Ransomware attackers are applying a significant focus on defense evasion tactics to increase dwell time in victim networks, according to a new report by Cisco Talos.
This trend is a result of the shift to the double-extortion ransomware model, in which attackers aim to steal sensitive data and threaten to publish it online alongside locking down the victims’ systems.
Ransomware threat actors need to gain persistent access to understand the network’s structure, locate resources that can support the attack, and identify data of value that can be stolen, the researchers said.
The Cisco Talos report analyzed the tactics, techniques and procedures (TTPs) of the 14 most active ransomware groups between 2023 and 2024.
No tags.