran remains focused on dissident activity, on hindering progress on the Abraham Accords, and on Western intentions towards renegotiations of nuclear accords. Iran’s main intelligence services — the Ministry of Intelligence and Security (MOIS or VAJA) and the Islamic Revolutionary Guard Corp (IRGC) — both use a network of contractors to support offensive cyber strategies. The use of personas (impersonating real people or fake created people) is a key tactic across Iranian threat groups.

    Russia:

    The war in Ukraine remained the focus for Russian activity. This falls into two camps; cyberespionage and disruption. This year has seen an increase in the amount of patriotic-minded cyber groups targeting organizations considered adversaries of Russia. For gangs, Telegram is the social media/messaging platform of choice for recruitment, targeting and celebrations of success. The malicious use of trusted third-party cloud services is frequently incorporated into Russian threat group operations.

    North Korea:

    North Korea threat groups fall into two groups: cyber espionage and revenue generation for the isolated regime. AppleJeus has been a fundamental tool for North Korea’s financial theft initiatives, and according to Elliptic, North Korean threat groups have stolen $2.3 billion USD in crypto assets between May 2017 and May 2023 (30% of this from Japan).

    State of the Threat Report 2023

    This latest State of the Threat Report is the seventh annual report from Secureworks providing a concise analysis of how the global cybersecurity threat landscape has evolved over the last 12 months. The information within the report is drawn from the Secureworks Counter Threat Unit’s (CTU) firsthand observations of threat actor tooling and behaviors and includes real-life incidents. Our annual threat analysis provides a deep dive insight into the threats our team has observed on the front line of cybersecurity.

    The Secureworks State of the Threat Report can be read in full here: https://www.secureworks.com/resources/rp-state-of-the-threat-2023

    About Secureworks

    Secureworks (NASDAQ: SCWX) is a global cybersecurity leader that secures human progress with Secureworks® Taegis™, a SaaS-based, open XDR platform built on 20+ years of real-world threat intelligence and research, improving customers’ ability to detect advanced threats, streamline and collaborate on investigations, and automate the right actions. Connect with Secureworks via Twitter, LinkedIn and Facebook and Read the Secureworks Blog

    Logo – https://mma.prnewswire.com/media/1558509/Secureworks_V1_Logo.jpg

    Cision View original content:https://www.prnewswire.co.uk/news-releases/ransomware-dwell-time-hits-low-of-24-hours-301947692.html

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email

    Related Posts

    Health and Fitness Manufacturers at the Forefront of Product Development at the 136th Canton Fair

    November 1, 2024

    Mibro Launches Lite3 Pro Smartwatch: The Ideal Work-Life Balance Companion for Urban Professionals

    July 1, 2024

    An All-New Choice: GAC Unveils Next-Gen M8 MPV in Kuwait

    May 27, 2024

    Unlocking Success: How Newborn Town Dominates the MENA Social Networking Market

    May 27, 2024

    CGTN: Eyeing Chinese modernization, China doubles efforts to further deepen reform on all fronts

    May 25, 2024

    ONCOCLÍNICAS APPROVES R$ 1.5 BILLION CAPITAL INCREASE

    May 24, 2024
    Latest News
    Sports

    Portugal attack stalls in DR Congo World Cup draw

    June 18, 2026

    HOUSTON, TEXAS / MENA Newswire / – Portugal opened its FIFA World Cup Group K…

    China raises emergency response after Qinghai earthquake

    June 17, 2026

    France opens World Cup with 3-1 win over Senegal

    June 17, 2026

    Dubai Customs helps seize 1.332 tonnes of Tapentadol

    June 16, 2026

    UAE President and Sisi discuss ties and region in Cairo

    June 16, 2026

    PM Modi strengthens India France technology and innovation ties in Nice

    June 16, 2026

    Dubai Customs intercepts 223 live animals at airport

    June 13, 2026

    Ebola cases in DR Congo rise as WHO warns on spread

    June 13, 2026
    © 2026 Malawi Mail | All Rights Reserved
    • Home
    • Contact Us

    Type above and press Enter to search. Press Esc to cancel.