

Supply chains, trust, and the Internet itself remain prime targets.
When Russia launched wide-ranging cyber-attacks while its army invaded Ukraine, it also deployed waves of wiper malware to destroy data.
The first wave targeted the data on the disks. As Ukraine fortified its defenses in that area, the second wave left the data on the disks alone and went after the metadata. The third wave bypassed the two previous targets and attacked the file systems.
As depicted in global news and during sessions of the RSA conference, this was a very methodical and effective approach designed to inflict maximum amounts of damage, and it reflects the methodical, often relentless, attack approaches shaping the threat landscape. In particular, as organizations fortify their defenses, adversaries will continue to focus on trust to gain access, using your partners, your vendors, and your employees against you. What does this mean for enterprise users?
As we discussed in our previous post on cyber threats, organizations must find new and novel defenses against adversaries who increasingly shift tactics. As adversaries become more nuanced, we must understand their moves and motivations to try to get one step ahead of them.
Several high-profile security incidents in the recent past altogether grimly encapsulate the myriad challenges companies now face.
Threat actors are targeting the foundational infrastructure of the internet as well. Sea Turtle, a 2019 service-based supply chain attack, targeted DNS infrastructure. The tools hacked registrants, modified DNS records, and hijacked DNS servers, so actors could have the legitimate domains pointed to servers that they owned.
Attacks will continue to escalate. Compounding much of this is the fact that nation-states can now buy these exploits, rather than developing them in-house. That means anybody with deep pockets can launch very sophisticated attacks.
Today’s threat landscape is increasingly complicated, one that requires organizations to know much more about potential adversaries. Anomali believes that the next evolution of cybersecurity will be one focused on adversary detection and response. In the future, it may be the only way to truly secure and maintain the upper hand.
While the panel trained a spotlight on the myriad challenges that organizations face trying to protect their infrastructure, there’s more need than ever for proactive security strategies driven by threat intelligence to help them defend against cyberattacks.
Defenders need relevant intelligence on the adversary at their immediate disposal. They also need to be able to correlate that data with telemetry from their environment so they can accurately figure out their risks and then decide on the best course of action.
Taking a proactive approach gives organizations the opportunity to outmaneuver their opponents with a risk-based cyber-defense strategy, deploying machine learning, analytics, and automation as enablers to fine-tune detection capabilities and focus on the adversaries that matter.
As mentioned previously, organizations need to understand as much about their adversaries as possible.
Organizations need to adopt a proactive, intelligence-driven defense. They need a solution that detects attackers and delivers the relevant intelligence necessary to defend against intruders. Instead of waiting for an attack to unfold, they need the necessary threat intelligence to predict an attacker’s next move and stymie infiltration attempts. This is the essence of adversary detection and response.
The threat landscape is constantly changing. Given its relentless nature, organizations must expect to adapt as they confront new challenges daily. By understanding their adversaries’ moves and motivations, they’ll be better equipped to proactively protect their operations and those who rely on them.
FEATURED RESOURCES


